Threat Database Trojans Trojan.ShellcodeRunner.YA

Trojan.ShellcodeRunner.YA

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 14,769
Threat Level: 80 % (High)
Infected Computers: 39
First Seen: April 17, 2024
Last Seen: June 8, 2026
OS(es) Affected: Windows

The detection of Trojan.ShellcodeRunner.YA on your system indicates a potential security threat that requires immediate attention. This report aims to provide you with essential information about the nature of this threat, its operational characteristics, symptoms of infection, and most importantly, steps to remove it from your computer.

What Is Trojan.ShellcodeRunner.YA?

Trojan.ShellcodeRunner.YA is identified as a Trojan-type threat. Trojans are malicious programs that can allow unauthorized access to a computer, leading to various forms of cyber attacks, including data theft, spyware installation, and further malware distribution. The name suggests it might be involved in running shellcode, which is a small piece of code used as the payload in the exploitation of a software vulnerability. It's crucial to understand that Trojans can be highly versatile and may not always be easily detectable, making them particularly dangerous.

How Trojan.ShellcodeRunner.YA Operates

While specific details about Trojan.ShellcodeRunner.YA's operation are not available, Trojans generally operate by disguising themselves as legitimate software. Once installed, they can create backdoors, allowing remote access to the infected computer. This access can be used for a variety of malicious purposes, including stealing sensitive information, installing additional malware, or using the infected computer as part of a botnet for distributed denial-of-service (DDoS) attacks or spamming. The ability to run shellcode implies it could exploit vulnerabilities in software to execute malicious code, potentially leading to a range of harmful activities.

Symptoms of Infection

Symptoms of a Trojan infection can vary widely depending on the specific goals of the malware. Common indicators include unusual system behavior, such as slow performance, frequent crashes, or unfamiliar programs and icons. You might also notice increased network activity, even when you're not using the internet, or receive notifications about applications trying to access the internet without your knowledge. Sometimes, Trojans may not exhibit obvious symptoms, making them difficult to detect without proper security software.

How to Remove Trojan.ShellcodeRunner.YA

  1. Enter Safe Mode with Networking: This will help prevent the malware from loading and give you a cleaner environment to work in. The process to enter Safe Mode varies depending on your operating system version.
  2. Perform a Full Scan with a Reputable Tool: Use a well-regarded anti-malware tool, such as SpyHunter, to perform a full scan of your system. This can help identify and remove the Trojan and any other malware that might be present.
  3. Uninstall Suspicious Programs: Go through your installed programs and remove any that you don't recognize or that were installed around the time you suspect the infection occurred.
  4. Reset Your Web Browsers: Trojans can sometimes install malicious extensions or alter browser settings. Resetting browsers like Chrome, Firefox, or Edge to their default settings can help remove these changes.
  5. Reboot and Re-scan: After taking these steps, reboot your computer and perform another full scan with your anti-malware tool to ensure that the threat has been fully removed.

Conclusion

Removing Trojan.ShellcodeRunner.YA requires careful and immediate action to prevent further damage to your system and protect your personal data. By following the steps outlined above and maintaining good security practices, such as regularly updating your software and being cautious with emails and downloads, you can significantly reduce the risk of future infections. Remember, the key to dealing with malware is vigilance and prompt action.

Analysis Report

General information

Family Name: Trojan.ShellcodeRunner.YA
Signature status: No Signature

Known Samples

MD5: 771b5d296a27175fc37aad43b6976a94
SHA1: 657247313cec67db9476e96d7e35e8d8cbca485f
SHA256: 5D452B9F9B866A41F8931B26E4DAEE570625F99207244560AE4D5549779B7E22
File Size: 1.71 MB, 1711634 bytes
MD5: 6206ec11cd3d7eb84f3ea840b5ff3814
SHA1: f7c04c96eec236bf803f5ff482a259713515cf8f
SHA256: 4DE296C98BB3D554122F4B366F17A0E14119D3EC48348AD839D748888DAF0C66
File Size: 2.55 MB, 2549080 bytes
MD5: 6ce3b0925eea2437e62ea93c35830a98
SHA1: f6e737f04c523d7f2779a919d154b52e2fd5a079
SHA256: 7E2C42D3737D33974978EC7A838A81C7372CAFE6515E15452BCB3CC70560CBB2
File Size: 3.30 MB, 3297944 bytes
MD5: 1a4eddbe37f9458feb2d0ffe0817a084
SHA1: 8e6972d9848e12fc79361d55392f95f269c07ddf
SHA256: 0A3DAB7F6AD5F1E03EB1029FFDA5D6BBBBF38EE228631FC4B7CCCADDA77697C0
File Size: 1.98 MB, 1980760 bytes
MD5: 61677f2db268d706597c7fe499089474
SHA1: 17c0a4dcd6a046e7936461d424a01228533a2367
SHA256: C6BAE1F06E7EDC1E89621FF12AD9F55182F9D957FB11D2DB7672C313D307927A
File Size: 10.00 MB, 9997312 bytes
Show More
MD5: 5732035f2d098b01805ba041e0b8e1ff
SHA1: 511e5c49dee85895ee11f492549d4cafd71083e2
SHA256: 690E800B3BF16102E2285DA6CA831221D141DD818763ECA3CEAE9DDAE009F893
File Size: 130.32 KB, 130323 bytes
MD5: b0638a2c1ef0391dd98b85d3ed046fbe
SHA1: e3588c702aed97b0a5ec9f5cc91114124c110b75
SHA256: 493229EA3495043838127F428BDCCD493CF50E9E8BA6528516F2D0942EC4CD89
File Size: 926.21 KB, 926208 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have resources
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
Show More
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • Matías Israelson (AKA: El_isra)
  • Python Software Foundation
File Description
  • color changer for windows CMD
  • POPS VCD Manager
  • Python Core
File Version
  • 3.6.3
  • 1, 3, 7, 1
  • 1, 0, 16, 87
Internal Name
  • DiagBox
  • POPSVCDMan
  • Python DLL
Legal Copyright Copyright © 2001-2016 Python Software Foundation. Copyright © 2000 BeOpen.com. Copyright © 1995-2001 CNRI. Copyright © 1991-1995 SMC.
Original Filename
  • DiagBox.exe
  • POPS-VCD-Manager.EXE
  • python36.dll
Product Name
  • Dialog box
  • POPS VCD Manager
  • Python
Product Version
  • 3.6.3
  • 1, 3, 7, 1
  • 1, 0, 16, 87

Digital Signatures

Signer Root Status
Python Software Foundation Microsoft Identity Verification Root Certificate Authority 2020 Hash Mismatch
Python Software Foundation StartCom Class 3 Object CA Hash Mismatch

File Traits

  • big overlay
  • dll
  • HighEntropy
  • No Version Info
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 7,449
Potentially Malicious Blocks: 426
Whitelisted Blocks: 7,003
Unknown Blocks: 20

Visual Map

0 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 0 0 0 0 ? ? ? ? x 0 ? 0 0 0 0 0 0 0 ? ? ? 0 ? ? 0 0 ? ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x 0 x 0 x x 0 x 0 x 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 x x x x 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 x x 0 0 0 0 0 0 0 0 0 x x x x x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x x x x x x x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x x x 0 0 0 x 0 0 0 x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 x 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x x x x x 0 x 0 0 x x x x 0 0 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 0 x x 0 x 0 x 0 x 0 0 0 0 0 0 x x 0 x 0 x x 0 x 0 0 0 0 x 0 x x 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x x 0 0 x x x x x 0 0 0 0 0 0 0 0 x x 0 0 x x 0 x 0 0 0 x 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x x x x 0 0 0 0 x x x 0 0 x 0 0 x x 0 x 0 x x x 0 0 x 0 x x x x x 0 0 0 x 0 x x 0 x 0 0 x 0 0 0 x 0 0 x 0 x 0 x x 0 0 0 0 x 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x x 0 x x x 0 0 x 0 x 0 x x x 0 0 x 0 0 x x x x x x 0 x 0 x x 0 0 x 0 x 0 x 0 x x x 0 0 0 0 0 0 x 0 x 0 0 0 x 0 0 x x 0 x x x x 0 0 x x 0 0 0 0 0 x 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 x x 0 x x x 0 0 0 x x 0 0 x x 0 0 x 0 0 0 0 x 0 0 x 0 x x 0 0 x x x x 0 x x x x 0 x 0 0 0 0 0 0 0 0 x x x x 0 0 0 x 0 x x x 0 0 x 0 x x x 0 x 0 0 x 0 x x x x x x x 0 x 0 0 0 x 0 x 0 0 x x 0 x 0 x x 0 x 0 0 0 0 0 0 0 x 0 0 x 0 x 0 x 0 0 0 0 x x 0 x 0 x 0 0 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.JC
  • BadJoke.UC
  • Pinkslipbot.A
  • ShellcodeRunner.YA
  • Small.N
Show More
  • Spy.Agent.GF

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtProtectVirtualMemory
Show More
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection
Other Suspicious
  • SetWindowsHookEx

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\f7c04c96eec236bf803f5ff482a259713515cf8f_0002549080.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\f6e737f04c523d7f2779a919d154b52e2fd5a079_0003297944.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\8e6972d9848e12fc79361d55392f95f269c07ddf_0001980760.,LiQMAxHB

Trending

Most Viewed

Loading...