Threat Database Trojans Trojan.MSIL.Wacapew.J

Trojan.MSIL.Wacapew.J

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.MSIL.Wacapew.J
Signature status: Self Signed

Known Samples

MD5: 999f830f71af4fe940f3c6bc3fa0772d
SHA1: 7fa347ab8b1d7dcf0ffdf0465185005ac9dfb1e0
SHA256: 627290DEDB98ED5692F11FC14C770AE598FC1D825572329D817E3E80BE5D0B41
File Size: 1.55 MB, 1548544 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name MetroLogic
File Description DataClientHub Component
File Version 1.0.0.0
Internal Name DataClientHub.exe
Legal Copyright Copyright © MetroLogic 2025
Original Filename DataClientHub.exe
Product Name DataClientHub
Product Version 1.0.0.0

Digital Signatures

Signer Root Status
MyStubCert MyStubCert Self Signed

File Traits

  • .NET
  • ntdll
  • x86

Block Information

Total Blocks: 6
Potentially Malicious Blocks: 6
Whitelisted Blocks: 0
Unknown Blocks: 0

Visual Map

x x x x x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Wacapew.J

Windows API Usage

Category API
User Data Access
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Process Manipulation Evasion
  • NtCreateThreadEx

Trending

Most Viewed

Loading...