Threat Database Trojans Trojan.Agent.XSKB

Trojan.Agent.XSKB

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.Agent.XSKB
Signature status: No Signature

Known Samples

MD5: 83472744ee9961d988adc958cf57c349
SHA1: 53244d85c0152fd9a9a1cabfba56f736d9a1bd8a
SHA256: 4D7B28317146854F5EB1CB5DA37AF6D11B6DB8FDE2BFA20F441659D19659D732
File Size: 95.23 KB, 95232 bytes
MD5: 16720558bc3c4237f76155fe2fcbcf43
SHA1: 9dc40bc76ca593fe50ea720733dca465aca099a1
SHA256: CD0DC4523D5AED3ED6F2302222B97B62C841E6CAD1D6884A2AC47D6290DD92D4
File Size: 95.23 KB, 95232 bytes
MD5: 768ac8ae72203442c259f9c3fbec11f5
SHA1: 5b74d9c814d5da603842642740d7c653a279188c
SHA256: 1A23078EACAB9109782AB0D3E93AFA34B6E8B16AC4FB209784BAF9D44020655D
File Size: 95.23 KB, 95232 bytes
MD5: 822475b1b2412233f4fffdd831b0145e
SHA1: e9692cb7cc0bf27d93beef120a2bcd0fed63fb6b
SHA256: 4E7B2B3A86FAC39041E89FC26B4CEDFEFACD285E7F389CC8AD4275FCF124C0B4
File Size: 95.23 KB, 95232 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have resources
  • File doesn't have security information
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • fptable
  • GetConsoleWindow
  • No Version Info
  • x86

Block Information

Total Blocks: 478
Potentially Malicious Blocks: 4
Whitelisted Blocks: 474
Unknown Blocks: 0

Visual Map

0 0 0 0 0 x x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 1 0 0 0 2 0 1 0 1 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 0 2 2 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 0 3 1 1 1 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.IUY
  • Agent.KFVA
  • Agent.XCD
  • Agent.XSKB
  • Downloader.DTA
Show More
  • Kryptik.BBO
  • Stealer.BRK
  • Trojan.Agent.Gen.ASE
  • Trojan.Agent.Gen.SX
  • Trojan.Downloader.Gen.IE
  • Trojan.Kryptik.Gen.CHY
  • Trojan.Kryptik.Gen.CIQ

Files Modified

File Attributes
c:\users\user\downloads\temp.log Generic Write,Read Attributes

Trending

Most Viewed

Loading...