Threat Database Trojans Trojan.Agent.GDFF

Trojan.Agent.GDFF

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.Agent.GDFF
Signature status: No Signature

Known Samples

MD5: c8a7b6c49d71bb77e4de68d27d282124
SHA1: 4329a8a87e8932a723a0be5192df977dc0e9b09a
SHA256: 4EDCEC268676CBD776DFCAB5E6D948BC8DCA81EC32F1427C96863B46F9819E03
File Size: 290.30 KB, 290304 bytes
MD5: 3334194f90694733b02ff0d800889c4a
SHA1: 4186ebd3f33feb247e94a69bc4ff4c66a7f20c05
SHA256: 24FCCCF7FC5935773FBBE538A525C2B8F16B03E82B7EEDE0E12C42BEF86B9612
File Size: 290.30 KB, 290304 bytes
MD5: 5134452ad61b1185f6d030ab0fc47511
SHA1: bab7a7e21d4dfc11e4f2aa3f88718286c830f548
SHA256: 05134C0384C1CF5F1E4AF77CC2A5E122286B3B6E0C91100DAE2DCF267ADB1B12
File Size: 290.30 KB, 290304 bytes
MD5: e9318de5224a92d8185523671d3b9b53
SHA1: 182c384a5e5502c0804185be52f5a8f71f4f4be9
SHA256: 26F154D58DE885502092765F8C0C98E6D051FCADE837696996DB7036317B55B2
File Size: 3.07 KB, 3072 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have resources
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • No Version Info
  • x86

Block Information

Total Blocks: 3
Potentially Malicious Blocks: 3
Whitelisted Blocks: 0
Unknown Blocks: 0

Visual Map

x x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.GDFF

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 RegNtPreCreateKey

Windows API Usage

Category API
Process Shell Execute
  • ShellExecute

Shell Command Execution

(NULL) 6c6914edd2d3100ae98c0b3de6a06f5e2eccb5d194cb24aed35a87598fe76d3d.exe
(NULL) Documents
(NULL) 323a413f1ee14b2f0240794acceaeec7a6e4ef0d0c50b51dd7cbe89137570bb8.exe
(NULL) CONTRATO 143 -TESORERIA.docx
(NULL) 1040e6a9db5901cffe43130edc0cf0f492ad398fea476fc5d2f94bb333e65c39.exe
Show More
(NULL) Stata-MP.v17.0.x64_

Trending

Most Viewed

Loading...