Threat Database Trojans Trojan.Agent.LFGA

Trojan.Agent.LFGA

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.Agent.LFGA
Signature status: Hash Mismatch

Known Samples

MD5: 55530b918a3e4bce008d90577fa24bc7
SHA1: 30a94fda026d74717f393be7034e95e0e5755baf
SHA256: 4D6274B9FF920844A1F8223A2BDBF6AA80B7F8FCCCBD99217361CB3E946976EB
File Size: 43.30 KB, 43304 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Comments Free and open source software for video recording and live streaming
Company Name OBS Project
File Description OBS Library D3D11 wrapper
File Version 30.0.0
Internal Name libobs-d3d11
Legal Copyright (C) Lain Bailey
Original Filename libobs-d3d11
Product Name OBS Studio
Product Version 30.0.0

Digital Signatures

Signer Root Status
Digiarty Software, Inc. DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Hash Mismatch

File Traits

  • dll
  • x86

Block Information

Total Blocks: 87
Potentially Malicious Blocks: 8
Whitelisted Blocks: 78
Unknown Blocks: 1

Visual Map

0 0 0 x ? 0 0 x x x 0 0 0 0 x x 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 3 1 2 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Trojan.ShellcodeRunner.Gen.OB

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWriteFile
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\30a94fda026d74717f393be7034e95e0e5755baf_0000043304.,LiQMAxHB

Trending

Most Viewed

Loading...