Threat Database Trojans Trojan.PeCan.A

Trojan.PeCan.A

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 10,589
Threat Level: 80 % (High)
Infected Computers: 2,982
First Seen: January 16, 2013
Last Seen: February 15, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.PeCan.A
Signature status: No Signature

Known Samples

MD5: 9d61232dceca966940288bdd8a1b6396
SHA1: 4072e2fe2e6083a73f1d14f754c07e5861278502
SHA256: 1A88FFFA3EE96460BD9CAD72EDCD9E450DF2E32E4925820F2926F494EE7A3879
File Size: 408.06 KB, 408064 bytes
MD5: 8344ca17b5f23ef7dbcec522779ec742
SHA1: 5270361d34e9034ee779c24d9840352c29e47ab8
SHA256: 05B4DFFE16C941E1C64357C9D13673B58F6D1DCC0DEEB11759851957D0D08D49
File Size: 704.54 KB, 704536 bytes
MD5: 9cb7474dba8b8e5fd70b7f0a4c03f78a
SHA1: 1c5adefd84fc931f09899e14fd0f49e2b2991a66
SHA256: 06D86C0EC5ABC7BCDE3BE8BF0C1F45A0C85BE34255E4350F58E9A23D104D8B6E
File Size: 316.95 KB, 316952 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name SmartKey
File Description CUDAOpen
File Version 1, 0, 0, 1
Internal Name CUDAOpen
Legal Copyright 2007-2012(C)SmartKey.All rights reserved.
Original Filename CUDAOpen.dll
Product Name CUDAOpen
Product Version 1, 0, 0, 1

File Traits

  • 2+ executable sections
  • dll
  • HighEntropy
  • No Version Info
  • x86
  • Zprotect

Block Information

Total Blocks: 5
Potentially Malicious Blocks: 1
Whitelisted Blocks: 4
Unknown Blocks: 0

Visual Map

0 0 0 0 x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • PSW.Gamania.A
  • PeCan.A

Files Modified

File Attributes
c:\users\user\appdata\local\temp\dxwmxlyfwm.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ecaqxkfurqwhlghscycs.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\mvygkxzcwaaovbunwnlq.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\test.dat Generic Read,Write Data,Write Attributes,Write extended,Append data

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWriteFile
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\1c5adefd84fc931f09899e14fd0f49e2b2991a66_0000316952.,LiQMAxHB

Trending

Most Viewed

Loading...