Threat Database Trojans Trojan.Vundo.J

Trojan.Vundo.J

By CagedTech in Trojans

Threat Scorecard

Threat Level: 90 % (High)
Infected Computers: 68
First Seen: July 24, 2009
Last Seen: February 3, 2026
OS(es) Affected: Windows

Aliases

15 security vendors flagged this file as malicious.

Antivirus Vendor Detection
Symantec Packed.Generic.217
Sunbelt Trojan.Win32.Vundo.Gen (v)
Panda Trj/CI.A
NOD32 a variant of Win32/Kryptik.MU
Kaspersky Packed.Win32.Krap.n
Fortinet W32/Krap.N!tr
F-Secure Trojan:W32/Vundo.gen!A
eTrust-Vet Win32/VundoCryptorAF!generic
CAT-QuickHeal Win32.Packed.Krap.n.6
BitDefender Gen:Trojan.Heur.Vundo.7018E7D7D7
AVG Generic13.AQSC
Avast Win32:MoPack
Authentium W32/Virtumonde.AH2.gen!Eldorado
Antiy-AVL Packed/Win32.Krap
a-squared Trojan.Win32.Vundo!IK

SpyHunter Detects & Remove Trojan.Vundo.J

File System Details

Trojan.Vundo.J may create the following file(s):
# File Name MD5 Detections
1. oxlwyr.dll 2fc45cd304021afc18c3940e44d8d653 0
2. foenvj.dll 47807b23779807efcc0bb5c5e3df4f28 0
3. rnfxhe.dll 24f4d9d7b70f2b98c4b588851b37099f 0
4. uwapvk.dll 35308a5772a06d6eb96ed150391f05a0 0

Analysis Report

General information

Family Name: Trojan.Vundo.J
Signature status: No Signature

Known Samples

MD5: 4b4ed4f2b9edf92a6d64c0a7f40c3e09
SHA1: 15ec737eee7afeeb14997338c7d6590c5c84b0d7
SHA256: D611D03C6A1F97BB96B1C66E99710993B48A9426D2DFDAC00AFA09A05DE7B988
File Size: 37.89 KB, 37888 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have resources
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • 2+ executable sections
  • dll
  • ntdll
  • VirtualQueryEx
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 71
Potentially Malicious Blocks: 63
Whitelisted Blocks: 5
Unknown Blocks: 3

Visual Map

x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x ? x x x x x ? x x x ? x x x x x x x x x x x 0 x 0 x x x x x 0 0 x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Vundo.J

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\15ec737eee7afeeb14997338c7d6590c5c84b0d7_0000037888.,LiQMAxHB

Related Posts

Trending

Most Viewed

Loading...