Threat Database Trojans Trojan.Tyuyan.A

Trojan.Tyuyan.A

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 90
First Seen: August 10, 2021
Last Seen: December 12, 2025
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Tyuyan.A
Signature status: No Signature

Known Samples

MD5: e3ce272469ce0c44895dda90600cfcaf
SHA1: 97f3d4c99787549ae9de1c355deea6e54a2ed2b7
SHA256: 224C0D8F0ADDA5536B9A4593D494673C6442FE72AC82560C602157FC136B332E
File Size: 4.04 MB, 4044800 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • HighEntropy
  • imgui
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 8,410
Potentially Malicious Blocks: 755
Whitelisted Blocks: 7,634
Unknown Blocks: 21

Visual Map

0 0 0 0 0 0 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x x 0 x 0 0 0 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x 0 x 0 x 0 x 0 0 0 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 x 0 0 0 x x x x x x x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x 0 x 0 x x x x x 0 x x 0 x x x x 0 x x x x x x x x x x x x x x x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x x x x x 0 x x x x x 0 x x x x x x x x 0 x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 1 0 0 0 1 1 1 1 1 1 1 1 0 1 0 0 1 1 1 0 0 x x 0 0 0 0 0 0 x 0 x 0 0 0 0 x 0 x x 0 x 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 x 0 0 x 0 x x 0 0 0 0 0 0 x 0 0 0 0 x x 0 0 x 0 0 0 x 0 0 x x x x 0 0 x 0 x 0 x x x x 0 0 0 x 0 x x x x x 0 x x x x 0 0 x x x x x x 0 0 x x 0 0 0 0 x x x x x x 0 0 x 0 x x x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x 0 x x x x 0 0 x x x x x x x x 0 0 x x x x 0 x 0 0 0 x 0 x 0 x x x x x x x 0 x 0 0 x x 0 x 0 0 x x 0 0 0 x 0 x x x x x x 0 x 0 0 x x x x x 0 0 x x 0 x 0 x x x 0 x 0 x 0 0 x x x x x x x 0 x 0 x x x x x x x x x 0 0 x x x x x x x 0 x x x x x x x x x x x x x x 0 x x 0 x x x x x x 0 x x x 0 0 x x x x x x x 0 0 x x 0 x x 0 0 x 0 x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 x 0 0 x 0 0 x x x 0 0 x 0 x 0 x x 0 0 0 x x x 0 x x 0 x x 0 0 x x x 0 x x x 0 x x 0 x x x 0 0 0 0 x x 0 0 0 0 x x x x 0 x x x x 0 x x x 0 x 0 x x x x x x x x x x x x 0 x x 0 0 x 0 x 0 0 0 0 0 x 0 0 x x x 0 x x x 0 0 x 0 0 0 x x x x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 x 0 0 x x x x x x 0 0 x x 0 0 0 x x x 0 x 0 0 x x x x 0 x x 0 0 x 0 0 x 0 x x 0 x 0 x x x 0 x x 0 x x x 0 x 0 0 0 x x x 0 0 x x 0 x x x x x x x x 0 0 x 0 x x x 0 x 0 x x x x x x x x x x x x x x x 0 x x 0 x 0 0 0 0 0 x x 0 0 x 0 x x x x x x x 0 x x x 0 x x x x x x x x x x x x x x x x x x x x x x x 0 x x x 0 x x x x x x 0 x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x 0 x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x 0 x x 0 x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x 0 x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 x x 0 x x x x x x x x 0 x x 0 x x x x x x x 0 0 x x x x x x 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 1 1 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Convagent.I
  • Draobo.A
  • Farfli.LE
  • Trojan.Downloader.Gen.RG
  • Tyuyan.A
Show More
  • Ursnif.AD

Files Modified

File Attributes
c:\users\user\appdata\local\temp\8132989d36\10001718.temp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\8132989d36\intermediate.tis Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\8132989d36\intermediate.tis Generic Write,Read Attributes
c:\users\user\appdata\local\temp\8132989d36\intermediate.tis Synchronize,Write Attributes
c:\users\user\appdata\local\temp\8132989d36\main.twin Generic Write,Read Attributes
c:\users\user\appdata\local\temp\8132989d36\main.twin Synchronize,Write Attributes
c:\users\user\appdata\local\temp\8132989d36\t_baibaoyun_win32.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\8132989d36\t_baibaoyun_win32.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\8132989d36\tapi.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\8132989d36\tapi.dll Synchronize,Write Attributes
Show More
c:\users\user\appdata\local\temp\8132989d36\tlib.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\8132989d36\tlib.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\8132989d36\ts.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\8132989d36\ts.dll Synchronize,Write Attributes
c:\users\user\downloads\çrmn.ini Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\syswow64\ts.dll Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144

Registry Modifications

Key::Value Data API Name
HKLM\software\classes\appid\{900527eb-7d74-41de-9e3e-80e4b267e0f2}:: TSPlug RegNtPreCreateKey
HKLM\software\classes\appid\tsplug.dll::appid {900527EB-7D74-41DE-9E3E-80E4B267E0F2} RegNtPreCreateKey
HKLM\software\classes\ts.tssoft:: TSPlugInterFace Class RegNtPreCreateKey
HKLM\software\classes\ts.tssoft\clsid:: {BCE4A484-C3BC-418B-B1F6-69D6987C126B} RegNtPreCreateKey
HKLM\software\classes\ts.tssoft\curver:: Ts.TsSoft RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{bce4a484-c3bc-418b-b1f6-69d6987c126b}:: TSPlugInterFace Class RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{bce4a484-c3bc-418b-b1f6-69d6987c126b}\progid:: Ts.TsSoft RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{bce4a484-c3bc-418b-b1f6-69d6987c126b}\inprocserver32:: C:\WINDOWS\SysWow64\TS.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{bce4a484-c3bc-418b-b1f6-69d6987c126b}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\classes\typelib\{525cf7e5-db36-491f-a91c-2db86e67126d}\1.0:: TSPlug 1.0 ÀàÐÍ¿â RegNtPreCreateKey
Show More
HKLM\software\classes\typelib\{525cf7e5-db36-491f-a91c-2db86e67126d}\1.0\flags:: 0 RegNtPreCreateKey
HKLM\software\classes\typelib\{525cf7e5-db36-491f-a91c-2db86e67126d}\1.0\0\win32:: C:\WINDOWS\SysWow64\TS.dll RegNtPreCreateKey
HKLM\software\classes\typelib\{525cf7e5-db36-491f-a91c-2db86e67126d}\1.0\helpdir:: C:\WINDOWS\system32 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{f3e95c10-606a-474e-bb4a-b9ccbf7db559}:: ITSPlugInterFace RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{f3e95c10-606a-474e-bb4a-b9ccbf7db559}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{f3e95c10-606a-474e-bb4a-b9ccbf7db559}\typelib:: {525CF7E5-DB36-491F-A91C-2DB86E67126D} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{f3e95c10-606a-474e-bb4a-b9ccbf7db559}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{f3e95c10-606a-474e-bb4a-b9ccbf7db559}:: ITSPlugInterFace RegNtPreCreateKey
HKLM\software\classes\interface\{f3e95c10-606a-474e-bb4a-b9ccbf7db559}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{f3e95c10-606a-474e-bb4a-b9ccbf7db559}\typelib:: {525CF7E5-DB36-491F-A91C-2DB86E67126D} RegNtPreCreateKey
HKLM\software\classes\interface\{f3e95c10-606a-474e-bb4a-b9ccbf7db559}\typelib::version 1.0 RegNtPreCreateKey

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Other Suspicious
  • SetWindowsHookEx