Threat Database Trojans Trojan.Agent.MYF

Trojan.Agent.MYF

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.Agent.MYF
Signature status: Self Signed

Known Samples

MD5: 0133b3826a5207065de8564b9efb49f1
SHA1: 7efc681385cbea76bfec12fe365247c7f3031813
SHA256: 58EEB125E65881FF53D133D6DF64488B9773701AC6261712FCBD2DF2E8BC88FE
File Size: 1.32 MB, 1324976 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have relocations information
  • File has exports table
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments Modified By DSystem mdyblog.blog.163.com 茂名市第二中学 老九
Company Name DSystem
File Description WinPE Commander (Modified By DSystem mdyblog.blog.163.com)
File Version 201201.88.05.94 X64
Legal Copyright NoCopyRight (L) 2012-2015 DSystem Non rights reserved.
Original Filename PECMD.EXE
Product Name PECMD
Product Version 201201.88.05.94

Digital Signatures

Signer Root Status
Copyright(C) 2013-2024 51Cxsoft.com 版权所有 Copyright(C) 2013-2024 51Cxsoft.com 版权所有 Self Signed
Copyright(C) 2013-2024 51Cxsoft.com 版权所有 Copyright(C) 2013-2024 51Cxsoft.com 版权所有 Self Signed

File Traits

  • x64

Block Information

Total Blocks: 2,225
Potentially Malicious Blocks: 1,536
Whitelisted Blocks: 689
Unknown Blocks: 0

Visual Map

x 0 x x x x x x x x 1 x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x 0 x x x 0 x x x 0 x 0 x x x x x x x x x x 0 x 0 x x x x x 0 x 0 x x x x x 0 x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x 0 x 0 x x 0 x x x x x x x x x x x x 0 x x x x x x x 0 x x x x x x x x x x x x 0 x 0 x 0 x 0 x x x x x x 0 x 0 x x x x x x x x x 0 x x x x 0 x x x x x 0 x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x 0 x x x x 0 x x x x x x x x x x x x 0 x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x 0 x x x x x x x x x x x 0 x 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x 0 x x x x x x 0 0 0 x x 0 0 x x 0 0 x x 0 x x x 0 0 x x x x x x x x x x 0 x x x x x x x x x x x 0 0 x x x x x x x x x x x x x x 0 x x x x x x 0 x x x x x x x x x x x x x x 0 x 0 0 x 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 x x 0 0 0 x 0 0 0 0 0 0 x x x x 0 x x x x x 0 x x x x x 0 x x x x 1 x x x x x x x 1 x 1 x x x x 1 x x x x x 0 x 0 0 0 x 0 x x x x x x x x 0 x 0 x x x x x x x x x 0 x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x 0 0 0 x x x x x x x x x x x x 0 x x x x x x x x x x x 0 x x x x x x x 0 x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x 0 0 x x x x x x x 0 0 x x x x x x x x 0 x x 0 x 0 x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 x 0 x 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x 0 x x x 1 x x x x x x x x x x x x x 0 x x x x x x x x x x x 1 x x x x 0 x x x x x x x x x x x 1 x x x x x x x x x x x x x x x x x x 0 x x x x x x x 0 0 x 0 x 0 x x 1 1 x x 1 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x 0 x x x x x x x x x x x 1 1 x x 0 x x x x x x x x x x 0 x x x x x x x x x x x x 1 1 x x 0 1 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x 0 x 0 x x x x x x x x x x x x x x x x x 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 1 x x x x x x 1 x x 1 x x 1 x x x 1 x x x x x x x x x x x 0 x x x x x x x x x 0 x x 0 x x x x x x 0 x x x x 0 x x x x x x x x x x x x x x x 0 0 x 0 0 0 0 x x x x x 0 x x x x x 1 x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x 1 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x 0 x 0 x x x x x x x x 0 x x x x x x x x x x x 0 x 1 x x x 0 x 0 0 x x 0 0 0 x x 0 x x x x x x x x x x 0 x 0 x x x x x x x x x x x x x 1 x x x x x x x x x x x x x x x x x x x 1 x x x x x x x x x x x x x x x 0 x x x x x x x x x x x x 0 x x x x x 1 x 1 x 0 x x x x x x 1 x x x 0 x x 0 x x x x x x x x 0 0 x x x x x x x x x x x 1 x x x 0 x x x 1 x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x 1 x x x 1 x x x 0 x x x x 1 x 0 x x 0 x x x x 0 x x x 1 x 1 x x x x x x x x x x x x x x x x x 0 1 x x x x 0 x x x x x x x x x 1 x x x x x x x x x x x x x x x x x x x 0 x 0 x x x x 0 0 0 0 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 2 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.MYF

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAdjustPrivilegesToken
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
Show More
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Other Suspicious
  • AdjustTokenPrivileges

Trending

Most Viewed

Loading...