Threat Database Trojans Trojan.RBot.B

Trojan.RBot.B

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 19,211
Threat Level: 80 % (High)
Infected Computers: 109
First Seen: May 17, 2023
Last Seen: June 12, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.RBot.B
Signature status: No Signature

Known Samples

MD5: 365f03a4cbd37a7e4610d40e62c5104d
SHA1: 45bf63709e477d44e6abb0f2c15a8880d7ca952a
File Size: 195.07 KB, 195072 bytes
MD5: 5500602601bce74ed72e28371192583b
SHA1: 4ced764eccef8319654cecad36935fe25540b6eb
SHA256: D733D4EFD3D0C92953A3D518AD711DF56F032A87C97CCE32BE91CECD1A923BDB
File Size: 1.22 MB, 1220608 bytes
MD5: d247a12afcee57bc87fcf1ae6fe6049e
SHA1: 44986497fa23da0f3d71220f226f31466d88927e
SHA256: 9856B6C2A20A7996A4E2A9E9318B854B76BF9ADA70BB40BC703539D90F376CBA
File Size: 1.51 MB, 1506304 bytes
MD5: 7ccffc6a7906c604d8df84521577a730
SHA1: bc8495bb140cf8fb1d310474fa8f692fb1e9ab82
SHA256: 0E6C0FF46F480A052E49E3A7617511552ADF3DF79DDE123ABBDC21A4246FDB8C
File Size: 244.74 KB, 244736 bytes
MD5: 5791f789aef99ac4a07b1503ea3dc77a
SHA1: daca2472b74e74072280c4a37d25a8f11aee9042
SHA256: D952FF405E9F265E59F71EF73F9F977FF5DE60718F2F23CCF74594D1B03480E3
File Size: 193.54 KB, 193536 bytes
Show More
MD5: 44af23f6593ed88b5f9e6956a81d6b71
SHA1: 8974d05d499ddd39f11282979c1b31448ef47537
SHA256: 1A26A75F72437E94D8E4ABABF279A5DB8253A6A90392DEDD9333F55319C06D0E
File Size: 100.35 KB, 100352 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Microsoft Corporation
File Description
  • FWIMPORT MFC Application
  • Win32 Cabinet Self-Extractor
File Version
  • 6.00.2600.0000 (xpclient.010817-1148)
  • 1, 0, 0, 1
Internal Name
  • FWIMPORT
  • Wextract
Legal Copyright
  • Copyright © 1998
  • © Microsoft Corporation. All rights reserved.
Original Filename
  • FWIMPORT.EXE
  • WEXTRACT.EXE
Product Name
  • FWIMPORT Application
  • Microsoft® Windows® Operating System
Product Version
  • 6.00.2600.0000
  • 1, 0, 0, 1

File Traits

  • .adata
  • 00 section
  • 2+ executable sections
  • HighEntropy
  • No Version Info
  • VirtualQueryEx
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 9
Potentially Malicious Blocks: 1
Whitelisted Blocks: 1
Unknown Blocks: 7

Visual Map

0 x ? ? ? ? ? ? ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • RBot.B

Registry Modifications

Key::Value Data API Name
HKLM\software\classes\.key:: regfile RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{533017fd-f2bd-7d14-bb2f-3d61a5c06cac}:: QrE4VOujXxnKJqS/ RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{533017fd-f2bd-7d14-bb2f-3d61a5c06cac}:: QrE4VOujXxnKJqS/ RegNtPreCreateKey

Trending

Most Viewed

Loading...