Threat Database Trojans Trojan.Blackmoon.Y

Trojan.Blackmoon.Y

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 16,674
Threat Level: 80 % (High)
Infected Computers: 25
First Seen: August 13, 2024
Last Seen: June 20, 2026
OS(es) Affected: Windows

The detection of Trojan.Blackmoon.Y on your system indicates a potential security threat that requires immediate attention. Trojans are a type of malware that can cause significant harm to your computer and compromise your personal data. In this removal report, we will provide you with an overview of the threat, its operating methods, symptoms of infection, and a step-by-step guide on how to remove it from your system.

What Is Trojan.Blackmoon.Y?

Trojan.Blackmoon.Y is a type of Trojan horse malware that can infect your computer through various means, such as downloading infected software, opening malicious email attachments, or visiting compromised websites. Once installed, it can allow unauthorized access to your system, steal sensitive information, and disrupt your computer's performance. The name "Trojan.Blackmoon.Y" suggests that it may be a variant of a known Trojan horse malware, but without further information, it is difficult to determine its exact origin or purpose.

How Trojan.Blackmoon.Y Operates

Trojan.Blackmoon.Y, like other Trojans, operates by disguising itself as a legitimate program or file, making it difficult to detect. It can create backdoors, allowing hackers to remotely access your system, and can also spread to other computers through network connections. The malware can also modify system settings, disable security software, and install additional malware or unwanted programs. Its primary goal is to remain undetected and continue to cause harm to your system and compromise your personal data.

Symptoms of Infection

Identifying the symptoms of a Trojan infection can be challenging, as they can be similar to those caused by other types of malware or system issues. However, some common signs of infection include slow system performance, frequent crashes, and unexpected changes to system settings. You may also notice unfamiliar programs or icons on your desktop, or receive suspicious pop-ups or alerts. Additionally, your antivirus software may detect and alert you to the presence of malware, or you may notice that your internet connection is slower than usual.

  • Slow system performance or crashes
  • Unfamiliar programs or icons on your desktop
  • Suspicious pop-ups or alerts
  • Changes to system settings or security software
  • Slow internet connection

How to Remove Trojan.Blackmoon.Y

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for a more effective removal process.
  2. Use a reputable malware removal tool, such as SpyHunter, to perform a full scan of your system and detect any malware or unwanted programs.
  3. Uninstall any suspicious programs or software that you do not recognize or that were installed without your knowledge.
  4. Reset your web browsers, such as Chrome, Firefox, or Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your computer and perform a second scan with your malware removal tool to ensure that all threats have been removed.

Conclusion

Removing Trojan.Blackmoon.Y from your system requires careful attention to detail and a thorough understanding of the removal process. By following the steps outlined in this report, you can effectively remove the malware and prevent further harm to your system. It is essential to remain vigilant and to continue monitoring your system for any signs of infection or suspicious activity. Regularly updating your security software, avoiding suspicious downloads, and being cautious when opening email attachments or visiting unknown websites can help to prevent future infections and keep your system secure.

Analysis Report

General information

Family Name: Trojan.Blackmoon.Y
Packers: UPX!
Signature status: No Signature

Known Samples

MD5: ea4c1e215f7369d50543683a27136467
SHA1: b998f699e9eb7186e132028e793d7df981aa8344
SHA256: E4903A875B7A3CB9B6EF6161243B403722935349F4F6190C54F54FA933313580
File Size: 517.12 KB, 517120 bytes
MD5: 0809cb5af2c943ceda7f751b3052502b
SHA1: b19f30ada93fb92e6a917e9aa05ebc080af4f8b1
SHA256: C5300F7DFF54870D69061A2E16E3F0AFB8D586E10550A7FBF6C5E2D552B258D3
File Size: 248.83 KB, 248832 bytes
MD5: 80cac197d4661fc7d628de995aae4af4
SHA1: 15c3fb38724554eab519e5e3a1a33dd8e76454e1
SHA256: AABFDE30019DF5474E0B4337AE504EE8332BECCCA23A3CAF8CC4C7741CD3C1BC
File Size: 433.66 KB, 433664 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have resources
  • File doesn't have security information
  • File has been packed
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Comments This is version 4.955 made 1st June 2016
Company Name Peter L. Dowson
File Description
  • IPC Interface and More, for Microsoft Flight Simulator X and beyond
  • RemoteCam ActiveX Control Module
File Version
  • 4.955
  • 4, 0, 9, 0
Internal Name
  • FSUIPC4
  • RemoteCam
Legal Copyright
  • Copyright (C) 2003 - 2012
  • Copyright (c) Peter L. Dowson 2016
Legal Trademarks Flight Simulator is by Microsoft; the original IPC module for FS was by Adam Szofran
Original Filename
  • FSUIPC4
  • RemoteCam.OCX
Private Build 9OX1CPNQKPDJO
Product Name
  • FSUIPC4 DLL: FS new universal IPC interface
  • RemoteCam ActiveX Control Module
Product Version
  • 4.955
  • 4, 0, 9, 0
Special Build 0SLLVII433GI6

File Traits

  • 2+ executable sections
  • dll
  • HighEntropy
  • packed
  • upx
  • UPX!
  • x86

Block Information

Total Blocks: 2,493
Potentially Malicious Blocks: 14
Whitelisted Blocks: 1,084
Unknown Blocks: 1,395

Visual Map

? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? x 0 ? 0 ? ? ? 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x x x ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 ? ? 0 ? ? ? 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? ? ? 0 0 ? ? 0 0 0 0 ? 0 ? ? 0 0 0 0 0 ? ? ? ? ? ? ? ? 0 0 ? ? 0 ? 0 ? 0 ? 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? ? ? 0 0 ? 0 0 0 0 0 0 ? ? ? ? ? 0 ? ? ? ? 0 0 ? ? ? 0 0 0 0 0 0 ? 0 0 0 0 ? ? ? ? 0 0 ? 0 ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? ? 0 ? x 0 0 x 0 0 x 0 0 x ? ? 0 ? 0 0 0 0 0 0 0 0 ? 0 0 ? ? 0 ? 0 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 ? 0 0 0 0 ? ? ? ? 0 0 ? ? 0 0 ? ? 0 0 0 0 ? 0 0 ? 0 0 ? 0 0 ? 0 0 ? ? ? 0 0 ? 0 ? 0 ? 0 0 0 ? ? 0 0 0 0 ? 0 ? ? 0 0 0 0 0 0 0 ? 0 0 0 0 ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? 0 0 0 0 ? x 0 ? 0 ? ? ? ? ? ? 0 0 ? 0 0 ? ? 0 ? ? ? ? ? ? 0 0 0 0 ? 0 ? ? 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 0 0 ? ? ? ? ? ? ? ? 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 0 ? ? 0 x 0 ? x 0 ? 0 ? 0 0 0 0 ? ? ? ? 0 ? ? 0 ? ? 0 0 0 0 0 ? ? ? ? 0 ? ? 0 ? 0 0 0 ? 0 0 0 ? ? ? ? 0 ? 0 ? 0 ? ? 0 ? 0 0 0 0 ? 0 0 0 x 0 0 ? 0 0 ? 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 ? ? ? ? 0 0 0 ? ? 0 x 0 0 ? 0 ? 0 ? ? 0 0 ? ? ? 0 ? ? 0 0 ? ? 0 ? ? 0 0 0 0 0 0 ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 ? 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 ? ? ? ? 0 0 ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 ? ? ? ? ? ? ? ? ? ? 0 0 0 ? ? ? ? ? ? ? 0 0 0 ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 0 1 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? 0 ? ? 0 0 0 0 0 ? ? ? 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 0 0 0 1 1 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 1 0 1 0 0 1 0 0 1 0 0 1 0 0 0 0 1 0 0 0 0 2 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 3 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Registry Modifications

Key::Value Data API Name
HKCU\control panel\desktop::foregroundlocktimeout RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\b998f699e9eb7186e132028e793d7df981aa8344_0000517120.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\b19f30ada93fb92e6a917e9aa05ebc080af4f8b1_0000248832.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\15c3fb38724554eab519e5e3a1a33dd8e76454e1_0000433664.,LiQMAxHB

Trending

Most Viewed

Loading...