Threat Database Trojans Trojan.Agent.CVH

Trojan.Agent.CVH

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.Agent.CVH
Signature status: No Signature

Known Samples

MD5: c51abe3b8995a4b82ddb8d511c6e4beb
SHA1: 12c071e39aeb111bfafa3560ca0cb8a4fb1c397d
SHA256: E9EF55C44EC8A16219538F4EEF31849B8E7B901E184A0463FD98E83C37BA4533
File Size: 256.51 KB, 256512 bytes
MD5: 70729ce3e47abe30d4217c744f9ae6a2
SHA1: a63e77c786670473d514eb7d17717efe39290f07
SHA256: A27DE130980E69AB8A3C370410882856464A128231C1C6C403F9AA4FB9D4625B
File Size: 257.02 KB, 257024 bytes
MD5: b3cf16c003db33edd478e49ca0f8681c
SHA1: 4fe17620bfba5d44e03692dbe8e13df6b75bd5e1
SHA256: D5DD9F6FEBE42A4870CE5F2CFF47CE01605E2F4A9DD3628023CC092D3BA3C791
File Size: 257.02 KB, 257024 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments
  • LunaTranslator v7.11
  • LunaTranslator v7.23
File Description LunaTranslator
File Version
  • 7.23.2.1
  • 7.23.1.0
  • 7.11.4.0
Internal Name LunaTranslator
Legal Copyright HIllya51 (C) 2025
Original Filename LunaTranslator
Product Name LunaTranslator
Product Version
  • 7.23.2.1
  • 7.23.1.0
  • 7.11.4.0

File Traits

  • HighEntropy
  • x64

Block Information

Total Blocks: 214
Potentially Malicious Blocks: 11
Whitelisted Blocks: 202
Unknown Blocks: 1

Visual Map

0 0 x x 0 0 0 0 x x 0 0 0 x 0 0 0 0 x 0 0 0 0 x 0 0 x x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 2 0 0 2 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.CVH

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
Show More
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState

Trending

Most Viewed

Loading...