Threat Database Trojans Trojan.Agent.DV

Trojan.Agent.DV

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 15,780
Threat Level: 80 % (High)
Infected Computers: 33
First Seen: July 27, 2022
Last Seen: December 5, 2025
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Agent.DV
Signature status: No Signature

Known Samples

MD5: 6c79177fd0c299dd81ae03fc9c0e0b3d
SHA1: 0b39a8786b663967b41c27e531088e8bfa868415
SHA256: 6E2CD955BFE556F2719D786396D59EF0EC31B49D00A3DDC49A67C698C7FE8810
File Size: 2.87 MB, 2868201 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
File Version 3, 1, 0, 4
Original Filename swengine.exe
Product Version 3, 1, 0, 0

File Traits

  • WinZip SFX
  • x86
  • ZIP (In Overlay)

Files Modified

File Attributes
c:\users\user\appdata\local\temp\rde906.tmp\____mmfp.ocx Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\rde906.tmp\____mmfp.ocx Generic Write,Read Attributes
c:\users\user\appdata\local\temp\rde906.tmp\____mmfp.ocx Synchronize,Write Attributes
c:\users\user\appdata\local\temp\rde906.tmp\____swmx Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\rde906.tmp\____swmx Generic Write,Read Attributes
c:\users\user\appdata\local\temp\rde906.tmp\____swmx Synchronize,Write Attributes
c:\users\user\appdata\local\temp\rde906.tmp\____swmxs Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\rde906.tmp\____swmxs Generic Write,Read Attributes
c:\users\user\appdata\local\temp\rde906.tmp\____swmxs Synchronize,Write Attributes
c:\users\user\appdata\local\temp\rde906.tmp\dpolmap.swf Generic Read,Write Data,Write Attributes,Write extended,Append data
Show More
c:\users\user\appdata\local\temp\rde906.tmp\dpolmap.swf Generic Write,Read Attributes
c:\users\user\appdata\local\temp\rde906.tmp\dpolmap.swf Synchronize,Write Attributes
c:\users\user\appdata\local\temp\rde906.tmp\rde907.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\rde906.tmp\rde907.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\rde906.tmp\rde908.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\rde906.tmp\rde908.tmp Generic Write,Read Attributes
c:\users\user\appdata\roaming\macromedia\flash player\#sharedobjects\aocwauan\localhost\users\user\downloads\0b39a8786b663967b41c27e531088e8bfa868415_0002868201\sw3_6161430.sol Generic Read,Write Data,Write Attributes,Write extended,Append data

Registry Modifications

Key::Value Data API Name
HKLM\software\classes\typelib\{873efd18-33bc-4e25-921f-ebd42eb51126}\1.0:: swmxengine Type Library RegNtPreCreateKey
HKLM\software\classes\typelib\{873efd18-33bc-4e25-921f-ebd42eb51126}\1.0\flags:: 0 RegNtPreCreateKey
HKLM\software\classes\typelib\{873efd18-33bc-4e25-921f-ebd42eb51126}\1.0\0\win32:: c:\users\user\downloads\0b39a8786b663967b41c27e531088e8bfa868415_0002868201\1 RegNtPreCreateKey
HKLM\software\classes\typelib\{873efd18-33bc-4e25-921f-ebd42eb51126}\1.0\helpdir:: c:\users\user\downloads RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{b3c01eee-068d-4609-8f4e-72e3f7e80b30}:: _IScreenweaverScript_FlashEvents RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{b3c01eee-068d-4609-8f4e-72e3f7e80b30}\proxystubclsid32:: {00020420-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{b3c01eee-068d-4609-8f4e-72e3f7e80b30}\typelib:: {873EFD18-33BC-4E25-921F-EBD42EB51126} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{b3c01eee-068d-4609-8f4e-72e3f7e80b30}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{b3c01eee-068d-4609-8f4e-72e3f7e80b30}:: _IScreenweaverScript_FlashEvents RegNtPreCreateKey
HKLM\software\classes\interface\{b3c01eee-068d-4609-8f4e-72e3f7e80b30}\proxystubclsid32:: {00020420-0000-0000-C000-000000000046} RegNtPreCreateKey
Show More
HKLM\software\classes\interface\{b3c01eee-068d-4609-8f4e-72e3f7e80b30}\typelib:: {873EFD18-33BC-4E25-921F-EBD42EB51126} RegNtPreCreateKey
HKLM\software\classes\interface\{b3c01eee-068d-4609-8f4e-72e3f7e80b30}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8a81c0b5-29bf-43d3-9165-49568262b70c}:: IScreenweaverFlashObject RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8a81c0b5-29bf-43d3-9165-49568262b70c}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8a81c0b5-29bf-43d3-9165-49568262b70c}\typelib:: {873EFD18-33BC-4E25-921F-EBD42EB51126} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8a81c0b5-29bf-43d3-9165-49568262b70c}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{8a81c0b5-29bf-43d3-9165-49568262b70c}:: IScreenweaverFlashObject RegNtPreCreateKey
HKLM\software\classes\interface\{8a81c0b5-29bf-43d3-9165-49568262b70c}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{8a81c0b5-29bf-43d3-9165-49568262b70c}\typelib:: {873EFD18-33BC-4E25-921F-EBD42EB51126} RegNtPreCreateKey
HKLM\software\classes\interface\{8a81c0b5-29bf-43d3-9165-49568262b70c}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{9c2eb1e6-f11c-4f76-8eec-0b9ccd0e6131}:: IScreenweaverFlashArray RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{9c2eb1e6-f11c-4f76-8eec-0b9ccd0e6131}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{9c2eb1e6-f11c-4f76-8eec-0b9ccd0e6131}\typelib:: {873EFD18-33BC-4E25-921F-EBD42EB51126} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{9c2eb1e6-f11c-4f76-8eec-0b9ccd0e6131}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{9c2eb1e6-f11c-4f76-8eec-0b9ccd0e6131}:: IScreenweaverFlashArray RegNtPreCreateKey
HKLM\software\classes\interface\{9c2eb1e6-f11c-4f76-8eec-0b9ccd0e6131}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{9c2eb1e6-f11c-4f76-8eec-0b9ccd0e6131}\typelib:: {873EFD18-33BC-4E25-921F-EBD42EB51126} RegNtPreCreateKey
HKLM\software\classes\interface\{9c2eb1e6-f11c-4f76-8eec-0b9ccd0e6131}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{3a6a129b-a0eb-4fb6-b474-56d8b3ba34ad}:: IScreenweaverScript RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{3a6a129b-a0eb-4fb6-b474-56d8b3ba34ad}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{3a6a129b-a0eb-4fb6-b474-56d8b3ba34ad}\typelib:: {873EFD18-33BC-4E25-921F-EBD42EB51126} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{3a6a129b-a0eb-4fb6-b474-56d8b3ba34ad}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{3a6a129b-a0eb-4fb6-b474-56d8b3ba34ad}:: IScreenweaverScript RegNtPreCreateKey
HKLM\software\classes\interface\{3a6a129b-a0eb-4fb6-b474-56d8b3ba34ad}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{3a6a129b-a0eb-4fb6-b474-56d8b3ba34ad}\typelib:: {873EFD18-33BC-4E25-921F-EBD42EB51126} RegNtPreCreateKey
HKLM\software\classes\interface\{3a6a129b-a0eb-4fb6-b474-56d8b3ba34ad}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{c8046ab4-bbf7-430e-b854-2496ac8bea59}:: IScreenweaverScript_Flash RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{c8046ab4-bbf7-430e-b854-2496ac8bea59}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{c8046ab4-bbf7-430e-b854-2496ac8bea59}\typelib:: {873EFD18-33BC-4E25-921F-EBD42EB51126} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{c8046ab4-bbf7-430e-b854-2496ac8bea59}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{c8046ab4-bbf7-430e-b854-2496ac8bea59}:: IScreenweaverScript_Flash RegNtPreCreateKey
HKLM\software\classes\interface\{c8046ab4-bbf7-430e-b854-2496ac8bea59}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{c8046ab4-bbf7-430e-b854-2496ac8bea59}\typelib:: {873EFD18-33BC-4E25-921F-EBD42EB51126} RegNtPreCreateKey
HKLM\software\classes\interface\{c8046ab4-bbf7-430e-b854-2496ac8bea59}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{43895b07-f220-4f6e-88ec-38e400ed4125}:: IFlashHostSite RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{43895b07-f220-4f6e-88ec-38e400ed4125}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{43895b07-f220-4f6e-88ec-38e400ed4125}\typelib:: {873EFD18-33BC-4E25-921F-EBD42EB51126} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{43895b07-f220-4f6e-88ec-38e400ed4125}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{43895b07-f220-4f6e-88ec-38e400ed4125}:: IFlashHostSite RegNtPreCreateKey
HKLM\software\classes\interface\{43895b07-f220-4f6e-88ec-38e400ed4125}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{43895b07-f220-4f6e-88ec-38e400ed4125}\typelib:: {873EFD18-33BC-4E25-921F-EBD42EB51126} RegNtPreCreateKey
HKLM\software\classes\interface\{43895b07-f220-4f6e-88ec-38e400ed4125}\typelib::version 1.0 RegNtPreCreateKey

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
User Data Access
  • GetComputerName
  • GetUserName
  • GetUserObjectInformation

Trending

Most Viewed

Loading...