Threat Database Trojans Trojan.MSIL.Heracles.DQ

Trojan.MSIL.Heracles.DQ

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 1
First Seen: January 7, 2025
Last Seen: March 4, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Heracles.DQ indicates that your system has been compromised by a potentially malicious program. This type of threat is generally categorized as a Trojan, which is a broad term for malware that disguises itself as legitimate software. The presence of Trojan.MSIL.Heracles.DQ on your system poses a risk to your personal data and system security, and it is essential to take immediate action to remove it.

What Is Trojan.MSIL.Heracles.DQ?

Trojan.MSIL.Heracles.DQ is a type of malware that can infect your system through various means, such as exploited vulnerabilities, phishing attacks, or drive-by downloads. Once installed, it can perform a range of malicious activities, including data theft, system compromise, and the installation of additional malware. The name Trojan.MSIL.Heracles.DQ suggests that it is a Trojan-type threat, but the specifics of its behavior and purpose can vary.

How Trojan.MSIL.Heracles.DQ Operates

Trojan.MSIL.Heracles.DQ operates by exploiting weaknesses in your system's security, often through social engineering tactics or by taking advantage of unpatched vulnerabilities. It can then establish a connection with its command and control server, allowing it to receive instructions and transmit stolen data. The malware may also attempt to install additional components or update itself to evade detection and improve its capabilities.

Malware like Trojan.MSIL.Heracles.DQ can be particularly challenging to detect, as it often disguises itself as legitimate software or system files. However, its presence can be inferred through suspicious system behavior, such as unusual network activity, slowed system performance, or the appearance of unfamiliar programs or files.

Symptoms of Infection

The symptoms of a Trojan.MSIL.Heracles.DQ infection can vary, but common indicators include:

  • Unexplained system crashes or freezes
  • Slowed system performance or responsiveness
  • Unusual or unexplained network activity
  • The appearance of unfamiliar programs, files, or system components
  • Changes to system settings or configuration

It is essential to be aware of these symptoms and take prompt action if you suspect that your system has been compromised.

How to Remove Trojan.MSIL.Heracles.DQ

To remove Trojan.MSIL.Heracles.DQ from your system, follow these steps:

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for internet access.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove the malware.
  3. Uninstall any suspicious programs or software that may be related to the infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or settings.
  5. Reboot your system and perform a follow-up scan to ensure that the malware has been completely removed.

It is crucial to be thorough and meticulous when removing malware to prevent re-infection and ensure that your system is fully cleaned.

Conclusion

The detection of Trojan.MSIL.Heracles.DQ is a serious issue that requires immediate attention. By understanding the nature of this threat and taking the necessary steps to remove it, you can protect your system and personal data from further harm. Remember to stay vigilant and proactive in maintaining your system's security, including keeping your software up-to-date, using strong antivirus protection, and being cautious when interacting with unfamiliar programs or files.

Analysis Report

General information

Family Name: Trojan.MSIL.Heracles.DQ
Signature status: No Signature

Known Samples

MD5: 0011219ecf13fe79d4384a3c636a8ab8
SHA1: e159ddd9713a1fc9e6c4d3321f251fb3f2046244
SHA256: 5FCC5F15790B7AB89DC967A6DE8055998149279C40BD2DD4C8F48BB3B486AEEC
File Size: 90.62 KB, 90624 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
Comments etieOMMcioWUeoeifsWi
Company Name etieOMMcioWUe
File Description etieOMMcio
File Version 1.0.0.0
Internal Name マックス.exe
Legal Copyright etieOMMcioWUeoe 2015
Legal Trademarks etieOMMcioWUeoeifsWihtr
Original Filename マックス.exe
Product Name etieOMMcio
Product Version 1.0.0.0

File Traits

  • .NET
  • RijndaelManaged
  • x86

Block Information

Total Blocks: 12
Potentially Malicious Blocks: 5
Whitelisted Blocks: 5
Unknown Blocks: 2

Visual Map

0 ? x ? x x x x 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\appdata\local\temp\trojan.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 -k�8��8tX��B�8 �� �6 �v 5� �Z xy ��T�B�������������5����ee��Bx�< �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9�/��0P%1`1�1HO1�D5�05�G RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 ~� % xy* �/��Y�d�kP~� ��ރ�p��^�o���zee+Vs} kP~ ��1���7 ���ﺃee����1��fe��h�n RegNtPreCreateKey
Show More
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 .k8��8tX��B�8 �� �6 �v 5� �Z xy ��T�B�������������5����ee��Bx�< �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9�/��0P%1`1�1HO1�D5�05�G RegNtPreCreateKey
HKCU\environment::see_mask_nozonechecks 1 RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 䤪晧꣙ǜ RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcAcceptConnectPort
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcCreatePortSection
  • ntdll.dll!NtAlpcCreateSectionView
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
Show More
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationObject
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSetTimerEx
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
User Data Access
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
  • ShellExecuteEx
Keyboard Access
  • GetAsyncKeyState
Other Suspicious
  • AdjustTokenPrivileges
Network Winsock2
  • WSAStartup
Service Control
  • OpenSCManager
  • OpenService

Shell Command Execution

(NULL) C:\Users\Vxfqqozq\AppData\Local\Temp\Trojan.exe
netsh firewall add allowedprogram "C:\Users\Vxfqqozq\AppData\Local\Temp\Trojan.exe" "Trojan.exe" ENABLE

Related Posts

Trending

Most Viewed

Loading...