Threat Database Trojans Trojan.Refog.C

Trojan.Refog.C

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 17,148
Threat Level: 80 % (High)
Infected Computers: 22
First Seen: February 12, 2024
Last Seen: February 2, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Refog.C
Signature status: No Signature

Known Samples

MD5: f1c9083939a3fc6740bb2e5229383466
SHA1: 2b3aafa079f3cd381cae16119a023fbc787f5d84
SHA256: C3F032CA733A03A48AF90A0BE0ECC7C43825881FE1587E2E60B5D02CBCE51D03
File Size: 74.75 KB, 74752 bytes
MD5: c5b940fa13915409ccc1cb48bdb53706
SHA1: eca2532462b2e323ce62309fac0a70e4dfc695b6
SHA256: C4A1C6CC53EA77B783B32BD9CA9C3749FCDD3813961A9821FE61308FCAEF74CB
File Size: 74.75 KB, 74752 bytes
MD5: 309a3d9e46d1a16a68036df8f390b227
SHA1: 0c0acbebd5c4d201c4080e71f32808bec09ab7fb
SHA256: C084D261AE3A1A86B50DA33C9837ACC25244F3FD47F0538E59934D4D5D68FA1B
File Size: 74.75 KB, 74752 bytes
MD5: 8edac645fa01ef8c803b5d29d770d672
SHA1: 045cc55c2d79caf9739408c971460ca0017f6c5f
SHA256: C16182167E4273899FA539EF71B00A4CF6E947B32E7CDB3D2DB8F7F3B061C624
File Size: 74.75 KB, 74752 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
File Version
  • 9.5.2.4800
  • 9.5.0.4600
  • 9.4.7.4500
  • 9.4.4.4380
Product Version
  • 9.5.2.4800
  • 9.5.0.4600
  • 9.4.7.4500
  • 9.4.4.4380

File Traits

  • x64

Block Information

Total Blocks: 213
Potentially Malicious Blocks: 12
Whitelisted Blocks: 201
Unknown Blocks: 0

Visual Map

x 0 2 0 0 0 0 0 0 0 0 0 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x 0 x x x x x 0 0 0 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 x 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN
Show More
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState

Trending

Most Viewed

Loading...