Threat Database Trojans Trojan.Agent.GHDE

Trojan.Agent.GHDE

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.Agent.GHDE
Signature status: No Signature

Known Samples

MD5: 735e436f901acb511cf8a8be68338a56
SHA1: 1945bc73d0a44a1e218f7d4981385d69f712e7a2
SHA256: E707E9372186300292EC4890C8485CA6C287CDBCE55CE6F1C1DCD8A64243B992
File Size: 6.97 MB, 6967309 bytes
MD5: f1087605f954a8e8740ab5636f67ab14
SHA1: c01808190671ac227e26254a4af85292c2bb755f
SHA256: 4651A7021CA5EA50652F7ABA744EDBA0B7EC44FA56CE711570408C73595958D7
File Size: 8.80 MB, 8799600 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Igor Pavlov
File Description 7z Setup SFX
File Version 9.20
Internal Name 7zS.sfx
Legal Copyright Copyright (c) 1999-2010 Igor Pavlov
Original Filename 7zS.sfx.exe
Product Name 7-Zip
Product Version 9.20

File Traits

  • No Version Info
  • x86

Files Modified

File Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\adobenotificationhelper.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\adobenotificationhelper.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\config.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\config.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\coresyncinstall.log Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\coresyncinstall.log Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\fruity convolver.nfo Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\fruity convolver.nfo Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\fruity formula controller.fst Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\7zs3dff.tmp\fruity formula controller.fst Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\fruity reeverb 2.png Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\fruity reeverb 2.png Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\install.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\install.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\license.rtf Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\license.rtf Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\microsoft_vc110_cxxamp_x64.msm Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\microsoft_vc110_cxxamp_x64.msm Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\microsoft_vc120_crt_x64.msm Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\microsoft_vc120_crt_x64.msm Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\microsoft_vc120_debugcxxamp_x64.msm Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\microsoft_vc120_debugcxxamp_x64.msm Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\microsoft_vc120_debugcxxamp_x86.msm Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\microsoft_vc120_debugcxxamp_x86.msm Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\unzip32.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\unzip32.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\vrfauto.h Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs3dff.tmp\vrfauto.h Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs44c5.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs44c5.tmp\agentactivationruntimestarter.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs44c5.tmp\agentactivationruntimestarter.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs44c5.tmp\config.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs44c5.tmp\config.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs44c5.tmp\install.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs44c5.tmp\install.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\7zs44c5.tmp\wmsyspr9.prx Generic Write,Read Attributes
c:\users\user\appdata\local\temp\7zs44c5.tmp\wmsyspr9.prx Synchronize,Write Attributes

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess

Shell Command Execution

.\Install.exe
config.exe /hdidmrvG "390358" /S

Trending

Most Viewed

Loading...