Threat Database Trojans Trojan.Agent.GDSHA

Trojan.Agent.GDSHA

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.Agent.GDSHA
Signature status: No Signature

Known Samples

MD5: 2e2669a33eace6d3a59a8e45c3324fdf
SHA1: 18291592b731ac519bd371d25beafb092dc72570
SHA256: 6E6CE6A918228FC609ECD2682CEA75E470CFBD3AA2A0A5BAFAD40A7DACBDA51F
File Size: 55.30 KB, 55296 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • No Version Info
  • x86

Block Information

Total Blocks: 209
Potentially Malicious Blocks: 16
Whitelisted Blocks: 191
Unknown Blocks: 2

Visual Map

0 x x x x x x x ? ? 0 0 x x x x x x 0 x x x 0 0 0 1 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 1 1 0 0 0 1 0 0 0 2 3 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 1 0 0 0 0 0 2 2 1 0 0 1 0 0 1 1 1 0 0 0 0 0 1 0 0 0 0 1 1 0 0 1 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
Generic Write,Read Attributes,Delete,LEFT 262144
Generic Write,Read Data,Read Attributes,Delete,LEFT 262144
c:\users\user\appdata\local\temp\dfil1.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\dfil2.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\dfil3.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\dfil4.exe Generic Write,Read Attributes
c:\users\user\desktop\documents backup.lnk Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\desktop\update.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\desktop\update.exe Synchronize,Write Attributes
Show More
c:\users\user\downloads\update.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\downloads\update.exe Synchronize,Write Attributes
c:\users\user\update.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\update.exe Synchronize,Write Attributes
c:\windows\appcompat\programs\amcache.hve Read Data,Read Control,Write Data
c:\windows\appcompat\programs\amcache.hve.log1 Read Data,Write Data
c:\windows\appcompat\programs\amcache.hve.log2 Read Data,Write Data

Registry Modifications

Key::Value Data API Name
HKLM\software\classes\txtfile\shell\open\command:: "c:\users\user\downloads\18291592b731ac519bd371d25beafb092dc72570_0000055296" "%1" RegNtPreCreateKey

Windows API Usage

Category API
Network Wininet
  • InternetOpen
  • InternetOpenUrl
  • InternetReadFile
Process Shell Execute
  • CreateProcess
Network Lmaccess
  • NetShareEnum

Shell Command Execution

C:\Users\Tasmedts\AppData\Local\Temp\DfIl1.exe (NULL)
C:\Users\Tasmedts\AppData\Local\Temp\DfIl2.exe (NULL)
C:\Users\Tasmedts\AppData\Local\Temp\DfIl3.exe (NULL)
C:\Users\Tasmedts\AppData\Local\Temp\DfIl4.exe (NULL)

Trending

Most Viewed

Loading...