Threat Database Trojans Trojan.Agent.XVE

Trojan.Agent.XVE

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.Agent.XVE
Signature status: No Signature

Known Samples

MD5: 2e8f7f71c545ac4287be592ca974f3c0
SHA1: 4fcd9a745998a889ccd0ae808c84157b67b1e0c3
File Size: 249.81 KB, 249808 bytes
MD5: ad8532f60f22b87273fda6bae8356e74
SHA1: d18f45387d59c1cd9560ddbd3282a8f9338dc690
SHA256: DB71BABDC84BAD1450D941BEA511FAB19B65417AF4ED6D285A747D6705325142
File Size: 252.37 KB, 252374 bytes
MD5: b435cf22f1069b57a824164e77f994ce
SHA1: 0be7396d4c8688cacb4dfe0d5aab30eb9dd6db50
SHA256: 67A6E5FCCE453DA6666A9F5776793BC26FAC02562E920F276A3CA431210954EB
File Size: 144.80 KB, 144799 bytes
MD5: 3ba1b6c1eb709f72a07b5c0433780cc5
SHA1: 887e10c31d9e09b748bc74d6202437bd27effa7c
SHA256: 3F1ACF314F134E881DF9B0CF391E9B2E268EDF7697688DEB0A4A2A4B7AECB2DC
File Size: 249.81 KB, 249808 bytes
MD5: 77b88abd1c12750c24a811fde6e10bb2
SHA1: 974351ee1fe40a48902f7556f5a411f04ab35ddb
SHA256: 3FFCADE6468201BFE253D5F8F472F86A1043D25F52D47FA57BE2542FC0A5CC57
File Size: 84.94 KB, 84942 bytes
Show More
MD5: dbfafb67eaba9162c6d15ecacd15ceee
SHA1: 5288ff85559cc49133c6227a93dd42d9236622b9
SHA256: 1AB39306A17D03FEEDE7FB2137CAC57B269C869FECD07FDF6AB4673577F48199
File Size: 257.96 KB, 257962 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have resources
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
Show More
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • dll
  • No Version Info
  • x64

Block Information

Total Blocks: 365
Potentially Malicious Blocks: 1
Whitelisted Blocks: 364
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.DFCN
  • Agent.DRZ
  • Agent.GFJ
  • Agent.KSPA
  • Agent.PFPA
Show More
  • Agent.XBA
  • Agent.XGA
  • Agent.XVL
  • CobaltStrike.HO
  • CobaltStrike.MI
  • Injector.GDH
  • Injector.KDS
  • KeyLogger.CL
  • Kryptik.HRB
  • Kryptik.XSA
  • Lsassdump.A
  • Metasploit.X
  • ReverseShell.Gen.A
  • ReverseShell.PF
  • Rozena.XC
  • Rozena.XP
  • ShellcodeRunner.PC
  • Trojan.Agent.Gen.CDN
  • Trojan.Agent.Gen.LW
  • Trojan.Downloader.Gen.RV
  • Trojan.Kryptik.Gen.CKY
  • Trojan.Kryptik.Gen.XE

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
Show More
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTerminateProcess
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState

Trending

Most Viewed

Loading...