Threat Database Trojans Trojan.Ursnif.DB

Trojan.Ursnif.DB

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 13,822
Threat Level: 80 % (High)
Infected Computers: 11
First Seen: June 12, 2022
Last Seen: December 12, 2025
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Ursnif.DB
Signature status: No Signature

Known Samples

MD5: d6ef63245a9f52bc1cb434f09a24a5bd
SHA1: b3584f9f994ec61442fdf2dbacda60ff60fb0915
SHA256: CEDCC35DE25BDD5B64B08D75255EB4DAB73C64C2F0CB000C24F2B7783A247BC9
File Size: 1.54 MB, 1544016 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Node.js
File Description Node.js JavaScript Runtime
File Version 18.16.0
Internal Name node
Legal Copyright Copyright Node.js contributors. MIT license.
Original Filename node.exe
Product Name Node.js
Product Version 18.16.0

File Traits

  • 2+ executable sections
  • big overlay
  • HighEntropy
  • MPRESS
  • MPRESS Win32
  • Native MPRESS x86
  • Node.js
  • packed
  • x86

Block Information

Total Blocks: 3
Potentially Malicious Blocks: 0
Whitelisted Blocks: 2
Unknown Blocks: 1

Visual Map

? 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • CoinMiner.BB
  • Emotet.AAJ
  • Emotet.AAL
  • Kryptik.FHE
  • Tofsee.BP
Show More
  • Upatre.WIA

Trending

Most Viewed

Loading...