Threat Database Trojans Trojan.Donut.M

Trojan.Donut.M

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 2
First Seen: May 20, 2025
Last Seen: March 6, 2026
OS(es) Affected: Windows

The detection of Trojan.Donut.M on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the security and integrity of your computer, and it's essential to understand its nature and take steps to remove it.

What Is Trojan.Donut.M?

Trojan.Donut.M is a type of Trojan horse malware, which is a broad category of malicious software that disguises itself as legitimate programs. The name "Trojan.Donut.M" suggests that it's a specific variant of malware, but its exact characteristics and behaviors may not be immediately clear. Trojans are often used to gain unauthorized access to a system, steal sensitive information, or disrupt normal computer operations.

How Trojan.Donut.M Operates

Like other Trojans, Trojan.Donut.M likely operates by exploiting vulnerabilities in software or tricking users into installing it. Once inside a system, it may attempt to communicate with its creators or other malicious servers to receive instructions or transmit stolen data. The malware may also try to evade detection by disguising itself as a legitimate process or hiding in temporary files. Its primary goal is to remain undetected while causing harm to the infected system or stealing valuable information.

Symptoms of Infection

Systems infected with Trojan.Donut.M may exhibit a range of symptoms, including slow performance, frequent crashes, or unusual network activity. You might notice that your computer is behaving erratically, such as displaying unexpected pop-ups, redirecting to unfamiliar websites, or experiencing unexplained changes to your desktop or settings. In some cases, the malware may not produce any noticeable symptoms, making it difficult to detect without the aid of security software.

  • Unexplained changes to system settings or files
  • Increased network activity or suspicious connections
  • Slow system performance or frequent crashes
  • Appearance of unexpected pop-ups or advertisements

How to Remove Trojan.Donut.M

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for internet access.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all instances of the malware.
  3. Uninstall any suspicious programs or applications that may be related to the malware.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or settings.
  5. Reboot your computer and perform another full scan to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.Donut.M from your system requires a combination of technical knowledge and the right tools. By following the steps outlined above and maintaining good security practices, such as keeping your software up to date and being cautious when opening email attachments or downloading files, you can help protect your system from future infections. Remember that prevention is key, and staying informed about the latest threats and security best practices is essential in today's digital landscape.

Analysis Report

General information

Family Name: Trojan.Donut.M
Signature status: No Signature

Known Samples

MD5: 71272a7ff4901c90f9d60b26f018d335
SHA1: 27ef6c323e9331a713643615e644c3edaf3396a9
SHA256: 53FB89600F7B00B44FBD8260A895A31084161AC58FD4C0780E8AC2060740489F
File Size: 8.75 MB, 8747008 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • dll
  • HighEntropy
  • x86

Block Information

Total Blocks: 15,019
Potentially Malicious Blocks: 4,397
Whitelisted Blocks: 10,622
Unknown Blocks: 0

Visual Map

x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x 0 x x 0 0 x x x x x 0 x x 0 0 x x x 0 x x x 0 0 x x 0 0 x 0 x 0 0 x 0 0 x x x 0 x x x 0 0 x x 0 0 x x x x x x x x x x 0 0 x x 0 x x 0 x x x x x x 0 0 x 0 0 x 0 0 x 0 0 x x 0 x x 0 0 x x 0 0 x x x x x x 0 x x 0 0 x 0 x 0 0 x x x x x 0 0 x x 0 0 x x x x 0 x x x x 0 x x x x x 0 x x 0 x x x 0 x 0 x x x 0 0 x x 0 0 x 0 x x x x x x x 0 x 0 x 0 x x 0 0 x x 0 0 x x x 0 x x x 0 0 x x 0 0 x x 0 0 x 0 0 x x x 0 x 0 0 x x x x 0 x 0 0 x 0 x x 0 x x 0 x x 0 0 0 x 0 0 x x 0 x x x x x x 0 x 0 0 x x x 0 0 x x x x x 0 x 0 0 0 x x 0 x x x x 0 x x 0 0 x x x x 0 x 0 x x x x 0 x x 0 x x 0 x 0 x x x x 0 x 0 x x x x 0 x x 0 0 x 0 0 0 x 0 x x x x x x 0 x x x 0 0 x 0 0 x 0 0 x 0 0 x x x x x x x x x x x x x x x 0 0 x x x x 0 x 0 x x 0 x x x 0 0 x x 0 x x 0 0 x x x x x x x x x x 0 x 0 0 x x x x 0 x x x x x x x x x 0 0 x x x x x x 0 x 0 0 x x x x x x 0 x x 0 x x 0 x x x x x 0 0 x x 0 x 0 x 0 x x x x 0 0 x x x x x 0 x 0 x x 0 x 0 0 x x 0 x 0 x 0 x x x x 0 0 x x x x 0 x x x x 0 x 0 0 x x 0 0 x 0 x x 0 0 0 x x 0 x x 0 0 x 0 x x x x 0 x x 0 x x 0 x 0 x 0 x x x x 0 x 0 x x x x 0 x 0 x x x 0 x x 0 x x x 0 x x x x x 0 0 0 x 0 x 0 0 x 0 x x x 0 x x 0 0 0 x x x x 0 0 x x x 0 x x x 0 0 x 0 0 0 x x x 0 0 x x x x 0 0 x x 0 x 0 x x 0 0 x x x 0 0 x 0 x x 0 x 0 x x x x 0 x x 0 x x 0 x x 0 x x 0 x x 0 x x 0 0 x x 0 x x x 0 0 x x x x 0 x x 0 x x 0 x x x x x x x x 0 x x x 0 x x 0 0 x x 0 x x 0 x x 0 0 x x x x 0 0 x x x x 0 0 x 0 x 0 x 0 0 x 0 x x x 0 x 0 x x 0 x x 0 0 x 0 0 x x x x x x 0 0 x x 0 x x x x x x 0 x x x x x x x x 0 x x x x x x x 0 x x x x 0 0 x x x x x x x x x x x 0 0 0 x 0 0 x 0 0 x x 0 x x x 0 0 x x x x 0 0 x 0 x x 0 x x x x 0 0 x x 0 0 x 0 x 0 0 0 x x 0 0 x 0 x x 0 x x x x x 0 x 0 0 x 0 0 x x x x 0 0 0 x 0 x x 0 x x 0 0 x x 0 0 x x x 0 x x 0 0 x x x x x x x x x x 0 x 0 x x 0 x x x 0 x x 0 x 0 x x x x x 0 x 0 x 0 x x x x x x x 0 0 x x x x x x x 0 x x x x x x x x x x 0 x x 0 x x 0 0 x 0 x 0 x x 0 0 x 0 x x 0 x x 0 x x x x x 0 0 x x 0 x 0 x x x 0 x x x 0 x 0 x x x x x x 0 x 0 0 x 0 x x 0 x x 0 0 x 0 0 x 0 0 x x x 0 0 0 x 0 x x 0 0 x x 0 0 x x x x x 0 x x x 0 x x x 0 x x x x x 0 0 x x 0 x 0 x x 0 0 x x 0 x x 0 x 0 0 x x x 0 0 x 0 x x x x x 0 0 x 0 0 x x x x x x x x 0 0 x 0 0 x x 0 x 0 x x x x x x x x x 0 x x x 0 x 0 0 x x x 0 0 x 0 x x x 0 0 0 x x x x x x 0 0 x x x 0 x 0 x 0 x x x 0 x x x x 0 0 x 0 0 x x x x 0 0 x 0 0 x x 0 0 x x 0 0 0 x 0 x 0 x x 0 0 x 0 0 x 0 x x 0 x x x x x x 0 x 0 0 x x 0 x x 0 x x 0 0 x x x x 0 0 x x 0 x x x x x x x x x x 0 x x x x 0 x x x x x x x x x x x x 0 x 0 0 x 0 x 0 0 x x x 0 x 0 x x 0 x x 0 x x x x x x x x x x 0 x x 0 0 x 0 0 x x 0 x x x x x x x x x x x x x x 0 0 x 0 x 0 x 0 0 x x x x x x x x x x x 0 x x x x 0 0 x 0 0 x x x x 0 x 0 x x x 0 0 x x 0 0 0 x x x x x 0 x x 0 0 x x x x x x x x 0 x x 0 x x x x x 0 0 x x x x x x x 0 0 x 0 x x x x 0 x 0 x x 0 x 0 x x x 0 0 x x 0 x 0 0 x 0 0 x 0 0 x x x 0 x 0 x 0 x x x 0 0 x 0 x 0 0 x x x x 0 0 x x 0 x 0 x x x 0 0 0 x x x x 0 x x 0 0 x x 0 x 0 x x x x x x x 0 0 0 x 0 x x 0 0 x x x 0 x 0 0 x 0 x 0 0 x 0 0 x x x x 0 x 0 x x 0 0 x x 0 x x x x x 0 x 0 0 x x x 0 x x 0 0 0 x x x x x 0 x x x x x x 0 x 0 x x x 0 x 0 x 0 0 x x 0 x x x x x x x x x 0 x 0 x x x 0 x 0 0 x x x x x x 0 0 x x x x x x 0 x x x 0 x x x x x x 0 x x 0 x x x 0 0 0 x 0 0 x 0 x x x 0 x 0 0 x x 0 x x x 0 x 0 x x x x x 0 0 x 0 0 x 0 0 x x 0 x 0 x 0 x 0 0 x 0 x x x 0 0 x x 0 x x 0 0 x x x 0 x x x x x x x 0 0 x 0 x x 0 0 x 0 x x 0 x 0 x x x 0 0 x x x 0 x x x x x x x x x x x x x x x x 0 0 x 0 0 x x x x x 0 0 0 x x 0 x x 0 0 x 0 0 x x x 0 x 0 x 0 x 0 x x x x x x x x x 0 x x x x 0 x 0 0 x x x x 0 0 x 0 0 x x x 0 0 0 x x x x 0 x 0 0 x x 0 x 0 0 0 x x x 0 0 x 0 x 0 x x 0 x 0 x x x x x x x x x x x x x x x x x 0 0 x x x x x x 0 x x x x x x x 0 0 x x 0 x 0 x 0 x 0 x x x x x x x x 0 0 x x x x 0 x x 0 0 x x x 0 x x x 0 x x x x x x 0 x x 0 x x x 0 0 x 0 x x 0 0 x x x x x 0 0 x x 0 x 0 x 0 x x x x 0 0 x x 0 0 x x 0 x x x x x 0 0 x x x x 0 x 0 0 x x 0 0 x 0 x x x x 0 x x 0 x x x 0 x x 0 x 0 x x 0 0 x 0 0 x x x x x x x 0 x x x x 0 0 x x x 0 0 x x x x 0 x x x x 0 0 x x x x 0 0 x 0 0 x x x 0 0 x x 0 x x x x x x x 0 0 0 x 0 x x x x 0 0 x x x 0 0 0 x x 0 0 x x 0 x 0 x x 0 0 x x x x 0 x x 0 0 0 x 0 0 0 x 0 x x 0 x x x 0 x x 0 0 x x x x 0 0 0 x 0 0 x x x 0 0 x x 0 x 0 0 x x x x 0 x x x 0 0 x 0 0 x x x 0 x x x 0 x x x
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Donut.M

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\27ef6c323e9331a713643615e644c3edaf3396a9_0008747008.,LiQMAxHB

Related Posts

Trending

Most Viewed

Loading...