Threat Database Trojans Trojan.Agent.Gen.FMR

Trojan.Agent.Gen.FMR

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 0
First Seen: September 16, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Agent.Gen.FMR
Signature status: No Signature

Known Samples

MD5: 4c50f672db85076c7ae04179af794e64
SHA1: e797807df88ab5299867da0bc2f53f9105f1af64
SHA256: F4FCA18CA97257BCAE8A78B616D476EEF1C95BDFC5F493408BAF237C904FCB80
File Size: 703.49 KB, 703488 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name streihlurraeg LLC
File Version 2.2.35.5056
Internal Name Ferryaurs.exe
Original Filename Ferryaurs.exe
Product Name Ferryaurs
Product Version 2.2.35.5056

File Traits

  • GetConsoleWindow
  • ntdll
  • x64

Block Information

Total Blocks: 665
Potentially Malicious Blocks: 39
Whitelisted Blocks: 473
Unknown Blocks: 153

Visual Map

? x 0 ? ? 0 x ? x 0 ? x 0 ? 0 x x x x ? 0 ? 0 ? ? 0 ? ? ? x ? x ? ? 0 0 ? x 0 x ? ? ? ? 0 x x x ? 0 0 0 ? ? 0 0 0 ? 0 x x ? ? ? ? ? ? ? x ? 0 ? 0 ? ? ? ? x ? ? ? ? ? 0 ? ? ? ? 0 0 ? ? ? ? ? ? 0 ? x ? 0 ? ? ? ? ? ? 0 ? ? ? 0 ? ? 0 ? ? ? ? 0 ? ? ? ? ? 0 ? ? ? 0 0 0 0 ? ? ? ? 0 ? ? ? ? ? ? x ? x ? ? ? ? ? ? ? x 0 ? 0 ? x ? ? ? ? 0 0 ? 0 1 ? ? ? ? ? ? 0 ? 0 0 ? x ? x ? ? 0 ? 0 x 0 ? x 0 ? 0 0 0 x 0 ? ? ? ? ? x x 0 0 0 ? 0 ? ? x ? x 0 ? ? ? ? ? 0 0 0 ? 0 ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 2 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x 0 ? x ? 0 0 0 0 0 x 0 0 x ? x ? ? 0 ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtWriteFile
  • UNKNOWN