Threat Database Trojans Trojan.Agent.AIAF

Trojan.Agent.AIAF

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 15,382
Threat Level: 80 % (High)
Infected Computers: 577
First Seen: November 28, 2023
Last Seen: November 10, 2025
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Agent.AIAF
Signature status: No Signature

Known Samples

MD5: 55d41e1f30272e045a54ebe449dedc30
SHA1: 0a4d89675c864a20e79c1fc6b6f3e26e41c43f5a
SHA256: EB4DD91FF7B4DE9D4A39C36B918693C859AF335C84409B5577F15CDE04934002
File Size: 1.65 MB, 1652248 bytes
MD5: 36ad4b36cbd7ea2f61ac360d0bd85cf3
SHA1: 39171831d1ee80c3b3934dd9f4f7b78c1ca42206
SHA256: 0A6EC4391894F8D22FD0DD9EE06188E727C8DA173C5F69F0DE75FFF144B5FBB3
File Size: 1.54 MB, 1542335 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name Epic Games
File Description Easy Anti-Cheat Bootstrapper (EOS)
File Version 1.6.0.0
Internal Name EACLauncher.exe
Legal Copyright Copyright Epic Games, Inc.
Original Filename EACLauncher.exe
Product Name Easy Anti-Cheat Bootstrapper (EOS)
Product Version 1.6.0

File Traits

  • CryptUnprotectData
  • No CryptProtectData
  • ntdll
  • VirtualQueryEx
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 3,500
Potentially Malicious Blocks: 1,207
Whitelisted Blocks: 2,267
Unknown Blocks: 26

Visual Map

0 0 0 0 0 x x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x 0 x x x x 0 x x 0 0 x 0 x x x x 0 0 x x x x 0 0 0 0 x 0 0 x x x 0 x 0 0 x 0 0 x 0 0 x x x 0 0 0 0 x x x 0 0 x 0 x 0 x x x x x 0 0 0 0 x x x x 0 0 0 x 0 0 x 0 0 x 0 x x 0 0 0 0 x x x 0 x x x x 0 x x 0 x x x x x x x x x x x 0 x 0 x x x x x 0 x x x x x x x x x ? x ? x x x x x x 0 0 x 0 0 x 0 x x x x x x x x x x 0 0 x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x 0 x x 0 0 x 0 x x x x x x x x x x x x 0 0 x x x x x x x 0 0 x x x x 0 0 x 0 x x 0 x x x 0 x x 0 x x x x x 0 x x x x x x x 0 x x x x x 0 0 x 0 x x ? x x x 0 x 0 x x x x x 0 x x x ? x 0 x x x x x x x x x x 0 x 0 x 0 x 0 0 0 x x 0 x x 0 0 x x x x x 0 x x x x x 0 0 x x x x x x x x x x x x 0 x x x x x ? x x x x x x x x x x x x x x ? ? ? x x ? x x ? x 0 x x x x x ? ? 0 0 x 0 0 x x x ? x x 0 x x x x x 0 0 x x x x x x x x x x ? x x x x x ? x x x x x x x x x x x x x x x x x 0 x x x x x ? x x x x x 0 x 0 x x x x x x x 0 0 x x 0 0 x x x x x x 0 0 x 0 0 x 0 0 0 0 x x 0 0 x 0 x 0 0 0 x x 0 0 x x 0 x 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 ? x 0 ? x 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 x x 0 x 0 0 0 0 0 0 0 x 0 x 0 0 0 x 0 0 x 0 0 0 0 0 x x x x x x x x x 0 x 0 x x 0 0 x x x x x x x 0 0 x x 0 0 x x 0 x ? 0 x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x x x 0 x 0 0 0 0 0 x 0 0 0 0 x 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x x 0 x x 0 x 0 x x x x x x x x x 0 0 x x x x x 0 x x x x x x x x x x x 0 ? x x 0 0 0 x x 0 x x 0 ? 0 x x 0 0 1 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x x 0 0 0 ? 0 0 0 x x x 0 x x 0 x x 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x x 0 x x 0 x x x 0 ? x x x x x x 0 x x x 0 0 x x 0 0 0 x x x x x x x x 0 0 x x x x x x 0 0 0 0 x x 0 x 0 0 ? 0 0 0 0 0 0 0 0 x 0 x 0 x x 0 0 x 0 0 x 0 0 0 x 0 x x x x x x 0 x 0 0 x x x x x x x x 0 x 0 0 x 0 0 0 0 x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x x 0 0 0 x x 0 0 0 x x 0 x x 0 0 x 0 x x x x x x x x x x 0 x x 0 x x x x x x x x x 0 x x 0 x x x 0 x 0 x 0 0 0 0 x 0 x 0 0 0 x x 0 0 0 x x x 0 x 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x x x x 0 x x 0 x 0 x 0 0 0 x x x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 x 1 0 0 x x x x 0 x x 0 0 x x x x x 0 0 x x 0 x 0 x 0 x x 0 x 0 x 0 x 0 x x 0 x x x 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 x x 0 x x 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 x x 0 0 x 0 0 0 0 0 x x 0 0 0 0 0 0 x x x 0 x 0 1 0 x x x x x x x x 0 x 1 0 0 x 0 0 0 x 0 0 x x 0 0 x 0 0 0 x 0 0 x 0 0 x x x x 0 0 0 0 x 0 0 x x x x 0 x x x x x 0 0 x x 0 x 0 0 x 0 x 0 0 x x 0 x 0 x x x x x 0 0 x 0 x 0 x x 0 x x x x x x x 0 0 x x x x x x x x x x x x x x 0 x 0 0 x x x x x 0 x x x x x x 0 x 0 0 0 x x 0 x 0 0 x 0 x x 0 x x x x x x 0 x x x 0 x 0 0 0 x 0 0 x 0 0 x 0 x 0 x x x x x 0 x x x x 0 0 x x 0 x 0 x 0 0 x x x x 0 x x x x x x x x 0 x x x x x x x x x x x x x x x 0 x x x 0 x x x 0 x 0 x x 0 0 x 0 0 0 x 0 0 0 x x x x 0 0 x 0 x 0 x x 0 x x x 0 x x 0 x x 0 x x x 0 0 x 0 0 0 0 0 x 0 x x 0 0 0 0 1 0 x x x x x x x x x x x x x x x 0 x x x x x 0 0 x x 0 0 x 0 0 x x x 0 0 0 0 x 0 x x x 0 x 0 0 x x 0 0 0 0 x x x x x x x 0 x 0 0 0 x 0 x 0 x 0 x 0 x x 0 0 x x 0 x 0 x x 0 0 x x 0 0 0 0 x 0 x x x x x x x 0 0 x x 0 x x x 0 x 0 0 x x 0 x 0 0 0 x x x 0 0 0 x 0 0 x x 0 0 x x x x x 0 x 0 0 x 0 x x x 0 x x x 0 0 0 0 0 0 0 0 0 0 x x x x x x 0 x x x 0 x x 0 0 x x 0 0 x x 0 x x 0 x 0 0 0 x 0 0 x 0 x 0 0 x 0 0 x 0 0 x 0 x x x x x x 0 x x x 0 x x x x x x x 0 x x x x x x x x x x 0 0 x 0 0 x x 0 x x x x 0 0 0 x x 0 x x 0 x x x 0 x x x x x 0 x 0 x x 0 x x 0 x x x 0 0 0 x x 0 x x x x x x x x x x x x 0 0 x x x x x 0 x x x x x x 0 x x 0 x x x x x 0 x 0 x x x x 0 0 0 x x 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x 0 0 x x x x 0 0 x x x x x 0 x x x x x 0 x x x x x x 0 0 x x x 0 x 0 x x x 0 0 0 0 x 0 x x x 0 x x x x 0 x
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.AIAB
  • Agent.AIAF
  • Agent.AIAG

Files Modified

File Attributes
c:\programdata\officetrackernmp131\officetrackernmp131.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\maxloonafest131\maxloonafest131.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\fanbooster131\fanbooster131.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\rise131m9asphalt.tmp Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\run::maxloonafest131 C:\Users\Hiwhgvdd\AppData\Local\MaxLoonaFest131\MaxLoonaFest131.exe RegNtPreCreateKey

Windows API Usage

Category API
User Data Access
  • GetUserName
Process Shell Execute
  • CreateProcess
Network Winsock2
  • WSAStartup
Network Winsock
  • getaddrinfo
  • socket

Shell Command Execution

schtasks /create /f /RU "Hiwhgvdd" /tr "C:\ProgramData\OfficeTrackerNMP131\OfficeTrackerNMP131.exe" /tn "OfficeTrackerNMP131 HR" /sc HOURLY /rl HIGHEST
schtasks /create /f /RU "Hiwhgvdd" /tr "C:\ProgramData\OfficeTrackerNMP131\OfficeTrackerNMP131.exe" /tn "OfficeTrackerNMP131 LG" /sc ONLOGON /rl HIGHEST

Trending

Most Viewed

Loading...