Threat Database Trojans Trojan.Agent.Gen.ESR

Trojan.Agent.Gen.ESR

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 27,469
Threat Level: 80 % (High)
Infected Computers: 1
First Seen: August 13, 2026
Last Seen: August 20, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Agent.Gen.ESR
Signature status: No Signature

Known Samples

MD5: 016258e3e449f7e3b65498f50f1075c1
SHA1: a7377cc95b59dbb2f7d360c6288c8560b43c73b5
SHA256: 7769E414CA1D18A3A0A124D839F0119294390C77E7331B1E9AA8CD9566180291
File Size: 401.41 KB, 401408 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have security information
  • File has exports table
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name Microsoft Corporation
File Description Cortana Action Manager
File Version 10.0.18362.1 (WinBuild.160101.0800)
Internal Name Cortana Action Manager
Legal Copyright © Microsoft Corporation. All rights reserved.
Original Filename ACTIONMGR.DLL
Product Name Microsoft® Windows® Operating System
Product Version 10.0.18362.1

File Traits

  • big overlay
  • dll
  • ntdll
  • x64

Block Information

Total Blocks: 270
Potentially Malicious Blocks: 69
Whitelisted Blocks: 201
Unknown Blocks: 0

Visual Map

0 0 0 0 0 x 0 0 x 0 0 x 0 0 0 0 1 0 0 0 0 1 0 0 0 0 2 0 0 0 1 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 x x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x x x x x x x x x x 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x 0 0 x x x 0 x x x x 0 x x 0 0 0 x 0 0 x 0 x x x 0 0 0 x x x x 0 0 0 x 0 x x 0 x x x 0 0 0 x x 0 x x 0 0 x 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 x x 0 x 0 x 0 0 x x 0 0 0 0 0 0 0 x x x x 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
Show More
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN