Threat Database Trojans Trojan.Agent.XFS

Trojan.Agent.XFS

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 27,435
Threat Level: 80 % (High)
Infected Computers: 1
First Seen: July 28, 2026
Last Seen: August 3, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Agent.XFS
Signature status: No Signature

Known Samples

MD5: 0b6c5420b925d462f80ca9ebf12f7a2e
SHA1: 7f2e694f2b505e517911ddb05cd0d78fa459a45f
SHA256: A3167A3B502C86F9786065A8DDEFBC52C2FFA8E0CD76620A87362AE44B93BB2B
File Size: 1.76 MB, 1755648 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have security information
  • File has exports table
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Comments Llandovery urinating
Company Name Untuned converters parathyroidectomies
File Description Headright punct adiaphorous biaxillary
File Version 6.168.150.7
Internal Name Insultant
Legal Copyright Copyright  Flaxes shakier intercorrelated pseudocone thong
Legal Trademarks Loobily asterolepis mishmee uneasily
Original Filename Originatress
Product Name Buzzgloak haemogram
Product Version 6.168.150.7

File Traits

  • dll
  • HighEntropy
  • x64

Block Information

Total Blocks: 248
Potentially Malicious Blocks: 104
Whitelisted Blocks: 144
Unknown Blocks: 0

Visual Map

x x x x x x x x x x x x x x x x 0 x x x 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 2 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 1 1 0 0 0 1 1 0 0 x x x x 0 x x x x x x x x x 0 x x 0 x x x x x x x 0 x x x x x 0 x 0 x x x x x x x x x 0 x x x x 0 x x x 0 x 0 x x x x x x 0 x x x x x x x x 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.XFS

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWriteFile