Threat Database Trojans Trojan.Agent.XFE

Trojan.Agent.XFE

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 5,707
Threat Level: 80 % (High)
Infected Computers: 252
First Seen: September 21, 2024
Last Seen: November 29, 2025
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Agent.XFE
Signature status: No Signature

Known Samples

MD5: f80ff2b512a892d71a76df2bd6ce82f5
SHA1: 2c675d1413330dd8e7c493418e378257bee527ca
File Size: 6.35 MB, 6349056 bytes
MD5: 873400c9ccc9bb8175fedc836b84a3f4
SHA1: 93aba4d252d23918b27220d0cdf25aa49bc16dbc
SHA256: FC5A6EE0BB1ECB271CD9247EAD2E4B0C19D7752BEA9F1A6BCF2461084209FC86
File Size: 6.41 MB, 6411008 bytes
MD5: b9342ea25533e07a29376946563eae8e
SHA1: 01c634bfb14442be1f2e16b8cc5f9f00f1fecfe2
SHA256: 83329550316CF98E8C49D202FC6E69E889D22EB28B91C52FFC904C9007A10C34
File Size: 5.74 MB, 5743872 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • Dupuis S.A.
  • Morelli SPA Group
  • Rendón de Ávila e Hijo y Flia.
File Description
  • Audible Tuner
  • Unistring
  • Violin Guide Loader
File Version
  • 2.1.8.38
  • 1.3.5.85
  • 1.2.54.370
Legal Copyright
  • 2022 (c) Morelli SPA Group
  • 2023 (c) Dupuis S.A.
  • 2025 (c) Rendón de Ávila e Hijo y Flia.
Product Name
  • Audible Tuner
  • Unistring
  • Violin Guide Loader
Product Version
  • 2.1.8.38
  • 1.3.5.85
  • 1.2.54.370

File Traits

  • big overlay
  • HighEntropy
  • x64

Block Information

Total Blocks: 263
Potentially Malicious Blocks: 138
Whitelisted Blocks: 115
Unknown Blocks: 10

Visual Map

x x 0 x x 0 x 0 0 0 0 0 ? ? ? ? 0 ? 0 0 0 0 x ? x x x x x ? x x x x 0 x x x x x x 0 0 x x 0 0 0 x 0 0 x 0 0 0 0 0 0 x x x x x x 0 0 0 x x x x 0 x x x x 2 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x ? x x x x x x x x x 0 0 x x 0 x x x 0 0 0 0 x x 0 x x x x x x x x x x x x x x x x x x ? x x x x x x x x x x x x x x x x x x x x x x x x 0 0 x x x 0 0 x x x x x x x x x ? x x x x x 0 x x x x x x x x x x x x x x x x x x x x 0 x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.BKU
  • OpenSUpdater.BCA

Trending

Most Viewed

Loading...