Threat Database Trojans Trojan.Agent.NJB

Trojan.Agent.NJB

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 25,381
Threat Level: 80 % (High)
Infected Computers: 3
First Seen: October 17, 2024
Last Seen: May 12, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Agent.NJB
Signature status: No Signature

Known Samples

MD5: 259f5b1f62f13c4d2a1cec633a9388df
SHA1: 3a94c84c43c37fa311c3d7c31abb27eb0fad7f62
SHA256: 9B66CE672D87FC4F8E14156DD8954029AB1934E68861438A8848F3D466D760A6
File Size: 217.09 KB, 217088 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have security information
  • File has exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name Handysoft Corp.
File Description Common Utility
File Version 6, 7, 7, 0114
Internal Name HsUtil
Legal Copyright Copyright (C) Handysoft Corp. 1999-2003
Original Filename HsUtil.DLL
Product Name Handysoft BizFlow Groupware
Product Version 6, 7, 7, 0114

File Traits

  • dll
  • x86

Block Information

Total Blocks: 362
Potentially Malicious Blocks: 9
Whitelisted Blocks: 198
Unknown Blocks: 155

Visual Map

0 0 0 0 0 1 0 0 ? ? ? x x ? ? ? 0 0 0 0 0 0 0 ? 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 0 0 0 0 ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 ? ? ? ? 0 ? 0 ? ? ? 0 ? ? ? ? ? ? ? ? 0 0 0 ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 0 0 0 ? ? 0 0 ? ? ? ? ? ? ? 0 0 0 ? 0 0 0 ? ? ? ? ? 0 0 ? ? 0 0 ? ? ? ? ? ? 0 0 0 ? 0 0 0 ? 0 ? 0 ? 0 ? ? 0 ? ? 0 0 ? 0 ? ? ? 0 0 ? ? 0 ? ? 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? x x ? ? ? ? ? 0 0 ? 0 ? 0 ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 ? 0 ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWriteFile
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\3a94c84c43c37fa311c3d7c31abb27eb0fad7f62_0000217088.,LiQMAxHB

Trending

Most Viewed

Loading...