Threat Database Trojans Trojan.RBot.B

Trojan.RBot.B

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 13,538
Threat Level: 80 % (High)
Infected Computers: 102
First Seen: May 17, 2023
Last Seen: January 7, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.RBot.B
Signature status: No Signature

Known Samples

MD5: 365f03a4cbd37a7e4610d40e62c5104d
SHA1: 45bf63709e477d44e6abb0f2c15a8880d7ca952a
File Size: 195.07 KB, 195072 bytes
MD5: 5500602601bce74ed72e28371192583b
SHA1: 4ced764eccef8319654cecad36935fe25540b6eb
SHA256: D733D4EFD3D0C92953A3D518AD711DF56F032A87C97CCE32BE91CECD1A923BDB
File Size: 1.22 MB, 1220608 bytes
MD5: d247a12afcee57bc87fcf1ae6fe6049e
SHA1: 44986497fa23da0f3d71220f226f31466d88927e
SHA256: 9856B6C2A20A7996A4E2A9E9318B854B76BF9ADA70BB40BC703539D90F376CBA
File Size: 1.51 MB, 1506304 bytes
MD5: 7ccffc6a7906c604d8df84521577a730
SHA1: bc8495bb140cf8fb1d310474fa8f692fb1e9ab82
SHA256: 0E6C0FF46F480A052E49E3A7617511552ADF3DF79DDE123ABBDC21A4246FDB8C
File Size: 244.74 KB, 244736 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Microsoft Corporation
File Description Win32 Cabinet Self-Extractor
File Version 6.00.2600.0000 (xpclient.010817-1148)
Internal Name Wextract
Legal Copyright © Microsoft Corporation. All rights reserved.
Original Filename WEXTRACT.EXE
Product Name Microsoft® Windows® Operating System
Product Version 6.00.2600.0000

File Traits

  • .adata
  • 00 section
  • 2+ executable sections
  • HighEntropy
  • No Version Info
  • VirtualQueryEx
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 3
Potentially Malicious Blocks: 1
Whitelisted Blocks: 1
Unknown Blocks: 1

Visual Map

0 x ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • RBot.B

Registry Modifications

Key::Value Data API Name
HKLM\software\classes\.key:: regfile RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{533017fd-f2bd-7d14-bb2f-3d61a5c06cac}:: QrE4VOujXxnKJqS/ RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{533017fd-f2bd-7d14-bb2f-3d61a5c06cac}:: QrE4VOujXxnKJqS/ RegNtPreCreateKey

Trending

Most Viewed

Loading...