Threat Database Worms Worm:Win32/Morto.A

Worm:Win32/Morto.A

By JubileeX in Worms

Threat Scorecard

Popularity Rank: 15,181
Threat Level: 50 % (Medium)
Infected Computers: 4,218
First Seen: August 30, 2011
Last Seen: February 4, 2026
OS(es) Affected: Windows

Worm:Win32/Morto.A is a malicious worm that allows attackers obtain unauthorized access to a compromised PC system. Worm:Win32/Morto.A spreads by attempting to attack administrator passwords for Remote Desktop connections on the network. Worm:Win32/Morto.A corrupts PC systems that have weak passwords. Worm:Win32/Morto.A is also able to download and install other malware threats. Worm:Win32/Morto.A consists of some components that include an executable dropper component (the installer) and a DLL component, which executes the payload. Worm:Win32/Morto.A copies itself by using other parasites like Trojan.DownLoader4.48720 or Trojan horse Generic24.OJQ. Worm:Win32/Morto.A will connect to a remote server without its victim's awareness and will block you from using all anti-virus software to evade detection and deletion. You should delete Worm:Win32/Morto.A from the affected machine immediately after detection.

File System Details

Worm:Win32/Morto.A may create the following file(s):
# File Name Detections
1. %windows%\temp\ntshrui.dll
2. %Windows%\clb.dll
3. \sens32.dll
4. %Windows%\clb.dll.bak
5. c:\windows\offline web pages\cache.txt

Analysis Report

General information

Family Name: Worm.Runouce.A
Signature status: Hash Mismatch

Known Samples

MD5: 74ec84ad6a3590959d66ae0f9acabcb5
SHA1: 9c72c6199d08fc05daaf657442af56a2c453ca0a
SHA256: C0B998CADAAB36D1BC3FAD60472FF118885CAB8BCFDEDEA3E221FBAB59835213
File Size: 194.79 KB, 194790 bytes
MD5: aa956247b158dd9abb55d50332352210
SHA1: 72aafca0185684c1da47356efa7b6e5b55a1827c
SHA256: A7DE8932C72A0C7662567FBF5397F4E8FAFBCAFC79066CC92A717114A421D392
File Size: 283.74 KB, 283740 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Microsoft Corporation
File Description Microsoft Edge Update
File Version 1.3.211.7
Internal Name Microsoft Edge Update
Legal Copyright Copyright 2018 Microsoft Corporation
Original Filename MicrosoftEdgeUpdate.exe
Product Name Microsoft Edge Update
Product Version 1.3.211.7
Upstream Version 1.3.99.0

Digital Signatures

Signer Root Status
Microsoft Corporation Microsoft Code Signing PCA 2011 Hash Mismatch

File Traits

  • 2+ executable sections
  • HighEntropy
  • Installer Manifest
  • nosig nsis
  • No Version Info
  • Nullsoft Installer
  • x86

Block Information

Total Blocks: 1,067
Potentially Malicious Blocks: 52
Whitelisted Blocks: 995
Unknown Blocks: 20

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 0 0 1 0 1 0 0 1 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 x x x x x x x x x 0 x x x 0 x x 0 x x x 0 x x x x x x x x x x x 0 x x x x 0 x x x x x x x x x x x x x x 0 x x x x x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Trending

Most Viewed

Loading...