Threat Database Trojans Trojan.ShellcodeRunner.DH

Trojan.ShellcodeRunner.DH

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 24,636
Threat Level: 80 % (High)
Infected Computers: 6
First Seen: August 30, 2024
Last Seen: May 16, 2026
OS(es) Affected: Windows

The detection of Trojan.ShellcodeRunner.DH indicates that your system has been compromised by a malicious threat. This type of malware is designed to execute arbitrary code on a victim's machine, potentially leading to a range of harmful activities. It is essential to understand the nature of this threat and take immediate action to remove it from your system to prevent further damage.

What Is Trojan.ShellcodeRunner.DH?

Trojan.ShellcodeRunner.DH is a type of Trojan malware that can infect a computer system without the user's knowledge or consent. The name itself suggests that it is capable of running shellcode, which is a set of instructions that can be executed by the operating system. This type of malware can be used to install additional malicious software, steal sensitive information, or provide unauthorized access to the infected system.

How Trojan.ShellcodeRunner.DH Operates

Trojan.ShellcodeRunner.DH operates by exploiting vulnerabilities in the system or by tricking the user into installing it. Once installed, it can connect to a command and control server to receive instructions from its creators. It can then execute a range of malicious activities, including data theft, keylogging, or installing additional malware. The malware can also modify system settings and files, making it difficult to detect and remove.

Symptoms of Infection

The symptoms of a Trojan.ShellcodeRunner.DH infection can vary, but common indicators include slow system performance, unexpected pop-ups or advertisements, and unfamiliar programs or icons on the desktop. You may also notice that your browser homepage or search engine has been changed without your consent. In some cases, the malware can cause system crashes or freezes, making it difficult to use the infected computer.

  • Unexplained changes to system settings or files
  • Slow system performance or crashes
  • Unexpected pop-ups or advertisements
  • Unfamiliar programs or icons on the desktop
  • Changes to browser settings or homepage

How to Remove Trojan.ShellcodeRunner.DH

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and remove any detected threats
  3. Uninstall any suspicious programs or applications that you do not recognize
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons
  5. Reboot your computer and perform another scan to ensure that the malware has been completely removed

Conclusion

Removing Trojan.ShellcodeRunner.DH from your system requires immediate attention to prevent further damage. By following the steps outlined above, you can help to ensure that your system is clean and secure. It is also essential to take preventive measures to avoid future infections, such as keeping your operating system and software up to date, using strong antivirus software, and being cautious when clicking on links or downloading attachments from unknown sources. Remember to always prioritize your system's security and take prompt action if you suspect that your computer has been compromised.

Analysis Report

General information

Family Name: Trojan.ShellcodeRunner.DH
Packers: UPX!
Signature status: No Signature

Known Samples

MD5: 03bf680459a087914d9e2b7d3fa82f93
SHA1: b1c1640933c75923932b051974b543d5d6a0da1b
SHA256: B9477F9C1128552CEC1D5BE900AE76CF505657EAEDD7EEDBF9B57773668818E2
File Size: 175.13 KB, 175128 bytes
MD5: f2440a54b59c5a0e1f072e27eb41cf7f
SHA1: 2eb69a7827ff98b8443504f882027f5b2585d4e9
SHA256: 98B352BA32CD6CF19F254CA0A7FBA3CD917E6A9C4114F170AAB4E334AD9CE531
File Size: 14.85 KB, 14848 bytes
MD5: 7ee2c8f9ccff7931a117efa90df09fb3
SHA1: 8c9cd8790ecb3342cf3ae0e616c73e8efb3f54ed
SHA256: 270B9582310233758932B1B4CFD890D0C1F40F78063ADEC9124C4A6CA5D274A1
File Size: 68.61 KB, 68608 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File has been packed
  • File has exports table
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name NVIDIA
File Description NVIDIA Omniverse Carbonite SDK
Legal Copyright Copyright (c) 2018-2024, NVIDIA Corporation
Product Name NVIDIA Omniverse Carbonite SDK
Product Version 160.8+release160.tc10131.21294c50

Digital Signatures

Signer Root Status
NVIDIA Corporation DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Self Signed

File Traits

  • dll
  • packed
  • x64

Block Information

Total Blocks: 473
Potentially Malicious Blocks: 1
Whitelisted Blocks: 466
Unknown Blocks: 6

Visual Map

0 ? ? ? 0 0 ? ? ? x 2 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Trojan.Agent.Gen.COA

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateObject
Show More
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtQueryWnfStateNameInformation
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetSystemInformation
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtUpdateWnfStateData
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Trending

Most Viewed

Loading...