Threat Database Trojans Trojan.SystemBC.A

Trojan.SystemBC.A

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 18,125
Threat Level: 90 % (High)
Infected Computers: 2,233
First Seen: June 24, 2014
Last Seen: November 10, 2025
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.SystemBC.A
Signature status: No Signature

Known Samples

MD5: f8cf4064560064aff327cfea2eb9017a
SHA1: 814fc011d368efd60779564225d49ac6fbba571d
SHA256: 5780C7788362C809BA2C53895B953C61DFCB68660800A20C822C594469E22770
File Size: 16.38 KB, 16384 bytes
MD5: d089c4c45816b4884f96489e94740c4f
SHA1: b33230afcab34d442556209c8a94b2eb53bc642c
SHA256: E6669C5AEC66B050D80AF3C75C62D49E61BF66097250D5CB0D15CF698E0EEC74
File Size: 7.68 KB, 7680 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have resources
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • No Version Info
  • x86

Block Information

Total Blocks: 25
Potentially Malicious Blocks: 9
Whitelisted Blocks: 2
Unknown Blocks: 14

Visual Map

? ? ? x ? x ? ? ? ? ? ? ? x x 0 x x 0 x ? x x ? ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • SystemBC.A

Files Modified

File Attributes
c:\programdata\rfseh\vubvhhi.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\run::socks5 powershell.exe -windowstyle hidden -Command "& 'c:\users\user\downloads\b33230afcab34d442556209c8a94b2eb53bc642c_0000007680'" RegNtPreCreateKey

Windows API Usage

Category API
Network Winsock2
  • WSAStartup
User Data Access
  • GetUserNameEx
Network Winsock
  • closesocket
  • getaddrinfo
  • inet_addr
  • setsockopt
  • socket

Trending

Most Viewed

Loading...