Threat Database Trojans Trojan.Agent.KPA

Trojan.Agent.KPA

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.Agent.KPA
Signature status: No Signature

Known Samples

MD5: 630a279ef63576c066f07c1cb9e8b1ca
SHA1: f124f97cdb74f4d0f9da4173b86086909365c3e8
SHA256: 60F945D575E1F30CB228A7DE13E7D8172CFE0197A5DB196C0DC5C1DABD14410E
File Size: 136.00 KB, 136002 bytes
MD5: 57fda170c74bc7299b2c2a7ae192550e
SHA1: 32b273b29deab876020407ca3cf008cfbedf4853
SHA256: 6C748B24B519D3C0076E4653D46177F83D9F265C75E9FFEE06F5816F65107BB1
File Size: 131.97 KB, 131975 bytes
MD5: 0067ed5e424e0e6a544ce4fe01a3b386
SHA1: 6f7b0f22ee3c0458565901c1815bce7cde89ca74
SHA256: 899A0B38FE44DB2BA704375D3970814C20A567C4A265FC818B2BB3F2F67BD008
File Size: 136.00 KB, 136002 bytes
MD5: a0affbefb97e82430485aabba92edba7
SHA1: 34237e9df4608a8c2d8e65bbbf7d1138ca9573b2
SHA256: 88D66DCC41D54E5687B7742916B8ED60F77EEFC6139DDDFDE41D5BE5B707FA93
File Size: 132.20 KB, 132200 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • No Version Info
  • x64

Block Information

Total Blocks: 105
Potentially Malicious Blocks: 1
Whitelisted Blocks: 104
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.KPCA
  • Agent.PDFG
  • Agent.RAC
  • CobaltStrike.FSC
  • CobaltStrike.GP
Show More
  • Kryptik.FSEB
  • LockScreen.IA
  • LockScreen.KA
  • ReverseShell.GDA
  • ReverseShell.XI
  • Rozena.DTA
  • ShellcodeRunner.PFB
  • ShellcodeRunner.RF
  • ShellcodeRunner.RFA
  • ShellcodeRunner.RFB
  • Trojan.Agent.Gen.ALS
  • Trojan.Agent.Gen.BBK
  • Trojan.Injector.Gen.DIU
  • Trojan.Kryptik.Gen.BDJ
  • Trojan.Kryptik.Gen.CMI
  • Trojan.Kryptik.Gen.CWB
  • Trojan.ReverseShell.Gen.AC
  • Trojan.ShellcodeRunner.Gen.D
  • Trojan.ShellcodeRunner.Gen.LA

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Trending

Most Viewed

Loading...