Threat Database Trojans Trojan.Razy

Trojan.Razy

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 20,193
Threat Level: 80 % (High)
Infected Computers: 181,432
First Seen: February 12, 2016
Last Seen: March 20, 2026
OS(es) Affected: Windows

SpyHunter Detects & Remove Trojan.Razy

File System Details

Trojan.Razy may create the following file(s):
# File Name MD5 Detections
1. william.dll b0e610a39b803fc093da85a2bd62d3ee 1,373
2. dllhoste.exe 45a9bad6f4f0cc830077a2b64f54fe04 493
3. windefender.exe ec068db21439fb9fb820cbfb379ff72e 359
4. WINMM.dll a6a8f921e8ae486bf993b35fd2751f6e 337
5. a74b.tmp.exe dffa76a03c9207c18e5f182374a642fb 306
6. WINDEFENDER.EXE.del 3efa5b3649c8f5a9b207fb32485e2eb5 233
7. tLOKN1KQ+i.exe 763dcec66441cd224721e97a269884d7 68
8. Bermuda.exe f15ba3b5e0cace488f17bcb21a7c2d4e 9
9. 0485c553d4262fcdda174a65d201ac74f4fa5c97e1c041c075ce3356be5c1d86.exe d0d777a3ac385ae55b4b6b964077b780 6
10. Client.exe 6fee9f83e43cd164157bd73ac84e7696 2
11. fc2b86ec4624c7d3cf77eddbe321420f.exe 79ce5bdb79117804552978e9ea880ae3 2
12. 00f9941661dd2f1f8e982bd80e243e9b1138694eef8c186a5434d6f608c0b788.exe 035a2398c78db8c14ca4304bc1fb4989 0
13. 014ff9367f6677ad48d71a94d9616843ff97431fd2a489e75807577eaf9b53c2.exe 50035f3ef711d2328b47e8fe0806a5db 0
14. 0202e1f00fecabde6a5dfe45afc91fe193e0c8a4b2d834b335eea30110a917a2.exe 494442a24b81c43dc2081d4437ee0511 0
15. 02490006ca5835aa6e1ca6692476aae55817529829e7b6152c746af1dd9db477.exe 15ae460959169b03d1d552ae292cc0f0 0
16. 03c0ea5fc3e3e011dfe8b6c6dbe64ca2901de15ed015431ad4dadffd21ded6f4.exe 13526f6f7bf53d2b948d60f8d0554049 0
17. 042a663b0fa8f1334ffeb700a42b37355048a9fed8d90d584441995d59e67a55.exe af3cc31431ef2ab6210b80746d00f680 0
18. 067820bd01f7f25290ee2fa8c0bbb36e40e7987f27d7d4dfdb419ba29403de06.exe 45461b7e05f264ed24c41854c7729920 0
19. 07128f3bb25c3760048b3fbe25fef1589434fdd05c1295694e836bc3873e189f.exe 5d8fca006ff657ad00790cc89b9e2c6a 0
20. 07129056043699147c71b86afede0e0087e9d1be52c4b09b79c46d58e5f66471.exe a26a73d7a8acbb93189bf363d5f9927a 0
21. 07b41a29b1b3dce38011d4d0c90763320ffa64e4db1104121499015e95ff510b.exe af7272bf44871afde36b3cbd80468b4c 0
22. 07bf0586b4e238bbe690fbd93e912762ddebd55d9c61d08ee91114cee7522ba6.exe 95516e423bce3b39d6d1efaaf647b82d 0
23. 07d7dd70897eb4a5752f4dc707665d83f67a5bc1c69e841c345e06339461050c.exe 1bad04592cc81a34f9d7233c1b391793 0
24. 089507796e0a3aa859de237bc2cc873397d5352d7cd4816a685b4e8722c7554f.exe ff5de969e25d15e407d480c6b71c855f 0
25. 08f59ff10b42309ca5edd3f0e05d52c371ef3dbb48e0c334115ad078ce72b139.exe 0141c3736a5a1422cb8770fbeb4a66d2 0
26. 83befd8ceaa633a73bfdd0b941420ccf 83befd8ceaa633a73bfdd0b941420ccf 0
27. 2ae954948e02294fa4a223766fa64839 2ae954948e02294fa4a223766fa64839 0
More files

Registry Details

Trojan.Razy may create the following registry entry or registry entries:
File name without path
bo01289j3ofij.exe
Regexp file mask
%ALLUSERSPROFILE%\NlmService.exe
%ALLUSERSPROFILE%\windows\profile\service.exe
%APPDATA%\Adobe.exe
%APPDATA%\Avast.exe
%APPDATA%\Bermuda.exe
%APPDATA%\Microsoft\Video\uninstall.exe
%APPDATA%\ScreenMaker\SSMaker.exe
%APPDATA%\winlog.xml
%HOMEDRIVE%\pack\dllhoste.exe
%LOCALAPPDATA%\dvbsys.exe
%LOCALAPPDATA%\WinxOff.exe
%temp%\server.exe
%TEMP%\System.exe.exe
%USERPROFILE%\Desktop\godfcryp.exe

Directories

Trojan.Razy may create the following directory or directories:

%APPDATA%\ProgramFiles(32.3uu)
%APPDATA%\iaq
%APPDATA%\ikr
%APPDATA%\qfk
%LOCALAPPDATA%\william
%TEMP%\Win64

Analysis Report

General information

Family Name: Trojan.Razy
Signature status: No Signature

Known Samples

MD5: eb9b267c4010ad230c4b394dacae056f
SHA1: b1b20eec5059e333c437838d52f8684680d57828
SHA256: 2EA7372AF7E8F857D5F6E15D8700F9F78841678AC01F5EDEB59B992FCD6D02F5
File Size: 549.38 KB, 549376 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
File Version 7.2.1.1
Legal Copyright Copyright © 2020
Product Version 7.2.1.1

File Traits

  • HighEntropy
  • x86

Block Information

Total Blocks: 68
Potentially Malicious Blocks: 1
Whitelisted Blocks: 0
Unknown Blocks: 67

Visual Map

? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Network Winsock2
  • WSAStartup

Related Posts

Trending

Most Viewed

Loading...