Threat Database Trojans Trojan.Shiz.W

Trojan.Shiz.W

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 14,384
Threat Level: 80 % (High)
Infected Computers: 13
First Seen: October 24, 2022
Last Seen: August 7, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Shiz.W
Signature status: No Signature

Known Samples

MD5: 4c0ce2bfdf8b9e80c2b77e9ee7931909
SHA1: 8c2ab6aa91ea367c4d8df1cf097f657362ca98e6
SHA256: 6888172033B07A185F54142D07E005980E3EF43F04CB5BB8341609616E2C9D78
File Size: 220.16 KB, 220160 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
1 Kaspersky™ Anti-Virus ® is registered trademark of Kaspersky Lab ZAO.
Company Name Kaspersky Lab ZAO
File Description Net configurator
File Version 8.7.5.4
Internal Name netcfg
Legal Copyright © 1997-2010 Kaspersky Lab ZAO.
Product Name Kaspersky Anti-Virus
Product Version 2.1.7.8

File Traits

  • HighEntropy
  • x86

Block Information

Total Blocks: 8
Potentially Malicious Blocks: 6
Whitelisted Blocks: 2
Unknown Blocks: 0

Visual Map

x x 0 x x x 0 x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Shiz.W

Files Modified

File Attributes
\device\namedpipe\acsipc_server Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files (x86)\windows defender\galyqaz.com Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files (x86)\windows defender\galyqaz.com Synchronize,Write Attributes
c:\program files (x86)\windows defender\lymyxid.com Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files (x86)\windows defender\lymyxid.com Synchronize,Write Attributes
c:\program files (x86)\windows defender\lysyfyj.com Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files (x86)\windows defender\lysyfyj.com Synchronize,Write Attributes
c:\program files (x86)\windows defender\qetyfuv.com Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files (x86)\windows defender\qetyfuv.com Synchronize,Write Attributes
c:\program files (x86)\windows defender\vocyzit.com Generic Read,Write Data,Write Attributes,Write extended,Append data
Show More
c:\program files (x86)\windows defender\vocyzit.com Synchronize,Write Attributes
c:\program files (x86)\windows defender\vonypom.com Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files (x86)\windows defender\vonypom.com Synchronize,Write Attributes
c:\programdata\prevxcsi\csidb.csi Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\2d7f.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\2d7f.tmp Synchronize,Write Data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\103621de9cd5414cc2538780b4b75751 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\1b1495dd322a24490e2bf2faabae1c61 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\22d536c4b4ad2cef7ac6b7789fd235e3 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\52ae0202861c1a0fbe61cc3285c206ce Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\8b2b9a00839eed1dfdccc3bfc2f5df12 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\b46811c17859ffb409cf0e904a4aa8f8 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\e8e3be54280f7fc6822a95e8e7db113a Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\103621de9cd5414cc2538780b4b75751 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\1b1495dd322a24490e2bf2faabae1c61 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\22d536c4b4ad2cef7ac6b7789fd235e3 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\52ae0202861c1a0fbe61cc3285c206ce Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\8b2b9a00839eed1dfdccc3bfc2f5df12 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\b46811c17859ffb409cf0e904a4aa8f8 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\e8e3be54280f7fc6822a95e8e7db113a Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\apppatch\svchost.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\apppatch\svchost.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144

Registry Modifications

Key::Value Data API Name
HKCU\local settings\muicache\1b\52c64b7e::@c:\windows\system32\firewallcontrolpanel.dll,-12122 Windows Defender Firewall RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\winlogon::be6cf229 C:\WINDOWS\apppatch\svchost.exe RegNtPreCreateKey
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations *1\??\C:\Windows\SystemTemp\MicrosoftEdgeUpdate.exe.old5af52*1\??\C:\Windows\SystemTemp\CopilotUpdate.exe.old5af62*1\??\C:\P RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\winlogon::be6cf229 C:\WINDOWS\apppatch\svchost.exe RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\content::cacheprefix RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\cookies::cacheprefix Cookie: RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\history::cacheprefix Visited: RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
Show More
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey

Windows API Usage

Category API
Network Winsock2
  • WSAStartup
Process Manipulation Evasion
  • NtUnmapViewOfSection