Threat Database Trojans Trojan.ShellcodeRunner.HCA

Trojan.ShellcodeRunner.HCA

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 14
First Seen: October 13, 2025
Last Seen: July 20, 2026
OS(es) Affected: Windows

The detection of Trojan.ShellcodeRunner.HCA indicates that your system has been compromised by a potentially malicious threat. This type of threat is generally categorized as a Trojan, which is a broad term for malware that disguises itself as legitimate software. Trojans can have various functions and goals, ranging from data theft to providing unauthorized access to the infected system. Understanding the nature and behavior of Trojan.ShellcodeRunner.HCA is crucial for taking appropriate measures to secure your system and protect your data.

What Is Trojan.ShellcodeRunner.HCA?

Trojan.ShellcodeRunner.HCA, as detected by security software, suggests a type of malware designed to execute shellcode, which is a small piece of code used to exploit vulnerabilities in software. The term "Trojan" refers to the method of delivery rather than a specific malware family, implying that the threat is disguised as something benign to trick users into installing it. The ".HCA" suffix might indicate a specific variant or a designation used by the security software to categorize the threat. Understanding that Trojans are versatile and can be used for a wide range of malicious activities, from stealing sensitive information to installing additional malware, is essential for grasping the severity of the infection.

How Trojan.ShellcodeRunner.HCA Operates

The operation of Trojan.ShellcodeRunner.HCA involves exploiting system vulnerabilities to execute malicious code. Once installed, it can run in the background, potentially evading detection by traditional security measures. The primary goal of such malware can vary but often includes creating a backdoor for remote access, stealing personal data, or using the infected system's resources for malicious activities like cryptocurrency mining or spam distribution. The ability of Trojans to adapt and evolve, sometimes through updates or by downloading additional components, makes them particularly challenging to eradicate without comprehensive security tools.

Symptoms of Infection

Symptoms of a Trojan.ShellcodeRunner.HCA infection can be subtle and may not always be immediately apparent. Common indicators include unusual system behavior, such as slow performance, frequent crashes, or unfamiliar programs running in the background. Additionally, users might notice increased network activity, even when no applications that require internet access are running. In some cases, the malware might attempt to communicate with its command and control servers, which could be detected by network monitoring tools. Recognizing these symptoms early can help in mitigating the damage caused by the malware.

How to Remove Trojan.ShellcodeRunner.HCA

  1. Boot your system into Safe Mode with Networking to limit the malware's ability to interfere with the removal process.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all components of the Trojan.
  3. Uninstall any suspicious programs that were installed around the time the malware was detected, as these could be related to the infection.
  4. Reset your web browsers (Chrome, Firefox, Edge) to their default settings to remove any malicious extensions or settings that the malware might have altered.
  5. Reboot your system and perform another full scan to ensure that all remnants of the malware have been removed.

Conclusion

Removing Trojan.ShellcodeRunner.HCA requires a thorough approach to ensure that all components of the malware are eradicated from the system. By understanding the nature of Trojans and the potential risks they pose, users can take proactive steps to protect their systems and data. Regularly updating security software, being cautious with email attachments and downloads, and using strong, unique passwords can significantly reduce the risk of infection. In the event of a detection, following a systematic removal process, as outlined, can help in securely removing the threat and restoring system integrity.

Analysis Report

General information

Family Name: Trojan.ShellcodeRunner.HCA
Signature status: Hash Mismatch

Known Samples

MD5: 95218820ee42163e02f0fc0c08953632
SHA1: 3c8ad27e1bfafdf086177b76ecb224c2bbfa5e42
SHA256: 4938AFD67F03AE5F444F957A6292DE6C9C4A775A3F887B6ECD888237ECFA016D
File Size: 3.34 MB, 3343872 bytes
MD5: 5a43f6a4c485775926f2ac69db10c70e
SHA1: 07b0459d283794cbbf35aba4de78f00ba708a804
SHA256: E4B82972F20680EA807C60F99690810C6AAC71ECD64C2A22F982255AB95B48FA
File Size: 2.67 MB, 2671616 bytes
MD5: 499a070b985d54f3bada7efc024f8e83
SHA1: 97bba7d8dbbe28477b5d8db242b67dd52b85ef06
SHA256: 80D8450925814642716A01DAE63F4EBD68F4774108F507A14E1786C13D6A41D1
File Size: 2.64 MB, 2641920 bytes
MD5: c8962d0006dfa8aeaa8bac30e87d6db1
SHA1: 8e77cf304453bfc0d91061fe226da4911a5da37b
SHA256: EB1F0630EBF2748F520FE2582DCDD262E1EFB73B59DE1566AFE30A26E4E31C00
File Size: 2.73 MB, 2732032 bytes
MD5: 3d5bf24ab9b318e0df0a37c9539278d3
SHA1: 6e0af01d3ba0ae4ba3869f94e92fcdce96d2c062
SHA256: 39AE6E88A57495CEE6379CAF6D1A2CB5632DFDAE66FC9149239415E6F1EB6290
File Size: 2.72 MB, 2722816 bytes
Show More
MD5: f77c8fb7119909ae66b395f764fe76e6
SHA1: e4e63c0a4e7fd4953404373bdd810a52b7987822
SHA256: C316D0D92F65A4EA76D9B128B5EF79FEC2EAEA5025FB7F1E009C99424B11E8F6
File Size: 3.40 MB, 3397632 bytes
MD5: df1bda85eae0d850440d1c557fc4e7bb
SHA1: 2340d4dc74a3db8b912edb4a3ce605e5460f4c86
SHA256: DE2092E6E17E2E35A206B306E3E05B47732C3358F3C8BC96CB2B06936AA88D7A
File Size: 2.18 MB, 2184192 bytes
MD5: 2b21c894f844fdc9271d694f26bdbb10
SHA1: 873e9080962c71d855c2603d7a2357c52de9d69f
SHA256: D7F1C100CCCEAC4A998C57B1EB82423231A17DAB2B99F91EBC371A8A2AF86878
File Size: 3.28 MB, 3277888 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have resources
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name
  • Base Smart Inc
  • Global Digital Corp
  • Info Innovation Systems
  • Prime Tech Global Ltd
  • Quantum Logic Technologies
  • Solutions Meta Corp
  • Ultra Root Solutions
File Description
  • Explorer Plus
  • Full ML Compiler
  • Generator Reliable Generator Stack
  • Mega Engine Plus
  • ML Rapid Processor
  • Pro Extended Finder Quality
  • Queue Editor Ultimate
File Version
  • 20.7.98.2436
  • 13.1.11.4759
  • 9.4.63.6020
  • 8.7.7.3672
  • 6.7.53.6197
  • 4.7.59.5644
  • 3.1.94.9831
Internal Name
  • accuracy_trusted_future
  • certified_compiler_instant
  • concurrent_easy_encrypted
  • extended_network_machine
  • full_universal_distributed
  • hyper_quantum_engine
  • reliable_storage_standard
Legal Copyright
  • Copyright (C) 2020 Ultra Root Solutions
  • Copyright (C) 2021 Base Smart Inc
  • Copyright (C) 2022 Prime Tech Global Ltd
  • Copyright (C) 2022 Quantum Logic Technologies
  • Copyright (C) 2022 Solutions Meta Corp
  • Copyright (C) 2023 Global Digital Corp
  • Copyright (C) 2025 Info Innovation Systems
Original Filename
  • accuracy_trusted_future.exe
  • certified_compiler_instant.exe
  • concurrent_easy_encrypted.exe
  • extended_network_machine.exe
  • full_universal_distributed.exe
  • hyper_quantum_engine.exe
  • reliable_storage_standard.exe
Product Name
  • Accuracy Trusted Future Assembler
  • Certified Compiler Instant Detector
  • Concurrent Easy Encrypted Editor
  • Extended Network Machine Exceptional Searcher
  • Full Universal Distributed Reader
  • Hyper Quantum Engine Memory Editor
  • Reliable Storage Standard Builder
Product Version
  • 20.7.98.2436
  • 13.1.11.4759
  • 9.4.63.6020
  • 8.7.7.3672
  • 6.7.53.6197
  • 4.7.59.5644
  • 3.1.94.9831

Digital Signatures

Signer Root Status
Microsoft Corporation Microsoft Code Signing PCA 2011 Hash Mismatch

File Traits

  • dll
  • golang
  • HighEntropy
  • x64

Block Information

Total Blocks: 5,344
Potentially Malicious Blocks: 1,261
Whitelisted Blocks: 3,970
Unknown Blocks: 113

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.KFTA
  • Kryptik.FSK
  • Kryptik.KFT
  • Quasar.SA
  • Reconyc.FI
Show More
  • ShellcodeRunner.HCA
  • Trojan.ShellcodeRunner.Gen.AQ
  • Trojan.ShellcodeRunner.Gen.AR
  • Trojan.ShellcodeRunner.Gen.DP
  • Trojan.ShellcodeRunner.Gen.FC
  • Trojan.ShellcodeRunner.Gen.GV

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �l 1HO@V�y�^�P�����m���p�$�[�`�V����Q]��@K� RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtAlpcSetInformation
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateIoCompletion
Show More
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRemoveIoCompletionEx
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimerEx
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtYieldExecution
  • UNKNOWN

Trending

Most Viewed

Loading...