Threat Database Trojans Trojan.Agent.GHW

Trojan.Agent.GHW

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.Agent.GHW
Signature status: Hash Mismatch

Known Samples

MD5: e8f18ad76aba343f5176113ab890c1d4
SHA1: 7df223c136d0e7f823fd5169e2abf95aa8569f33
SHA256: BD8C5DB460A665AB669E6C8D695319DF68035B6E72A17EDF17C086CD9E3FB1A0
File Size: 2.39 MB, 2385136 bytes
MD5: 668c2b45ab7e74d36a514290599088eb
SHA1: d70c1b8373887df80f3652654895c5dfa0c14436
SHA256: 32CFFF30D6ED1F3395B8FFBC8319FAD8723F71547364A6CDE2FADDB2B80B5B1D
File Size: 2.06 MB, 2062928 bytes
MD5: b633c10826ade41fb2029c0ec6abb6c7
SHA1: e751470bec5c7c1e42fc89d3dc48ed51aba4074f
SHA256: DEC46207A352D2B8F21B6EE5698FE4C45C56CD09B2C13FFDA28736C60BABCDFB
File Size: 2.12 MB, 2123896 bytes
MD5: e66b896882f72d5011371b1eb296a594
SHA1: 52586243e0e11b8621c1d69347a77420be60b659
SHA256: 22ACA3698972EBB96A70D9EF2131BCF9718F74C99A904FC285BFD4798D32DC92
File Size: 2.16 MB, 2164920 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • DBSofts
  • Epic Games, Inc.
  • Surfshark
File Description
  • Easy Anti-Cheat Service (EOS)
  • ESF Database Migration Toolkit
  • Surfshark Installer
File Version
  • 2022.3.41.1022081
  • 12.2.0.9
  • 5.16.1999
Internal Name
  • Easy Anti-Cheat Service (EOS)
  • ESF Database Migration Toolkit
  • SurfsharkSetup
Legal Copyright
  • (c) 2005-2024 Unity Technologies. All rights reserved.
  • Copyright (C) 2025 Surfshark
  • Copyright (C) DBSofts Inc
  • Copyright Epic Games, Inc. All Rights Reserved.
Original File Name SurfsharkSetup.exe
Original Filename DMTW.exe
Product Name
  • Easy Anti-Cheat Service (EOS)
  • ESF Database Migration Toolkit
  • Surfshark
Product Version
  • 2022.3.41f1 (0f988161febf)
  • 12.2.0.9
  • 5.16.1999
  • 1.4.0

Digital Signatures

Signer Root Status
Mooii Tech co.,ltd. Class 3 Public Primary Certification Authority Hash Mismatch
EasyAntiCheat Oy GlobalSign Code Signing Root R45 Hash Mismatch
Surfshark B.V. GlobalSign Code Signing Root R45 Hash Mismatch
Huang Qinyin SSL.com Code Signing Intermediate CA ECC R2 Hash Mismatch

File Traits

  • 2+ executable sections
  • golang
  • HighEntropy
  • Installer Version
  • x64

Block Information

Total Blocks: 556
Potentially Malicious Blocks: 0
Whitelisted Blocks: 556
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.GHW
  • GoBot
  • GoBot.B
  • Injector.GSF

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtProtectVirtualMemory
Show More
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryTimerResolution
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimerResolution
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • ntdll.dll!NtYieldExecution
  • UNKNOWN
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState

Trending

Most Viewed

Loading...