위협 데이터베이스 트로이 목마 트로이목마.에이전트.젠.GAO

트로이목마.에이전트.젠.GAO

Trojan.Agent.Gen.GAO 는 "Agent" 계열에 속하는 다른 악성 프로그램과 유사한 동작을 보이는 트로이목마 유형의 위협을 식별하는 데 사용되는 일반적인 탐지 이름입니다. "Gen"으로 표시된 탐지는 일반적으로 이전에 등록된 정확한 시그니처가 아닌 동작 또는 휴리스틱 패턴을 기반으로 플래그가 지정되었음을 의미합니다. 즉, Trojan.Agent.Gen.GAO는 특정 악성 프로그램 하나가 아니라 유사한 코드 구조, 기능 또는 동작을 공유하는 다양한 악성 파일을 나타낼 수 있습니다.

이번 탐지에 대한 자세한 기술적 세부 사항이 확인되지 않았으므로, 아래 설명은 시스템에서 활성화된 후 일반적으로 이러한 작업을 수행하는 해당 범주의 트로이 목마의 일반적인 동작을 반영합니다.

이 위협이 일반적으로 하는 일은 무엇입니까?

일반적인 "에이전트" 탐지 유형으로 분류되는 트로이 목마는 대개 사용자의 동의나 인지 없이 백그라운드에서 조용히 실행됩니다. 이러한 유형의 위협은 일반적으로 다음과 같은 동작을 보입니다.

  • 감염된 기기에 추가적인 악성 구성 요소를 다운로드하고 설치합니다.
  • 시스템 설정이나 구성 파일을 수정하여 지속성을 유지합니다.
  • 공격자가 제어하는 원격 서버와 통신하여 지시를 받습니다.
  • 감염된 컴퓨터에서 시스템 세부 정보나 인터넷 검색 활동과 같은 정보를 수집합니다.
  • 탐지 및 제거를 피하기 위해 보안 도구를 비활성화하거나 방해하는 행위

Trojan.Agent.Gen.GAO로 표시된 개별 파일의 정확한 기능은 다양할 수 있습니다. 이는 탐지 방식이 휴리스틱 기반이며 공통적인 특징을 공유하는 여러 관련 없는 악성 파일에 적용될 수 있기 때문입니다.

바이러스가 컴퓨터에 침투하는 일반적인 경로

이 범주에 속하는 트로이 목마는 일반적으로 다음과 같은 광범위한 트로이 목마 유형에서 흔히 사용되는 방법을 통해 확산됩니다.

  • 합법적인 문서나 청구서로 위장한 이메일 첨부 파일이나 링크가 포함된 피싱 메시지
  • 크랙 및 키젠을 포함한 무료 또는 불법 복제 소프트웨어의 번들 설치 프로그램
  • 신뢰할 수 없는 웹사이트의 가짜 소프트웨어 업데이트 또는 오해의 소지가 있는 다운로드 버튼
  • 악성 광고를 통해 사용자가 감염된 다운로드 페이지로 이동합니다.
  • 감염된 이동식 드라이브 또는 P2P 파일 공유 네트워크

사용자에게 미치는 위험

이러한 트로이목마는 시스템에 그대로 두면 데이터 도난, 무단 원격 접근, 금전적 손실, 그리고 다운로드할 수 있는 다른 악성코드로 인한 추가 감염 등 여러 위험에 사용자를 노출시킬 수 있습니다. 트로이목마는 대개 은밀하게 작동하기 때문에 사용자가 즉시 영향을 알아차리지 못할 수 있으며, 이로 인해 공격자는 감염된 시스템에 대한 접근 권한을 더 오랫동안 확보할 수 있습니다.

감염 징후

이 탐지 방식은 일반적이므로 눈에 보이는 증상은 매우 다양할 수 있지만, 트로이 목마와 관련된 일반적인 경고 신호는 다음과 같습니다.

  • 명확한 원인 없이 시스템 속도가 눈에 띄게 느려지거나 CPU/네트워크 사용량이 증가하는 현상
  • 예기치 않은 팝업 창, 오류 메시지 또는 브라우저나 시스템 설정 변경
  • 사용자가 설치하지 않았는데도 새롭거나 익숙하지 않은 프로그램이 나타나는 경우
  • 보안 소프트웨어가 비활성화되었거나 업데이트할 수 없음
  • 비정상적인 외부 네트워크 연결

자신을 보호하는 방법

Trojan.Agent.Gen.GAO와 같은 위협으로부터 감염 위험을 줄이려면 운영 체제와 설치된 모든 소프트웨어를 최신 상태로 유지하고, 검증되지 않았거나 불법 복제된 출처에서 프로그램을 다운로드하지 않으며, 알 수 없는 발신자의 이메일 첨부 파일과 링크에 주의하고, 신뢰할 수 있는 보안 소프트웨어를 사용하여 시스템을 정기적으로 검사하고 모니터링해야 합니다. 중요한 파일을 정기적으로 백업하면 감염 시 피해를 최소화할 수 있으며, 안전한 인터넷 사용 습관을 들이면 이러한 위협에 노출될 가능성을 크게 줄일 수 있습니다.

분석 보고서

일반 정보

성씨: Trojan.Agent.Gen.GAO
서명 상태: Self Signed

알려진 샘플

MD5: 3f8fa75718b6d1b443b788a68cfdaf1e
샤1: 099349795fbbf59074b55926818ee554273f3ca9
샤256: 94069806A751BEADB67663DA37D0CB0697AB3D19A6E27F1E2118875BA17EAAC5
파일 크기: 55.30 KB,55296 바이트
MD5: 1def2ec226d667dece04162bdf7b9b69
샤1: 1b1aae6f2f2c4373b6d8be7d22422f8787fa28a1
샤256: 72FF3D5068252BD439E2E79570EAE5257B0D3E07E37FC72D62435B9D502514A2
파일 크기: 5.17 MB,5168536 바이트

Windows 휴대용 실행 파일 속성

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
더 보기
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

파일 아이콘

Windows PE 버전 정보

이름 값
Company Name Google LLC
File Description
  • Google Installer (x86)
  • Google Update Updater
File Version
  • 152.0.7667.19
  • 46.1.8905.0
Internal Name
  • Google Installer (x86)
  • Google Update Updater
Legal Copyright Copyright 2026 Google LLC. All rights reserved.
Original Filename
  • Chrome.exe
  • google.exe
Product Name
  • Google Installer (x86)
  • Google Update Updater
Product Version
  • 152.0.7667.19
  • 46.1.8905.0

디지털 서명

서명자 뿌리 상태
Google LLC Google LLC Self Signed

파일 특성

  • dll
  • HighEntropy
  • Installer Version
  • WriteProcessMemory
  • x64

블록 정보

총 블록 수: 999
잠재적으로 악의적인 차단: 301
허용된 블록: 698
알 수 없는 블록: 0

시각적 지도

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x x 0 x 0 x 0 0 x x x x x 0 x x 0 x x x x x x x 0 x x 0 0 0 x x 0 x x x x x x x x x 0 x x x 0 x 0 x x 0 0 0 0 x x x x 0 0 0 x x x x x 0 x x x x x 0 0 x x x x x 0 x 0 x 0 x x x 0 x 0 x 0 0 x x x x x 0 0 x x 0 0 0 0 x 0 x 0 x 0 x 0 x x x x x 0 x 0 0 x x x x 0 x 0 x x x 0 x x 0 0 x x x x x x x 0 x x 0 x 0 x x x x x x x x 0 0 x x x x x x x x x 0 x 0 0 x x x 0 x x x 0 0 x x 0 x x x x x x x 0 0 0 0 x x x 0 x x x x 0 0 0 x x x x x x x 0 x 0 0 x 0 x 0 x 0 0 x x x 0 0 0 x x 0 0 0 x 0 x 0 x 0 x x x 0 x x x 0 x 0 x 0 x 0 x x 0 0 0 0 0 0 x x 0 x x x 0 x x 0 x 0 0 x x x 0 x x x x x x 0 0 x 0 x x x 0 x x x x x x 0 x x x 0 x x x x 0 0 x x x 0 x 0 x x x x x 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x 0 x x 0 x x 0 x 0 0 0 0 0 0 0 0 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x 0 x 0 x 0 x 0 x 0 0 0 0 x 0 x x x x x 0 x 0 x 0 x 0 0 x x x 0 0 0 x x x 0 0 0 0 x 0 0 0 x 0 0 0 0 0 x x x x 0 x 0 x x 0 x x x x x x x x 0 0 x x 0 x 0 0 x 0 x x x x x 0 0 x x 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 x 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - 안전 블록 가능성 높음
? - 알 수 없는 블록
x - 잠재적으로 악의적인 차단

비슷한 가족

  • Trojan.Agent.Gen.FQJ
  • Trojan.Agent.Gen.GAO
  • Trojan.Kryptik.Gen.KLV

수정된 파일

파일 속성
c:\users\user\appdata\local\google\chrome\bwhkcggxry\chrome140.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\google\chrome\bwhkcggxry\chrome140.exe Read Attributes,Synchronize,Write Attributes
c:\users\user\appdata\local\google\chrome\bwhkcggxry\google.dll Generic Write,Read Attributes
c:\users\user\appdata\local\google\chrome\bwhkcggxry\google.dll Read Attributes,Synchronize,Write Attributes
c:\users\user\appdata\local\google\chrome\bwhkcggxry\gupdt.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\google\chrome\bwhkcggxry\gupdt.exe Read Attributes,Synchronize,Write Attributes
c:\users\user\appdata\local\google\chrome\bwhkcggxry\gupw.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\google\chrome\bwhkcggxry\gupw.exe Read Attributes,Synchronize,Write Attributes
c:\users\user\ntuser.dat{53b39e87-18c4-11ea-a811-000d3aa4692b}.txr.3.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\ntuser.dat{53b39e87-18c4-11ea-a811-000d3aa4692b}.txr.4.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
더 보기
c:\users\user\ntuser.dat{53b39e87-18c4-11ea-a811-000d3aa4692b}.txr.5.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\ntuser.dat{53b39e87-18c4-11ea-a811-000d3aa4692b}.txr.6.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data

레지스트리 수정

키::값 데이터 API 이름
HKCU\software\google\chrome\bwhkcggxry::ldr x�} xW�����$���(�C�6qd�Q;m�eI���mՒ'M;�m��%�G�\C�jp ?��p,���fYh��rhR���XJ[����i!��ͦK��s�G�]�Z �}�;��s�9��s�}�h�}�1B �%�aG3����r�c���%�]u���*�p(a�ţC�?�D�־�5��XC���g��**Jk^!X"d�aΓwXˌ�d�.��HH�e�V!R�F"\��x� ��� RegNtPreCreateKey
HKCU\software\google\chrome\bwhkcggxry::lsz 雒 RegNtPreCreateKey
HKCU\software\google\chrome\bwhkcggxry::isz �p RegNtPreCreateKey
HKCU\software\google\chrome\bwhkcggxry::udir C:\Users\Lldqpajw\AppData\Local\Google\Chrome\bwhkcggxry RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::googleupdate140 "C:\Users\Lldqpajw\AppData\Local\Google\Chrome\bwhkcggxry\chrome140.exe" /user RegNtPreCreateKey

Windows API 사용법

범주 API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
더 보기
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtPowerInformation
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Service Control
  • OpenSCManager
  • OpenService
Encryption Used
  • BCryptOpenAlgorithmProvider