Threat Database Trojans Trojan.Agent.Gen.ERS

Trojan.Agent.Gen.ERS

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 27,467
Threat Level: 80 % (High)
Infected Computers: 1
First Seen: August 13, 2026
Last Seen: August 20, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Agent.Gen.ERS
Signature status: Hash Mismatch

Known Samples

MD5: f538b23a9d697bc0b56fa2e2a18f84b7
SHA1: 0ae7c4949925ad9bfcce189a6321c734161d7529
SHA256: 5DBAC1E46837BF70F945B1EC32BD5A8A2BAA68C0485E6819A82128471601954F
File Size: 507.90 KB, 507904 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File has exports table
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name Microsoft Corporation
File Description System Settings About Handlers Implementation
File Version 10.0.18362.1 (WinBuild.160101.0800)
Internal Name AboutSettingsHandlers.dll
Legal Copyright © Microsoft Corporation. All rights reserved.
Original Filename AboutSettingsHandlers.dll
Product Name Microsoft® Windows® Operating System
Product Version 10.0.18362.1

Digital Signatures

Signer Root Status
Microsoft Windows Microsoft Windows Production PCA 2011 Hash Mismatch

File Traits

  • big overlay
  • dll
  • ntdll
  • x64

Block Information

Total Blocks: 760
Potentially Malicious Blocks: 243
Whitelisted Blocks: 517
Unknown Blocks: 0

Visual Map

0 0 0 x x 0 x 0 0 0 x 0 0 x 0 0 0 0 0 x 0 x 0 0 0 0 x 1 x 1 0 0 x x 0 0 x 0 x 0 x 0 x 0 x 1 0 x x 1 0 x 0 0 x x x 0 0 0 x 0 x 0 x 0 0 0 0 0 0 0 0 x x x 0 x 0 x 0 x x x 0 0 x 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x 0 x x x x x 0 x 0 x x x x x x x x x x 0 x x x x 0 x x 0 x x 0 0 0 0 0 x x x x x 0 x 0 0 x x x x 0 0 0 x x 0 x x 0 x x 0 0 0 x x x x 0 0 0 x x x 1 x 1 0 x 1 x 0 0 0 x 0 0 x 0 x 0 0 0 x x x x x 1 x 1 x 0 x 0 0 x x 0 x 0 0 0 0 x x x 0 x 0 x 0 0 0 x 0 x 0 x 0 0 0 0 0 x x x 0 0 0 x x x 0 0 x x x x x x x 0 x 0 0 x x x 0 x x x 0 x x 0 x 0 x 0 x x x 0 0 0 x x x 0 0 x x x 0 x x x 0 x x 0 x 0 x 0 0 0 x x x x x x x 0 x x x 0 0 0 0 0 x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 x x x 0 x 0 x 0 0 x 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x 0 0 0 x 0 x 0 0 0 0 0 0 0 x 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 x 0 x x 0 x 0 x 0 0 x x x 0 0 0 0 0 0 0 x x x 0 0 0 x 0 0 0 0 0 0 0 x x 0 x 0 0 x 0 0 0 0 0 0 x 0 0 0 0 x 0 x 0 0 0 x 0 0 x 0 0 0 x x 0 x 0 x x x x 0 x x x x x x x 0 x x x 0 x 0 x 0 x 0 x 0 x x 0 x x x x x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 2 0 0 0 1 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �n+ �v����Bx&� (�1�1HO@V�A��H[uN$b"hk�ql(�tǤw�n{b��P���!�����7� ���3�������������m�Ù��'N�IV�V����$�8წ���Κ�l��&M���~�=�SB1_T�Vw�`�V��%���������AE�zH��D�� RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
Show More
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN