Threat Database Trojans Trojan.Agent.JGE

Trojan.Agent.JGE

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.Agent.JGE
Signature status: No Signature

Known Samples

MD5: 98f48049f1cd6866ec6aefd8925abbd7
SHA1: b373c383900ce7f9463f14a2c1b868d75ce5f77c
SHA256: 20ABCDDCD76AE1AD672DD61E918C4C2B4BC0BFC72CCDB99A5686EDB6521A359F
File Size: 136.57 KB, 136572 bytes
MD5: 000ce51d7e2ae2bd9d450737135cb415
SHA1: 8c1145cfdf8030b77a9c81ab03918794f454fc0f
SHA256: EDAA966A89241DFC5B4F425EDB2CBB9AD490DDCABCEB23AA149EC7881212F53D
File Size: 136.08 KB, 136078 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have resources
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • No Version Info
  • x64

Block Information

Total Blocks: 119
Potentially Malicious Blocks: 3
Whitelisted Blocks: 115
Unknown Blocks: 1

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.JGE
  • Agent.KPEC
  • BadJoke.GDA
  • DiskWriter.R
  • Diztakun.P
Show More
  • Kryptik.DKA
  • Rozena.BU
  • Rozena.XT
  • Rozena.XTA
  • Shutdowner.B
  • Trojan.Agent.Gen.TJ
  • Trojan.ShellcodeRunner.Gen.BW

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
Show More
  • UNKNOWN
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState

Trending

Most Viewed

Loading...