Threat Database Trojans Trojan.Agent.KOSD

Trojan.Agent.KOSD

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 11,324
Threat Level: 80 % (High)
Infected Computers: 11
First Seen: January 29, 2026
Last Seen: May 5, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Agent.KOSD
Signature status: No Signature

Known Samples

MD5: 7019f78104ebaa5f5a7730aeb809b5f1
SHA1: 4a59c499253ddb9b10f11ce3e4b4137993b024f2
SHA256: 28650AEFC8DCA900EC5CCF7A5A16C5CBD55F6F8CFBFFD9ECF3DFDC365A34D333
File Size: 472.06 KB, 472064 bytes
MD5: 2511d615de03a8e890ecb79904c83b51
SHA1: d486735c249000f3ce2259b7a2d662cce31ecd9f
SHA256: FD59C9F768AEDB0F66228A83D73A957C0A3E4D379160D4C10B9E3517130AEC8B
File Size: 471.55 KB, 471552 bytes
MD5: 4542f555836a77d6c7b99c29fc8632db
SHA1: 5dd984f9d5e5ef8184ce736fd2452aea86cdaecb
SHA256: 59DABE1534B2564E2AA411870294D89E91DD5D1A4AB46E99AA4AE7959CAF5847
File Size: 472.06 KB, 472064 bytes
MD5: 7d5411b7611093fa25591f05a99fddef
SHA1: 1b553ade35f5000d319c101ba3cb57e36395f206
SHA256: 7FB89E6210CA8EFDD7022F3A41820420D6145F03344E6BE77F13D51A41A29316
File Size: 471.55 KB, 471552 bytes
MD5: 0d18353a6d62114f3f2c54015a789a19
SHA1: 073516bc8faa78e816f12fd18680490f216c972e
SHA256: 1E318CCEFD7B1373ACDEB98AD9D0AA45AC2F0732226A50305C34DA1362EEB82B
File Size: 471.55 KB, 471552 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name
  • International True Ventures
  • Sigma17.15 Department
  • Spiral.vertex Resources
  • Terra PLC
  • The Mega Crown Company
File Description
  • Apex Pipeline Link Frontend Service
  • Evolving Recovery for Packaging
  • Initiator Science Backup Gatherer
  • Organic Column Framework
  • Robust Pooler for Environment
File Version
  • 2026.1.22.3
  • 12.10.36.196
  • 8.33.749.6264
  • 3.42.11.965
  • 2.77.785.8318
Internal Name
  • 849ef1_path
  • controller_main
  • crest_starter
  • entitybroker
  • rule_valu
Legal Copyright
  • 2021 Sigma17.15 Department. All Rights Reserved.
  • Copyright (C) 2022, Spiral.vertex Resources. All Rights Reserved.
  • Copyright 2023 Terra PLC
  • Copyright 2023. The Mega Crown Company
  • International True Ventures, Copyright 2025
Original Filename
  • 849ef1_path.exe
  • controller_main.exe
  • crest_starter.exe
  • entitybroker.exe
  • rule_valu.exe
Product Name
  • Chief ML Connect
  • Deep Crypto Stunning Coach
  • Discount Surface Adaptive Terminator
  • ML Deep Builder
  • Options Profile Detector
Product Version
  • 12.5.12.175
  • 9.8.61.8193
  • 8.33.749.6264
  • 3.42.11.965
  • 2.77.785.8318

File Traits

  • HighEntropy
  • x64

Block Information

Total Blocks: 147
Potentially Malicious Blocks: 78
Whitelisted Blocks: 69
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x 0 x x x x 0 x x x x x x x x x x x x x 0 x x x x 0 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.KOSD

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreateResourceReserve
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcQueryInformationMessage
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtAlpcSetInformation
  • ntdll.dll!NtApphelpCacheControl
Show More
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtGetCompleteWnfStateSubscription
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Network Wininet
  • HttpOpenRequest
  • HttpSendRequest
  • InternetConnect
  • InternetOpen
  • InternetReadFile
Network Winhttp
  • WinHttpOpen
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext

Trending

Most Viewed

Loading...