Threat Database Trojans Trojan.Blackmoon.E

Trojan.Blackmoon.E

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 9,984
Threat Level: 80 % (High)
Infected Computers: 68
First Seen: April 7, 2021
Last Seen: July 14, 2026
OS(es) Affected: Windows

The detection of Trojan.Blackmoon.E on your system indicates a potential security threat that requires immediate attention. Trojans are a type of malware that can cause significant harm to your computer and compromise your personal data. In this report, we will provide you with an overview of the threat, its operating methods, symptoms of infection, and a step-by-step guide on how to remove it from your system.

What Is Trojan.Blackmoon.E?

Trojan.Blackmoon.E is a type of Trojan horse malware that can infiltrate your system without your knowledge or consent. The name "Trojan" refers to the malware's ability to disguise itself as a legitimate program or file, allowing it to evade detection and gain access to your system. Once inside, the malware can cause a range of problems, from stealing sensitive information to disrupting system performance.

How Trojan.Blackmoon.E Operates

Trojan horses like Trojan.Blackmoon.E typically operate by exploiting vulnerabilities in your system or tricking you into installing them. They can be disguised as legitimate software, attached to emails or downloads, or even embedded in infected websites. Once installed, the malware can communicate with its creators, allowing them to control your system remotely and steal sensitive information such as passwords, credit card numbers, or personal data.

Symptoms of Infection

If your system is infected with Trojan.Blackmoon.E, you may notice a range of symptoms, including slow system performance, unexpected crashes, or unfamiliar programs running in the background. You may also notice suspicious activity, such as unfamiliar login attempts or unexpected changes to your system settings. In some cases, the malware may not exhibit any noticeable symptoms, making it difficult to detect without proper scanning tools.

  • Slow system performance or freezes
  • Unfamiliar programs or processes running in the background
  • Suspicious login attempts or changes to system settings
  • Unexplained crashes or errors

How to Remove Trojan.Blackmoon.E

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for a more effective removal process.
  2. Run a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove the Trojan.Blackmoon.E malware.
  3. Uninstall any suspicious programs or software that may be related to the malware.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and run another full scan to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.Blackmoon.E from your system requires a combination of technical expertise and caution. By following the steps outlined in this report, you can help to ensure that your system is free from the malware and that your personal data is protected. Remember to always be vigilant when downloading software or opening email attachments, and to keep your anti-malware tools up to date to prevent future infections. If you are unsure about any aspect of the removal process, consider seeking the help of a professional technician to ensure that your system is properly cleaned and secured.

Analysis Report

General information

Family Name: Trojan.Blackmoon.E
Packers: UPX!
Signature status: No Signature

Known Samples

MD5: 89689e4ba0623e00a842082257866ce0
SHA1: c7ed40082e7cee6bb848462179c56b80eb0d2b3f
SHA256: 3AAE27151B982E785DAA520A64D464415BBCB792AAC8E35C999FC530EC380149
File Size: 228.86 KB, 228864 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have resources
  • File doesn't have security information
  • File has been packed
  • File has exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • dll
  • packed
  • x86

Block Information

Total Blocks: 1,363
Potentially Malicious Blocks: 705
Whitelisted Blocks: 160
Unknown Blocks: 498

Visual Map

x x ? ? ? 0 0 ? ? ? ? ? x 0 0 x x x ? 0 x x x x ? ? ? x ? ? ? ? x x x ? x x x 0 ? ? ? ? 0 ? 0 ? x 0 0 ? ? x ? ? ? x ? 0 ? ? x ? x ? 0 ? 0 ? ? ? ? ? ? 0 0 0 ? ? ? x ? ? x ? ? ? ? ? x x ? ? ? ? x ? ? x ? ? ? ? x ? ? ? x ? x x x x x x x 0 x x x x x x ? x x ? x x ? x x x x x x ? ? 0 ? ? x x ? ? 0 0 x x 0 x ? ? x ? 0 x ? 0 x x x ? x ? 0 ? ? ? ? x ? ? 0 0 ? x x x x ? x ? ? x 0 ? x x x ? x x x ? x ? x ? x ? x ? x ? ? ? ? x x x x x x 0 ? x x x x x x x x x x x x ? x 0 ? 0 x x x x ? 0 0 ? x x x ? ? 0 x ? x x x x x ? x ? x ? x x ? ? x x ? ? x ? x ? x x x x x x x x x ? x ? x x ? ? ? x ? ? x x x x x x x x x ? x ? x ? ? ? x x x x ? ? x ? ? ? x x x x ? x x x x x x x x x x x ? x x x ? x x x x ? x x x x x ? ? x x ? ? x x x x x ? x x x x x x ? x x x x x x x x x ? x x x x x x x x x x x x x x x x x x x x x x x x x x x x x ? x x x x x x x x x x x x ? x x x x 0 ? x x x x x x x x ? x x x x x ? x x 0 ? ? ? x x x x x ? x x ? x x x x x x x x ? x ? 0 x x ? x x x x x x ? ? ? x 0 ? 0 x x ? ? ? 0 ? x x ? 0 ? x x x ? x x x ? ? 0 x ? x ? x ? 0 x x ? ? x ? x ? ? x ? ? ? x ? x ? x x x ? ? x ? ? ? ? ? x x ? ? ? ? ? ? x x x x x ? x x x ? x ? x x ? ? ? ? ? ? x x x ? x x ? ? ? x x 0 x x x ? x x x 0 ? x x x x x x x x x 0 x x x x x x x x 0 x x x x x x x 0 0 x x x x x x x x x ? x x ? ? ? ? x x x x x x x x x x x ? ? x x x x x ? ? 0 x x ? ? ? x x ? x ? ? ? ? x x ? x x x x x x x x x x x x x x x x x ? x 0 ? ? x x ? ? ? x ? x ? ? ? ? ? ? ? ? 0 ? ? x ? ? ? x x x ? ? ? x x x x x x x x x x x x x x x x x x x x x x x x ? x x ? ? x x x x ? x 0 x x x 0 x x x x ? x x ? x ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x x x x x x x 0 x 0 x x x 1 x x x x x 0 0 x x x x x 0 x x x 0 x x 0 x x x x x x x x 0 x x x x 0 x x x ? x x 0 0 x x x x x x 0 0 x x x ? 0 x x x x x x x x x x 0 x x x x 0 0 x 0 x x x x x 0 x x 0 x x x x 0 x x x x x x 0 0 x x x x x x x x x x x 0 x x x x ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? x x ? ? ? x x x 0 ? ? 0 x ? ? ? ? x x x ? ? ? 0 ? ? 0 ? x x x x x ? ? ? 0 ? ? ? ? ? ? x ? ? ? ? x x ? ? ? ? x ? x x ? ? ? x x x x ? ? ? ? 0 x x x x x x x ? ? ? ? ? x ? ? ? ? ? ? ? ? ? x ? ? ? x x ? ? ? ? x x ? ? ? x ? ? x ? x ? ? ? ? ? x ? x ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? x ? ? x ? ? 0 ? ? ? ? ? ? ? ? ? x ? 0 ? ? ? ? ? x ? ? x x x ? x ? ? ? x x x ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? x x x x ? x x ? ? ? ? ? x ? ? ? ? 0 0 x ? ? x ? ? ? ? ? x x ? ? ? ? ? x ? ? ? ? x ? ? ? x ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x x ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? x 0 x x x x x x 0 x x x x x 0 x x 0 x 0 0 0 x 0 x x x 0 x x 0 x x x x x x x x 0 x 1 x x x x x x 0 0 x x x 0 x x x x 1 x x x x x x x x x x x x x x 0 x x 0 x x x x x 0 x x x x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\appdata\local\temp\9422e9.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\942308.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\c7ed40082e7cee6bb848462179c56b80eb0d2b3f_0000228864.,LiQMAxHB

Trending

Most Viewed

Loading...