Threat Database Trojans Trojan.Agent.XXA

Trojan.Agent.XXA

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.Agent.XXA
Signature status: No Signature

Known Samples

MD5: 47dafbda266caa1ea184f95f8af2bb21
SHA1: 5a2e001f95f919659aa9fb56d2ac3d98b9aab950
SHA256: 0F0F359FF109B469C8387F7CFD6D0C9CE722B132B007009375AC536DBD0078BE
File Size: 8.26 MB, 8260720 bytes
MD5: 20ed8f784b136173038b43b9febbcb2d
SHA1: b5cca2fe6ecbad875d242aaca1ead5565a1586d6
SHA256: 2D5B0382427D378C595FB85077820CF7D0EE191F91888953DC230641BCCA94D1
File Size: 27.92 KB, 27919 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have resources
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
Show More
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name NoahSystem
File Description Knight Online Client
File Version 4, 23, 13, 3000
Internal Name Warfare
Legal Copyright Copyright ? 2001. NoahSystem.co.ltd
Original Filename KnightOnline.exe
Product Name Knight Online Client
Product Version 4, 23, 13, 3000

Digital Signatures

Signer Root Status
Game Cafe Services Inc SSL.com Code Signing Intermediate CA RSA R1 Self Signed

File Traits

  • 00 section
  • 2+ executable sections
  • HighEntropy
  • No Version Info
  • x86

Block Information

Total Blocks: 33
Potentially Malicious Blocks: 9
Whitelisted Blocks: 24
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.XXA
  • Downloader.OFE
  • IRCBot.OB
  • IRCBot.QC
  • Keylogger.XA
Show More
  • Votos.A

Windows API Usage

Category API
Network Winsock2
  • WSAStartup

Trending

Most Viewed

Loading...