Threat Database Trojans Trojan.Agent.XVC

Trojan.Agent.XVC

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.Agent.XVC
Signature status: No Signature

Known Samples

MD5: 19f913a002f32c8e1d4afcb55e703c71
SHA1: 3d126de68fe4291faafd5c9533e97182bb0feee8
SHA256: AF63616285C78348FF1EA29025EFEA26FA48FBBFFF2074DE7CAD2405A17A20A2
File Size: 890.37 KB, 890368 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name Adobe Systems Incorporated
File Description Adobe PDF Broker Process for Internet Explorer
File Version 20.6.20034.366983
Internal Name AcroBroker.exe
Legal Copyright Copyright 1984-2020 Adobe Systems Incorporated and its licensors. All rights reserved.
Original Filename AcroBroker.exe
Product Name Adobe PDF Broker Process for Internet Explorer
Product Version 20.6.20034.366983

File Traits

  • 2+ executable sections
  • HighEntropy
  • x86

Block Information

Total Blocks: 629
Potentially Malicious Blocks: 185
Whitelisted Blocks: 443
Unknown Blocks: 1

Visual Map

x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x x 0 x x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 x x 0 0 1 0 0 0 x 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 x x 0 0 x 0 0 x 0 x 0 0 0 0 x 0 2 2 0 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x 0 x x 0 0 x 0 x x 0 0 0 0 x x 0 x x x 0 x x 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x 0 x x x 0 0 x 0 0 0 x x x x x x x x x 0 x 0 x x x x x x x 0 x x 0 x 0 0 0 0 0 0 0 0 0 x x x x x 0 x 0 2 0 0 0 x 2 x x x 0 x x x x x x x x x 0 0 0 0 0 0 0 0 0 x 0 x 0 0 x 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 x 0 0 0 x x 0 x 0 0 0 x 0 0 0 x x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 x 0 0 0 0 x 0 x 0 0 0 0 0 0 x 0 x 0 0 0 x x 0 0 0 x 0 0 0 0 0 0 0 0 x 1 0 0 0 0 x 0 x 0 1 0 0 0 0 0 0 0 0 0 x 1 x x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 x 0 0 0 0 x 0 0 0 0 0 0 x 0 x x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 1 1 1 1 1 1 2 3 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 x ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.XVC

Trending

Most Viewed

Loading...