Threat Database Trojans Trojan.MSIL.Padpin.B

Trojan.MSIL.Padpin.B

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 25,382
Threat Level: 80 % (High)
Infected Computers: 89
First Seen: October 20, 2021
Last Seen: March 3, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.MSIL.Padpin.B
Signature status: No Signature

Known Samples

MD5: 45dd75a12d9ea10b1cbe2fe2b8085564
SHA1: 79d4b09e77b5c1b2d3396d62cdbd143c3c330bf4
SHA256: 2E1142150999F1EB60407852C54C017FC0933F8B904F3874E129882DF02C34F0
File Size: 194.56 KB, 194560 bytes
MD5: 7326d535ad62a4012767686a259cabd9
SHA1: f7cd9580c4cc8832afb97be19a5642822b42cdc5
SHA256: 25EBD31C29135A47180FBD1A192E09E14FAB5DF65D45452ABE09F965F19AE3AF
File Size: 107.01 KB, 107008 bytes
MD5: c3140346e7b0fbbef57bd6a4054e6098
SHA1: 94747c1ccced1c18e570866ffd7ccb17a1c4625e
SHA256: 3E12DCAC5114328D60E5754888979A8D566C953C8600270EFC2449AC97975769
File Size: 265.22 KB, 265216 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • .NET
  • HighEntropy
  • No Version Info
  • x86

Block Information

Total Blocks: 154
Potentially Malicious Blocks: 55
Whitelisted Blocks: 97
Unknown Blocks: 2

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 x x ? x 0 x x x x 0 x x 0 0 x x x 0 0 x x x x x x x x x x 0 x x x x x x ? x x 0 0 0 0 0 x x 0 0 0 x x 0 0 x x 0 0 x x x x 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Padpin.B
  • MSIL.Padpin.C
  • MSIL.Padpin.D
  • MSIL.Padpin.E
  • MSIL.Padpin.F
Show More
  • MSIL.Padpin.G
  • MSIL.Vittalia.CA

Files Modified

File Attributes
\device\namedpipe Generic Read,Write Attributes
\device\namedpipe Generic Write,Read Attributes
c:\users\user\appdata\roaming\6s5d4f65ds4g65d47gfd684gfd_0019.sys Generic Write,Read Attributes
c:\users\user\appdata\roaming\system.exe Generic Write,Read Attributes

Windows API Usage

Category API
User Data Access
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess

Shell Command Execution

"C:\Users\Emmacxgo\AppData\Roaming\System.exe" c:\users\user\downloads\94747c1ccced1c18e570866ffd7ccb17a1c4625e_0000265216

Trending

Most Viewed

Loading...