Threat Database Trojans Trojan.ShellcodeRunner.XB

Trojan.ShellcodeRunner.XB

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 14,761
Threat Level: 80 % (High)
Infected Computers: 15
First Seen: September 13, 2024
Last Seen: December 4, 2025
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.ShellcodeRunner.XB
Signature status: No Signature

Known Samples

MD5: 67809ed9239bcb8bdc2c65105ff34a3d
SHA1: 825c4c3d24d77365d66599c9116e9a31f95320bf
File Size: 97.79 KB, 97792 bytes
MD5: 88f90df84f0a3086c7dec6a7a621988d
SHA1: 811e4d58ed4449eb533e953c5acac81168869cd9
SHA256: 3F109FCDD4EAC0940BBF1F3F200D6344C8E1486364B9E8CE62BDF9D450058D9E
File Size: 91.65 KB, 91648 bytes
MD5: df180b107b16a2336be29916bacb55d0
SHA1: b1d09770a84295250c797314140f894a56b97c6b
SHA256: 08BBEF1CC5D66541BB34BC44C19938498BC32219A9297FA6A23839512AC81B8A
File Size: 95.74 KB, 95744 bytes
MD5: 3ef7debdcfb6147b11fcf895ac423ece
SHA1: 9f44d86f95d6a1db2428f676ceff5992733b6b14
SHA256: 2D03A2C369B475CEE5D1630623F531AB8C3F5EB7D5EA55A0C3A6E44C4A23B017
File Size: 127.49 KB, 127488 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • 2+ executable sections
  • JMC
  • No Version Info
  • x64

Block Information

Total Blocks: 359
Potentially Malicious Blocks: 1
Whitelisted Blocks: 348
Unknown Blocks: 10

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.DGFC
  • Agent.FYM
  • Bladabindi.JBA
  • Exploit.OD
  • HackKMS.LN
Show More
  • Inject.LA
  • Injector.GFDC
  • ReverseShell.XE
  • ShellcodeRunner.LD
  • ShellcodeRunner.LR
  • ShellcodeRunner.XJ
  • ShellcodeRunner.XK
  • Spy.KeyLogger.AUB
  • Trojan.Agent.Gen.CK
  • Trojan.Downloader.Gen.AK

Trending

Most Viewed

Loading...