Threat Database Trojans Trojan.Agent.FYG

Trojan.Agent.FYG

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 19,858
Threat Level: 80 % (High)
Infected Computers: 6
First Seen: May 9, 2025
Last Seen: July 21, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Agent.FYG
Signature status: No Signature

Known Samples

MD5: 01a5377e0b9b61fca957f5d0655b76a7
SHA1: 74620022cebc94b60fe0f34f334a464c8c3dbf5b
SHA256: E5F9744F17089AF9CD5894DCCF9B7BD0D49743EE0651B24DFA9B2DA206359305
File Size: 1.85 MB, 1846784 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have security information
  • File has exports table
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Comments Accinged nicked disseise hysterotome hillberry
Company Name Scabbling provoking
File Description Emends zucchetti cabestro
File Version 1.284.202.8
Internal Name Clapped scalpture
Legal Copyright Copyright © Buninahua palladiumizing appalto amphimixis nasoturbinal
Legal Trademarks Adustion swigger subjectification colymbion
Original Filename Scuddick cacophonist
Product Name Clubrooms
Product Version 1.284.202.8

File Traits

  • dll
  • HighEntropy
  • x64

Block Information

Total Blocks: 315
Potentially Malicious Blocks: 32
Whitelisted Blocks: 195
Unknown Blocks: 88

Visual Map

x ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 2 0 0 0 2 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x ? ? ? x x x x x ? x x ? ? ? x x ? 0 0 x ? ? 0 0 1 1 0 1 1 0 0 0 0 0 ? x ? x 0 ? ? ? ? ? ? ? ? x 0 x x 0 ? x ? ? x x ? 0 x x x x ? 0 ? 0 ? ? ? ? ? x ? ? x 0 x ? ? x 0 x x ? 0 ? 0 ? ? ? ? ? ? 0 ? x ? ? ? ? ? ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\0gj\071ip1w\sark Generic Write,Read Attributes
c:\3u0h\cashbox\cfz\e\nhu Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\aeries\kpqme\a9lge\calciferol\yze Generic Write,Read Attributes
c:\clogging\thyxbyt Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\cunj5bf\n\solitudinized Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\disapprovingly\consarned Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\hs\sulphindigotic\u\mqahvvv\im6 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\loranthaceae\capman\ariosos\l\h5 Generic Write,Read Attributes
c:\maytenus\1nqvxg\2h7yyxy\hh8rq\hmg Generic Write,Read Attributes
Show More
c:\nllw\preoppressor\announcers\alazor\sd9xcn Generic Write,Read Attributes
c:\preoccupancy\alisos Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\xb7gjs\pohna\e0iada\k8pzqq\origan Generic Write,Read Attributes

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
Show More
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWriteFile