Threat Database Trojans Trojan.Agent.PFBA

Trojan.Agent.PFBA

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.Agent.PFBA
Signature status: No Signature

Known Samples

MD5: 4b4ca734baa8a9e54d93b1c8eb9e8019
SHA1: 1ff116ea11d4dd85d60a937c9a199ed3809a8ae0
SHA256: 9F6C707C2D4B625DA33AC32986160B053C24C19D2F857B7B38B2DCD0319A9DF7
File Size: 264.10 KB, 264104 bytes
MD5: d5760798040532f550f548d190069764
SHA1: f2d35c9508bcb967a59db2db0d9b1c8c4b3155f5
SHA256: 41DEDE2DBB1EEA22FEB42474F6400F93EA5EC7C0E7C7B5059F34D80B05E965F8
File Size: 286.12 KB, 286120 bytes
MD5: e7d18a600d70e533fa59d0c8fab0df8c
SHA1: 98f9b489c5e2f6e85055a099095a884021e6b87b
SHA256: B43661F6EDDCA58C82FD7131D7E164810C4467A3C7B328D9B93239462F420251
File Size: 286.12 KB, 286120 bytes
MD5: c1e21e64d06d696b0d0b2f714a5e7dca
SHA1: 3aedbd6043884b9a50222ff99c20558d6767a01a
SHA256: DB462874596627DA189CE70EF691A63369C931FF7C72A0A30CAE4DE5A0BAA3AB
File Size: 286.12 KB, 286120 bytes
MD5: aa4af97c346aa7c0422ebf78ac97ae9a
SHA1: 2e163c30c67c1ab79ccd3d0825dbe9ce880269d6
SHA256: 19C4CEBB4A9EDB95F8435B41B7432EB8B49A0169B65A2BADF0C5D040F4964D0C
File Size: 286.12 KB, 286120 bytes
Show More
MD5: fe515d774e6e7d0c122591cd016e8c05
SHA1: da1233baa46a883893e2fc0b276ae00b04dcd7e0
SHA256: 3965CEEF4B92E282F693A0A2AF31E9C0ECA70CAF2A892E44B0424EFC68DEAEB7
File Size: 534.44 KB, 534440 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name GSE
File Description GSE
File Version 1, 0, 0, 2
Internal Name GSE
Legal Copyright Copyright (C) 2021 GSE
Original Filename steam.exe
Product Name GSE
Product Version 1, 0, 0, 2
Source Control I D 8563863

Digital Signatures

Signer Root Status
GSE GSE Self Signed

File Traits

  • fptable
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 1,157
Potentially Malicious Blocks: 34
Whitelisted Blocks: 1,092
Unknown Blocks: 31

Visual Map

x x x 0 0 0 0 ? 0 0 0 x 0 0 ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x ? ? ? x ? 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 x x ? 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x ? ? x x 0 x 0 0 0 0 x x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 x x 0 0 ? 0 x 0 x 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 ? 0 0 0 x x x 0 ? 0 ? 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 1 0 0 0 0 0 0 0 0 0 2 1 0 1 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 3 1 1 1 1 0 1 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 0 2 2 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 1 0 0 0 0 0 2 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • DarkRAT.F
  • HackAgent.R

Trending

Most Viewed

Loading...