Threat Database Trojans Trojan.MSIL.Spy.RG

Trojan.MSIL.Spy.RG

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 15,265
Threat Level: 80 % (High)
Infected Computers: 23
First Seen: October 30, 2023
Last Seen: April 15, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.MSIL.Spy.RG
Signature status: No Signature

Known Samples

MD5: 96ca4283f1ebea1d03cb031ae85a206e
SHA1: 3f44afcb7e04b70e8a591fc0692f49e6085ed0a9
SHA256: 524726D12B6E6AD1013FF6AC9F1AB9CE1B5AA74542F1FB72F6A153B4D82F64FD
File Size: 203.26 KB, 203264 bytes
MD5: 37903e2e1a0332e3eacd2311dd71ec86
SHA1: 4ed44409f1bed913065037cb5c610895ab150557
SHA256: D49C0F2E95E8F08120E0980D36AFC5A1600EF6A57DA7E6892384F9DF84E51D9E
File Size: 369.66 KB, 369664 bytes
MD5: 9de700ac891b5de1ce4eaf59cba645cc
SHA1: b3e842e27b07d1cd353b2f283e8d63c02bd32cc0
SHA256: 2242091E48EB54640486C0FA2E6C2FB7A86103A767867F8F85FA0D2DA3DCE346
File Size: 346.42 KB, 346416 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 6.1.105.1
  • 1.1.2.0
Comments This installation was built with Inno Setup.
Company Name Dinamika Informatika
File Description
  • Database Restore Tool
  • Dinamika Backup Database Setup
  • Screen Lock Builder
File Version
  • 6.1.105.1
  • 1.1.2.0
Internal Name
  • eZeeRestore.exe
  • Screen Lock Builder.exe
Legal Copyright
  • Copyright © 2015
  • Copyright © eZee Technosys Pvt. Ltd. 2008
Legal Trademarks Magu
Original Filename
  • eZeeRestore.exe
  • Screen Lock Builder.exe
Product Name
  • Dinamika Backup Database
  • eZee NextGen
  • Screen Lock Builder
Product Version
  • 6.1.105.1
  • 1.1.2.0

File Traits

  • .NET
  • CryptoObfus
  • HighEntropy
  • x86

Block Information

Similar Families

  • MSIL.ArchSMS.A
  • MSIL.ArchSMS.B
  • MSIL.Injector.XC
  • MSIL.Keylogger.BF
  • MSIL.Krypt.ZADDB
Show More
  • MSIL.Redline.LE

Files Modified

File Attributes
c:\users\user\appdata\local\temp\is-ggv7l.tmp\b3e842e27b07d1cd353b2f283e8d63c02bd32cc0_0000346416.tmp Generic Write,Read Attributes
c:\windows\appcompat\programs\amcache.hve Read Data,Read Control,Write Data
c:\windows\appcompat\programs\amcache.hve.log1 Read Data,Write Data
c:\windows\appcompat\programs\amcache.hve.log2 Read Data,Write Data

Windows API Usage

Category API
User Data Access
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Process Shell Execute
  • CreateProcess
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
Keyboard Access
  • GetKeyState

Shell Command Execution

C:\Windows\Microsoft.NET\Framework\v2.0.50727\\dw20.exe dw20.exe -x -s 912
"C:\Users\Cewfayhr\AppData\Local\Temp\is-GGV7L.tmp\b3e842e27b07d1cd353b2f283e8d63c02bd32cc0_0000346416.tmp" /SL5="$3032A,100197,57856,c:\users\user\downloads\b3e842e27b07d1cd353b2f283e8d63c02bd32cc0_0000346416"

Trending

Most Viewed

Loading...