Threat Database Trojans Trojan.Runner.C

Trojan.Runner.C

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 19,569
Threat Level: 80 % (High)
Infected Computers: 20
First Seen: December 23, 2023
Last Seen: November 11, 2025
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Runner.C
Signature status: No Signature

Known Samples

MD5: 051ae8d34888c01d0bc1da2d957e204e
SHA1: 939bb5dc4d116dc9603e649cadac113144591547
SHA256: D533BDECD4185C813CB1BE531515EFA3700D5AFF28F29AD8298EA453BF217492
File Size: 2.70 MB, 2702848 bytes
MD5: f9691f1965a2720a4e7423bc457694d0
SHA1: 3aef28201b88551e76679619e11257e96e8a54ac
SHA256: 0D32E0578A6DB0B4A766B64A19C75AF49D9388753C9500564A45FFEEB83CE3E5
File Size: 3.77 MB, 3771012 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments
  • Online learning platform for comprehensive skill development.
  • This installation was built with Inno Setup.
Company Name
  • GS Software
  • SkillForge360
File Description
  • GS Backup Setup
  • Online learning platform for comprehensive skill development.
File Version
  • 4.1569.3.604089
  • 3.0
Internal Name SkillForge360
Legal Copyright Copyright © Forge360 Skills Technologies Inc. 2014
Product Name
  • GS Backup
  • SkillForge360
Product Version
  • 4.1569.3.604089
  • 3.0

File Traits

  • 2+ executable sections
  • HighEntropy
  • VirtualQueryEx
  • x86

Files Modified

File Attributes
c:\users\user\appdata\local\temp\is-09f6c.tmp\3aef28201b88551e76679619e11257e96e8a54ac_0003771012.tmp Generic Write,Read Attributes

Windows API Usage

Category API
User Data Access
  • GetUserObjectInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess

Shell Command Execution

"C:\Users\Olmsxfrh\AppData\Local\Temp\is-09F6C.tmp\3aef28201b88551e76679619e11257e96e8a54ac_0003771012.tmp" /SL5="$70028,3364000,121344,c:\users\user\downloads\3aef28201b88551e76679619e11257e96e8a54ac_0003771012"

Trending

Most Viewed

Loading...