Threat Database Trojans Trojan:Win32/Joinkjot.A

Trojan:Win32/Joinkjot.A

By GoldSparrow in Trojans

Threat Scorecard

Popularity Rank: 12,908
Threat Level: 90 % (High)
Infected Computers: 70
First Seen: September 18, 2014
Last Seen: August 7, 2026
OS(es) Affected: Windows

Trojan:Win32/Joinkjot.A is a Trojan horse that may be similar to other threats designed to obtain logins to online accounts. Trojan:Win32/Joinkjot.A may uses aggressive money extortion techniques and other methods to ultimately gain money from unsuspecting computer users or allow a remote attacker access to the infected computer. Those who may encounter the Trojan:Win32/Joinkjot.A Trojan on their computer are highly advised to remove it immediately using antispyware software. Removal of Trojan:Win32/Joinkjot.A will ensure your system and stored data is not compromised by an unknown hacker that seeks to gather data from infected computers. Use of that information can lead to serious issues like identity theft.

Analysis Report

General information

Family Name: Trojan.Upatre.VE
Signature status: No Signature

Known Samples

MD5: b617e182e5369bfa9f2b83f34acb7e06
SHA1: 3cba5feea52afa51734222adae31f8bda862e2f8
SHA256: 37F2918EEF6884B7AEFA713BB57C0E72F529818CF8D4C71D29A9A877B52A8E32
File Size: 34.98 KB, 34984 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • No Version Info
  • x86

Block Information

Total Blocks: 8
Potentially Malicious Blocks: 5
Whitelisted Blocks: 2
Unknown Blocks: 1

Visual Map

0 ? 0 x x x x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Upatre.VE

Files Modified

File Attributes
c:\users\user\appdata\local\temp\ppl32.exe Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �n7� �v xy������!wz#��%:�(�1`1�1HO>3�@V�A��J��X�_�zb"hi��k`k�qrnJu�~w�n{b����P��{�������b:���������6��h �a �n��F��m�Ù�ͪ�gi�t�������$�8წ���&M�`��oA�=� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �n8� �v xy������!wz#��%:�(�1`1�1HO>3�@V�A��J��X�_�zb"hi��k`k�qrnJu�~w�n{b����P��{�������b:���������6��h ���a �n��F��m�Ù�ͪ�gi�t�������$�8წ���&M�`��oA� RegNtPreCreateKey
Show More
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 鴵ȁ獖}鰚² RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �n=� �v xy������!wz#��%:�(�1`1�1HO>3�@V�A��J��X�_�zb"hi��k`k�qrnJu�~w�n{b����P��{�����7����M�b:���������6��h ���a �n��F��m�Ù��IVͪ�gi�t�������$�8წ���&M�`�(! RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection