Threat Database Trojans Trojan.Agent.VGB

Trojan.Agent.VGB

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.Agent.VGB
Signature status: No Signature

Known Samples

MD5: 15cf96d66cfef67b096d4b3c9e624f7d
SHA1: 1ae8bb503cee4c247132484fcea594bd1714ca79
SHA256: 3725DADA10090D9E0995AA94AB023E30ADB105670EEED33CAD24F17ACA814196
File Size: 9.08 MB, 9083392 bytes
MD5: 89698bf9702b16fde0a753b91bbd939f
SHA1: c78ff0ce8e1b9fa98ee5ac287be4296e4b636d31
SHA256: 454741E2D2C55B327B4726B502FFBAC7610AA67110055DAF1875BCD00669E06D
File Size: 4.39 MB, 4390912 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • HighEntropy
  • No Version Info
  • x86

Block Information

Total Blocks: 6,109
Potentially Malicious Blocks: 663
Whitelisted Blocks: 5,446
Unknown Blocks: 0

Visual Map

x x 0 x 0 x x x x x 0 x 0 x x x 0 x x x x x x x x x x x x x x x x x x x 0 x x x x x 0 x 0 x 0 0 x 0 0 x 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 x 0 0 x x 0 x x 0 0 0 0 0 0 0 0 0 2 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x x 0 0 0 0 0 0 0 x 0 x x x x 0 x 0 x x x x x 0 x x x 0 x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x x x x x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x x x x x x 0 x x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x 0 x x x x x 0 0 0 0 0 0 0 0 0 x 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x 0 0 x 0 0 0 0 0 0 x x x x x x x x x x 0 0 x 0 0 x x x x x x x x x x x x x 0 x x 0 x x x x x x 0 0 x x x x x x x 0 0 x x x 0 0 0 0 x 0 x 0 0 0 x 0 0 0 0 x 0 x 0 0 x 0 0 x x x 0 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x 1 x x x x x x 0 0 x 0 x x 0 0 0 0 0 x x x x 0 x 0 x x x 0 x 0 0 x x x 0 0 0 x x x x x x x x x 0 x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x x x x x x x x x 0 0 0 0 0 0 0 0 x x x x 0 x x x x 0 x x x x x x x 0 x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 x x x x x x x x 0 0 0 0 x x 0 0 0 x 0 x x x x 0 x x x 0 x x 0 0 0 0 x x x x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 x 0 x x x 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 x 0 x x x x 0 x x x x 0 x x x x 0 0 x x x x x x 0 0 x x x x x x x 0 0 0 0 0 x x x 0 x x x 0 x x x x x x x x x x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x x x x 0 x x x x x x x x x x x 0 0 x x x x x 0 0 0 x x 0 x 0 0 x x x x x 0 0 0 x x 0 x 0 0 x x x 0 0 0 0 x x x x x x x 0 0 x x x x 0 x x x x x 0 0 x x x x x x x x x x x x x 0 0 0 0 x x x x x x x x x x x 0 0 0 x x 0 0 0 0 x x 0 x x x 0 0 0 x 0 0 0 x 0 0 x x x x x x 0 0 0 x 0 x x x x 0 0 0 0 0 0 x x x x x x 0 x 0 x x x x x x x x x x x x x x 0 0 x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x x x 0 0 x x x x x x x x x x x x x x x x x x x x x 0 0 x 0 0 x x x x x x x x x 0 x x 0 0 0 0 0 0 x x x x x x x 0 0 0 0 0 x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 1 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.VGB

Files Modified

File Attributes
c:\users\user\appdata\local\spreadsheettools\32\lockxlsruntime.dll Generic Write,Read Attributes
c:\users\user\appdata\local\spreadsheettools\64\lockxlsruntime64.dll Generic Write,Read Attributes
c:\users\user\appdata\local\spreadsheettools\runtime.dll Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\157242231.dat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\157242232.dat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\201808991.dat Generic Write,Read Attributes
c:\users\user\appdata\local\temp\201808992.dat Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\lpd\{ea9852a9-00ee-4564-8128-57bd8d8f4c8f}:: RegNtPreCreateKey
HKCU\software\microsoft\lpd\{13965033-748f-46d6-b927-7646abc47bb4}:: RegNtPreCreateKey

Windows API Usage

Category API
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Anti Debug
  • IsDebuggerPresent
Network Info Queried
  • GetAdaptersInfo
User Data Access
  • GetComputerName

Trending

Most Viewed

Loading...