Threat Database Trojans TrojanDownloader:MSIL/Genmaldow.C

TrojanDownloader:MSIL/Genmaldow.C

By GoldSparrow in Trojans

Threat Scorecard

Popularity Rank: 22,180
Threat Level: 90 % (High)
Infected Computers: 247
First Seen: December 28, 2015
Last Seen: May 25, 2026
OS(es) Affected: Windows

TrojanDownloader:MSIL/Genmaldow.C is a threat that once inside a computer, can modify its Registry to be loaded every time the affected machine is initiated. The presence of TrojanDownloader:MSIL/Genmaldow.C may cause serious issues to the PC since it may download unwanted software and even malware (for example the HEUR:Exploit.Java.CVE-2013-2423.gen threat) automatically. Also, TrojanDownloader:MSIL/Genmaldow.C may connect a remote host to receive instructions, configurations and other specifics, install and execute files, support a digital certificate, look for the location of your PC, collect information such as financial data, passwords and user names for bank accounts and more. TrojanDownloader:MSIL/Genmaldow.C may slow down your machine's performance drastically. TrojanDownloader:MSIL/Genmaldow.C also may display unwanted advertisements that may disrupt your activities, cause unsafe redirections and hijack your Web browser. The removal of TrojanDownloader:MSIL/Genmaldow.C can be very tricky; therefore, the recommended removal method is using an exact malware removal product.

Analysis Report

General information

Family Name: Trojan.Ulise.B
Packers: UPX
Signature status: No Signature

Known Samples

MD5: f8311edebf263742b9c0048b9d25fd78
SHA1: 1193b902d90bd2a82f634ceec2fdac02987432bd
SHA256: 571A73C778560FEE400861E013CBB06A5A0DAE8A90CF69625135C6CC8DBE9F3B
File Size: 494.08 KB, 494080 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments 挂机系统
Company Name 流__沙
File Description 挂机系统
File Version 1.0.0.0
Legal Copyright 流__沙 版权所有
Product Name 挂机系统
Product Version 1.0.0.0

File Traits

  • .UPX
  • 2+ executable sections
  • HighEntropy
  • packed
  • upx
  • UPX!
  • x86

Block Information

Total Blocks: 1,664
Potentially Malicious Blocks: 428
Whitelisted Blocks: 1,146
Unknown Blocks: 90

Visual Map

? x x 0 ? x ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? x ? ? ? ? x ? x x ? ? x ? ? ? x ? ? ? ? ? x x x x x x x x x x x x x x ? x ? 0 0 x x x 0 ? x ? 0 ? x x x x x x ? ? ? ? ? ? ? x ? ? x ? ? x ? ? x x 0 x ? ? x x ? x ? x x x ? ? x ? x x x x x x x x x x x x x x ? x x x x x x x x x x x x x x x x x ? ? ? ? ? ? ? x x ? ? x 0 x x ? x x x x x x x ? x x x x x x x x x x x x x x x x x x ? ? ? ? ? ? 0 ? ? ? ? ? x ? ? ? x ? x ? ? ? ? ? ? ? x x x 0 x x 0 x x x x x x x x x x x 0 0 x 0 x x x x 0 x 0 x 0 0 0 x 0 x 0 x 0 x 0 0 x x x x x x x x x x x 0 x x x x x x x x 0 x 0 x x x 0 x x x x 0 x x x x 0 x x x x x x x x x x x x x 0 x x x x x 0 x x x x x 0 0 x 0 0 x 0 0 0 x x 0 0 x x x 0 0 0 0 x 0 0 x x x x x x 0 0 x 0 0 x 0 x x x 0 x x x x x 0 x 0 x x x x x x x x x x x x x 0 x x x x x x 0 0 x x 0 x x 0 0 0 x x x x 0 0 0 x 0 x x x x x x x x x x x x x x x x x x x 0 0 x 0 0 x x 0 x 0 x 0 0 0 x x x x x x 0 0 x x x x x x 0 0 0 x 0 0 x x x x x x x 0 x x 0 x x x x 0 x x 0 x x x x 0 x x 0 x 0 x 0 0 0 x 0 x x x 0 0 0 x x x x x x x x x x x x x x x x 0 0 0 x x 0 x x 0 x x 0 0 x x 0 0 x 0 0 x x 0 0 x x 0 0 x 0 0 0 x x 0 0 0 x x 0 x 0 0 x x x 0 x 0 0 x x 0 x 0 0 0 0 0 x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 x 0 0 0 x 0 x x x 0 0 0 0 0 x 0 x x x 0 x x x x x x 0 x x x x 0 x x 0 x 0 x x 0 x x x x x x x x x x x 0 x x x 0 x x x x 0 x 0 x x x 0 x 0 x x 0 x 0 x x x 0 0 x x x 0 x x 0 0 0 0 0 0 0 x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 0 1 0 1 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Bitcoinminer.FD

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation

Trending

Most Viewed

Loading...