Threat Database Trojans Trojan.MSIL.PNGLoader.A

Trojan.MSIL.PNGLoader.A

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 21,785
Threat Level: 80 % (High)
Infected Computers: 2
First Seen: May 2, 2024
Last Seen: February 21, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.MSIL.PNGLoader.A
Signature status: No Signature

Known Samples

MD5: 7c065bd83309a43d4a399ec6f4605b81
SHA1: 8adddf3734967f9c77fa718b0fdcbe81eee7ec02
SHA256: 0FBC2AD7D5BA54322E01CF51A7AF3A6E139E19C45CA44F5DC3033118A3B6856F
File Size: 201.22 KB, 201216 bytes
MD5: bf0affe5fb78f8fb340c34168c63e32e
SHA1: 05172d254f1cc3b4a8c55bca0152524f3e17eeab
SHA256: DED2513CDD36F2C41D50EAAF676CC6F69DFBA99D75D43D66B9A627ECDB234991
File Size: 201.22 KB, 201216 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 0.0.0.0
File Version 0.0.0.0
Internal Name Scopely.Sdk.Core.Runtime.dll
Original Filename Scopely.Sdk.Core.Runtime.dll
Product Version 0.0.0.0

File Traits

  • .NET
  • dll
  • x86

Block Information

Total Blocks: 770
Potentially Malicious Blocks: 59
Whitelisted Blocks: 442
Unknown Blocks: 269

Visual Map

? ? 0 0 x x x 0 0 0 0 0 x 0 0 0 x 0 x x 0 x 0 0 x x x 0 0 0 x x x x 0 0 x 0 0 0 x 0 x x x 0 0 0 0 0 x 0 0 0 x 0 x 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 x 0 x x 0 x 0 x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x 0 x 0 x 0 0 0 0 x 0 0 0 x x 0 0 0 0 0 0 0 x 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 ? x 0 ? ? 0 0 ? 0 0 0 ? ? 0 0 0 0 ? ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 ? ? ? ? 0 0 0 ? 0 0 ? 0 0 ? 0 0 0 ? 0 ? ? ? 0 0 ? ? ? ? ? ? 0 ? ? 0 ? ? ? 0 ? ? ? ? 0 0 ? 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 ? 0 ? ? ? ? ? ? ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 ? 0 0 ? ? ? 0 0 ? 0 0 ? 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 ? ? 0 ? ? ? ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 ? ? 0 0 ? ? ? ? ? ? ? 0 0 ? 0 ? 0 ? 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? ? ? ? ? ? ? 0 ? 0 0 0 0 0 0 0 ? ? ? 0 ? 0 0 0 0 0 ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? 0 ? 0 0 ? ? ? 0 ? ? 0 0 0 ? 0 0 0 0 0 0 0 ? 0 ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? 0 ? ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? ? 0 0 0 ? 0 0 ? 0 0 ? ? ? ? ? ? ? 0 ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? 0 ? ? 0 ? ? ? ? ? 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 ? ? 0 x ? ? x 0 0 x ? 0 0 ? ? ? ? ? 0 ? ? ? x ? ? 0 ? 0 0 ? 0 0 0 0 ? 0 0 ? 0 ? 0 ? 0 ? 0 ? ? ? 0 ? 0 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 ? ? ? 0 0 ? 0 ? 0 ? 0 0 ? 0 x 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
Show More
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Trending

Most Viewed

Loading...