Threat Database Trojans Trojan.MSIL.Disdroth.H

Trojan.MSIL.Disdroth.H

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 26
First Seen: January 5, 2024
Last Seen: April 16, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.MSIL.Disdroth.H
Signature status: No Signature

Known Samples

MD5: 239aaf4f51e9db2c9ce66f93a9b3b31c
SHA1: 5dadc39bb1369a3d1aba2dfaca92f66cb9d958b8
SHA256: 5A75A929C5D5F8D56480020AB48644F3BD959C780BD4E6E039F658E00EAA913A
File Size: 15.36 KB, 15360 bytes
MD5: fe9d3a1f170fc4d73124899134c46b60
SHA1: e0288b2667de67aac787314e3c2ee5d1f21527c9
SHA256: 571F1D635F73E7BFBCA25FEAB6ACA5ED7B814F25E478CB4615F6166460BD734D
File Size: 15.36 KB, 15360 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version
  • 3.3.7.2255
  • 2.8.5.0
Company Name CANON INC.
File Description
  • CNQMUTIL
  • i2skyx35
File Version
  • 3.3.7.2255
  • 2.8.5.6383
Internal Name
  • CNQMUTIL.dll
  • WDSync.dll
Legal Copyright
  • Copyright CANON INC. 2012-2017
  • Copyright © 2023
Original Filename
  • CNQMUTIL.dll
  • WDSync.dll
Product Name
  • CNQMUTIL
  • i2skyx35
Product Version
  • 3.3.7.2255
  • 2.8.5.6383

File Traits

  • .NET
  • dll
  • x86

Block Information

Total Blocks: 34
Potentially Malicious Blocks: 5
Whitelisted Blocks: 25
Unknown Blocks: 4

Visual Map

x 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 ? 0 0 0 0 0 0 x x x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Heracles.LO

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
Show More
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Trending

Most Viewed

Loading...