Threat Database Trojans Trojan.MSIL.Taskun.DC

Trojan.MSIL.Taskun.DC

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.MSIL.Taskun.DC
Signature status: Hash Mismatch

Known Samples

MD5: b0c964d7edcec46eb689cdadc9af74d9
SHA1: e721b422b884923d77da9a68bf2fb40e31a4f53c
SHA256: F47DCEF2319D483DD1E6B45F7F3801BB6D5904CC83235BF3A4B1C41D55447699
File Size: 8.29 MB, 8291021 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 2.0.0.0
Company Name The Windows Club
File Description 10AppsManager
File Version 2.0.0.0
Internal Name 10AppsManager.exe
Legal Copyright Copyright © The Windows Club 2015
Original Filename 10AppsManager.exe
Product Name 10AppsManager
Product Version 2.0.0.0

Digital Signatures

Signer Root Status
SUMMER INSTITUTE OF LINGUISTICS, INC. Sectigo Public Code Signing Root R46 Hash Mismatch

File Traits

  • .NET
  • big overlay
  • NewLateBinding
  • RijndaelManaged
  • x86

Block Information

Total Blocks: 536
Potentially Malicious Blocks: 295
Whitelisted Blocks: 241
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x x x x 0 x 0 x x 0 0 0 0 0 0 x x x x 0 x 0 0 0 0 0 0 0 0 0 0 x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x x x x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x x 0 x 0 x x 0 x x x x x x x x x x 0 x 0 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 x 0 x 0 0 0 0 x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x 0 x x x x 0 x x x x x x 0 x 0 0 x x 0 0 x x 0 x x 0 0 0 0 0 x 0 x 0 x 0 x 0 x x x x x x 0 0 0 0 0 x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x 0 x x x 0 x x x 0 x x x x x x 0 x x x 0 0 x x x x x x 0 0 0 x 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x x 0 x 0 0 0 x 0 x 0 x x x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.AgentTesla.XD
  • MSIL.Taskun.DC

Windows API Usage

Category API
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • CheckRemoteDebuggerPresent
  • IsDebuggerPresent
  • NtQuerySystemInformation
  • OutputDebugString
Encryption Used
  • BCryptOpenAlgorithmProvider
Other Suspicious
  • AdjustTokenPrivileges

Trending

Most Viewed

Loading...