Threat Database Trojans Trojan.Agent.MBE

Trojan.Agent.MBE

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.Agent.MBE
Signature status: No Signature

Known Samples

MD5: 21b786ffbaaece233937914fe301f4b7
SHA1: bb89a36485fc164d2fd6226bc484a82f05cbdf10
SHA256: 077D3E5A67C26782B06F047581CB16FDF230B19613C347D31DA1B9E581D06893
File Size: 453.63 KB, 453632 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Dege's stuff
File Description dgVoodoo 2.86.2 Control Panel
File Version 2.8.6.2
Internal Name dgVoodooCpl.rc
Legal Copyright Copyright (C) 2013-2025
Original Filename dgVoodooCpl.exe
Product Name dgVoodoo
Product Version 2.8.6.2

File Traits

  • x86

Block Information

Total Blocks: 441
Potentially Malicious Blocks: 351
Whitelisted Blocks: 90
Unknown Blocks: 0

Visual Map

1 1 0 0 x x 0 x 0 x x x x x x x x x x x x x x x x x x x 0 0 x x x x 0 x x x 0 x x 0 x x x x x x x x 0 0 x x x 0 x x x x x 0 0 0 x x x 0 x x x x x x x 0 x x x x x x x x x x 0 x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x 0 0 x x 0 0 x x x x x x x 0 x 0 0 x x x x x x x x x x x x x x x 0 x 0 x x x x x 0 x x 0 x x x x x x 0 x 0 0 x x x x x 0 x x x x 0 0 x x x x 0 x x x x x x x x x 0 x x x x x x x x x x x x x 0 0 x 0 x x x 0 x x x x x x 0 x 0 x x x x x x x 0 x x x 0 0 x x x x x x 0 0 x 0 0 0 x x x x x 0 0 x x x x x x 1 1 1 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x 0 x x x x x x x x x x x 0 x x x x x 0 x 0 x 0 x x 0 x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x 0 0 0 0 0 x 0 0 0 0 x x 0 0 0 x x 0 x 0 x x x x 0 0 0 0 0 0 x 0 0 x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.MBE

Files Modified

File Attributes
c:\users\user\appdata\local\d3dscache Generic Read,Generic Execute,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 786496
c:\users\user\appdata\local\d3dscache\68aec72ef23ec3ac\f4eb2d6c-ed2b-4bdd-ad9d-f913287e6768.idx Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\d3dscache\68aec72ef23ec3ac\f4eb2d6c-ed2b-4bdd-ad9d-f913287e6768.lock Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\d3dscache\68aec72ef23ec3ac\f4eb2d6c-ed2b-4bdd-ad9d-f913287e6768.val Generic Read,Write Data,Write Attributes,Write extended,Append data

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation

Trending

Most Viewed

Loading...