Threat Database Trojans Trojan.Agent.LOFD

Trojan.Agent.LOFD

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 21,352
Threat Level: 80 % (High)
Infected Computers: 3
First Seen: August 13, 2025
Last Seen: March 31, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Agent.LOFD
Signature status: No Signature

Known Samples

MD5: d439bc1f86783032d884a4ea9ec6e372
SHA1: 902b8d99befb5896f8ce1dcdbacdbb030ccd40cd
SHA256: 75A5B876BF2ABB67CA0D47807E00C228E3E8F48656C53109C541A3D5BF380AC7
File Size: 368.72 KB, 368718 bytes
MD5: f431df354b1ad6aa0f62bd4b7bef4797
SHA1: 33e8ba920dff6f73a9dca79234b201416cf055ba
SHA256: DA578C2A811CF55A8D91A2EF221069BCDF281DFB828A8A15F88493C029ADD828
File Size: 37.89 KB, 37888 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
File Version 1.00
Internal Name TJprojMain
Original Filename TJprojMain.exe
Product Name Project1
Product Version 1.00

File Traits

  • fptable
  • No Version Info
  • x64

Block Information

Total Blocks: 127
Potentially Malicious Blocks: 1
Whitelisted Blocks: 122
Unknown Blocks: 4

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 ? ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 1 0 1 2 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Other Suspicious
  • SetWindowsHookEx
Syscall Use
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Network Urlomon
  • URLDownloadToFile

Trending

Most Viewed

Loading...