Threat Database Trojans Trojan.Win32.Bublik.cfgi

Trojan.Win32.Bublik.cfgi

By GoldSparrow in Trojans

Threat Scorecard

Threat Level: 90 % (High)
Infected Computers: 505
First Seen: April 2, 2014
Last Seen: September 20, 2026
OS(es) Affected: Windows

Trojan.Win32.Bublik.cfgi is a Trojan that enables cybercriminals to obtain remote unauthorized access and control to the targeted computer system. Trojan.Win32.Bublik.cfgi can install itself onto a PC without a victim's agreement. Trojan.Win32.Bublik.cfgi can take over a variety of system files causing system errors and random crash of the PC. Trojan.Win32.Bublik.cfgi can slow down the computer system and reduce the PC's security. Trojan.Win32.Bublik.cfgi can drop and install extra malware threats onto the corrupted PC. Trojan.Win32.Bublik.cfgi can be hard to find and uninstall from attacked PC.

Analysis Report

General information

Family Name: Trojan.Imwee.A
Signature status: No Signature

Known Samples

MD5: 61ce74f8056792ec2447e6a20347ce02
SHA1: ef639fc67c97cee85a47b093e03a55f95cb6faa6
SHA256: 1973CF99717448A1F5E25DAF7CA0FD910C6A1FE45228934090EB15A20B868B73
File Size: 60.42 KB, 60416 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • No Version Info
  • x86

Block Information

Total Blocks: 173
Potentially Malicious Blocks: 8
Whitelisted Blocks: 165
Unknown Blocks: 0

Visual Map

x x x x x 0 x x x 2 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 3 0 0 0 0 0 0 1 0 0 1 0 0 0 1 0 0 1 0 0 0 2 2 0 0 1 0 0 0 1 1 1 0 1 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 1 1 0 0 0 0 1 0 0 0 0 2 0 0 1
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Network Wininet
  • HttpOpenRequest
  • HttpQueryInfo
  • HttpSendRequest
  • InternetConnect
  • InternetOpen
Network Winhttp
  • WinHttpOpen