Threat Database Trojans Trojan.Uwamson.F

Trojan.Uwamson.F

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 22,534
Threat Level: 80 % (High)
Infected Computers: 26
First Seen: August 10, 2021
Last Seen: June 14, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Uwamson.F
Signature status: No Signature

Known Samples

MD5: 115dcf15c9436a63ea156d1b725fd631
SHA1: 07fa0241e2cca0064e4b692a698bac118584762b
SHA256: B5015C2DF00413AD7178B0C4A16DF21D1DD34A8DF61D0054F567EA11BF0749B2
File Size: 39.94 KB, 39936 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name MMC flasher
File Description MODULE 101(005) Renault RH850
Legal Copyright All rights reserved
Product Version 10.005

File Traits

  • dll
  • HighEntropy
  • ntdll
  • x86

Block Information

Total Blocks: 29
Potentially Malicious Blocks: 29
Whitelisted Blocks: 0
Unknown Blocks: 0

Visual Map

x x x x x x x x x x x x x x x x x x x x x x x x x x x x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Uwamson.F

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\07fa0241e2cca0064e4b692a698bac118584762b_0000039936.,LiQMAxHB

Trending

Most Viewed

Loading...