Threat Database Trojans Trojan.Shiz.O

Trojan.Shiz.O

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 12,997
Threat Level: 80 % (High)
Infected Computers: 32
First Seen: February 7, 2022
Last Seen: August 7, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Shiz.O
Signature status: No Signature

Known Samples

MD5: 063c95c6bb9c322d21955990b060aeef
SHA1: 01472a1b074acdd06939edd38e3f9aa3dfd1a615
SHA256: 587F319734C462FD6E0992F74B2AEAD885861EE503ED30B17D4F83E2834B0A32
File Size: 379.90 KB, 379904 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have resources
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • No Version Info
  • ntdll
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 1,234
Potentially Malicious Blocks: 966
Whitelisted Blocks: 268
Unknown Blocks: 0

Visual Map

x x x x x x x x x x x x x x x x 0 x x 0 x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x 0 x 0 0 x x x x x x x x x x x x x x x x x x 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x x x x x x x x x x x 0 x 0 x x x x x x x x x x x x x x x x x x 0 x x x x x 0 x x x x x x 0 x x x x x x x x x x x x x x x x x 0 x x x x x x x 0 x x x x x x x x x x x x x 0 0 x x 0 x x x x x x x x x x x x x x x 0 x x x x 0 x x x x 0 x x x x x x x x x x x 0 x x 0 x x x x x x x x x x x x x x x x x x 0 0 0 0 0 0 0 x x x x x x x x x x x x x x 0 x 0 x x 0 x x x x x x x x x x x x x x x x x x x x x x 0 0 x x x x x x x x x x 0 x x x x 0 0 x 0 x x x x x x x x x x x x 0 x x x x x x x x x 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 x x 0 x x x x 0 x x 0 x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x 0 x x x x x x x x x x x 0 x x x x x 0 x x 0 x x x 0 0 x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 x x x x x x x x x x x x 0 x x 0 x x 0 x x x x 0 x x 0 x x x x x x x x x x 0 x x 0 x x x 0 x x x 0 x 0 x x x x x x x x x x x 0 x x x x x x x x x 0 x x x x x x 0 x x 0 x x x x x 0 x x x x 0 x x x x x 0 x x 0 x x x x x 0 x x x x x 0 x x 0 x 0 x 0 x x x x 0 x x 0 x x x x x x x 0 x x x x 0 x x 0 x 0 x x 0 x 0 x x x x x x x x 0 x 0 x 0 x 0 x 0 x x x 0 x x 0 x x 0 x 0 x x x x 0 0 x 0 x x x x x x x x x x x x x x x x 0 x x x x x x x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 x x 0 x x x x 0 x 0 x x x x 0 0 0 x 0 x 0 0 x x x x 0 0 0 0 0 x 0 x 0 x x x x 0 x x x 0 x 0 x 0 x x x x x x x x x x x 0 x x x x x x x x x x 0 0 x x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x x 0 x x x x x x 0 x x x x x x 0 x x x x x x x x 0 x x x x x x x x x x x x x x x 0 x x 0 0 x 0 0 x x x 0 0 0 x x x x x x x x x x x x x x 0 0 0 0 0 0 0 0 x x x x x 0 0 0 0 0 0 0 0 x x x x x 0 0 0 0 0 0 0 0 x x x x x x x x x x x x x x x x x x x x x 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 x x x x 0 0 x x x x x x x x x x x x x x x x x x x x 0 x x 0 0 x x 0 0 x x x x 0 x x x x x x x x x 0 x x x 0 x 0 0 x x x x x x x x x x 0 x x x x x x x x 0 x x 0 0 x 0 x x x x x x 0 x x x 0 x x 0 0 x 0 x x x x x x 0 x x x 0 x x x x x 0 x x x x x 0 x x x x x 0 x x x x x 0 x x x x x x x 0 x x x x x 0 x x x x x x x 0 x x x x x x x x x x x x 0 x x x x x x x x x 0 0 x x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x x 0 x x x x 0 0 0 0 0 0 0 0 0 0 x x x 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Shiz.D
  • Shiz.O

Files Modified

File Attributes
\device\namedpipe\acsipc_server Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\programdata\prevxcsi\csidb.csi Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\3fef.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\3fef.tmp Synchronize,Write Data
c:\windows\apppatch\svchost.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\apppatch\svchost.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows nt\currentversion\winlogon::be6cf229 &«þãSÒK@‚,Ö¹nŸâÏ ×òÁ_ÇüZ Ô>x< ªJdü'¬¬ôZŠ´ò ¼º4"ˆ2 tà'?xN<Ÿ’<¬îZ¼"‚‚œ(dÔtrºj¦ê ¤T\ˆÚœt2ÜêFJ$äPäâr.Ä'”ÒÒL² RegNtPreCreateKey
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations *1\??\C:\Windows\SystemTemp\MicrosoftEdgeUpdate.exe.old122e4*1\??\C:\Windows\SystemTemp\CopilotUpdate.exe.old12352*1\??\C:\P RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �n$ �v ������(�1`1�1HO@V�A��H[uU_*_�zb"hk`k�ql(�w�n{b��P��������������.���m�Ù��'N����=��$�8წ���&M�=�SB1_T�Vw��R���%�������AE�zH�Q]��D��&��$���L RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\winlogon::be6cf229 &«þãSÒK@‚,Ö¹nŸâÏ ×òÁ_ÇüZ Ô>x< ªJdü'¬¬ôZŠ´ò ¼º4"ˆ2 tà'?xN<Ÿ’<¬îZ¼"‚‚œ(dÔtrºj¦ê ¤T\ˆÚœt2ÜêFJ$äPäâr.Ä'”ÒÒL² RegNtPreCreateKey

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserName
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • VirtualAllocEx
Process Shell Execute
  • CreateProcess

Shell Command Execution

C:\WINDOWS\apppatch\svchost.exe (NULL)