Threat Database Trojans Trojan.Downloader.Agent.CC

Trojan.Downloader.Agent.CC

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 10,596
Threat Level: 80 % (High)
Infected Computers: 905
First Seen: April 6, 2022
Last Seen: June 29, 2026
OS(es) Affected: Windows

The detection of Trojan.Downloader.Agent.CC on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to download and install additional malicious software on your computer, which can lead to a range of problems, including data theft, system crashes, and compromised performance. In this report, we will provide an overview of the Trojan.Downloader.Agent.CC threat, its operating methods, symptoms of infection, and steps to remove it from your system.

What Is Trojan.Downloader.Agent.CC?

Trojan.Downloader.Agent.CC is a type of Trojan horse malware that is designed to download and install additional malicious software on your computer. The term "Trojan" refers to the fact that this type of malware disguises itself as a legitimate program or file, allowing it to evade detection and gain access to your system. The "Downloader" part of the name indicates that this malware is capable of downloading and installing additional malicious software, which can lead to a range of problems.

How Trojan.Downloader.Agent.CC Operates

Trojan.Downloader.Agent.CC operates by exploiting vulnerabilities in your system or tricking you into installing it. Once installed, it can download and install additional malicious software, including viruses, spyware, and adware. This malware can also modify system settings, steal sensitive information, and disrupt system performance. It is essential to remove this malware as soon as possible to prevent further damage to your system.

Symptoms of Infection

The symptoms of a Trojan.Downloader.Agent.CC infection can vary, but common signs include slow system performance, unexpected pop-ups and ads, and unfamiliar programs or icons on your desktop. You may also notice that your system is crashing or freezing frequently, or that your browser is being redirected to unfamiliar websites. If you suspect that your system is infected with Trojan.Downloader.Agent.CC, it is essential to take immediate action to remove the malware.

How to Remove Trojan.Downloader.Agent.CC

  1. Restart your computer in Safe Mode with Networking to prevent the malware from loading and to allow you to download and install removal tools.
  2. Download and install a reputable anti-malware tool, such as SpyHunter, and run a full scan of your system to detect and remove the malware.
  3. Uninstall any suspicious programs or applications that you do not recognize or that were installed recently.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and run another scan with your anti-malware tool to ensure that the malware has been completely removed.

Conclusion

In conclusion, the detection of Trojan.Downloader.Agent.CC on your system is a serious security threat that requires immediate attention. By understanding how this malware operates and taking steps to remove it, you can protect your system and prevent further damage. Remember to always be cautious when downloading and installing software, and to keep your anti-malware tools up to date to prevent future infections. If you are unsure about how to remove Trojan.Downloader.Agent.CC or if you need additional assistance, consider seeking help from a qualified IT professional or a reputable anti-malware vendor.

Analysis Report

General information

Family Name: Trojan.Downloader.Agent.CC
Signature status: No Signature

Known Samples

MD5: f3a58e6f4aee7e9721f7920733df7b11
SHA1: 42fa6f5f8259d07ff9450b27427b2a3f182af74e
SHA256: 9F48C2EC7606C5CB56C36D043E9CB98757EEBCBD1D7596D0DF3516DF637E08B9
File Size: 8.01 MB, 8009984 bytes
MD5: ffe72459e3ad3a3055157ab22a3bd999
SHA1: 9c9019374f4de980d4f962c4a52c673999c7d2a0
SHA256: 77678EBEE6AB20212F8F1B62E0815D542A8F7E6DEB525230B88DCEF56F761C3D
File Size: 7.99 MB, 7994880 bytes
MD5: 0113e9fe837734738381c299754f4bd0
SHA1: ed889dba56e81586e160abcac16452b967aaf6b0
SHA256: 1AF4CD3DC0E83F4472D21FAFEC25EAC2635BC318160F1CAF020B96D3D6E0338C
File Size: 8.01 MB, 8009984 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have security information
  • File has exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
File Version 5, 0, 6, 0
Internal Name WebUI
Legal Copyright Copyright (C) 2013
Original Filename WebUI.dll
Product Name WebUI
Product Version 5, 0, 6, 0

Digital Signatures

Signer Root Status
ORANGE VIEW LIMITED DigiCert High Assurance EV Root CA Hash Mismatch
ORANGE VIEW LIMITED DigiCert High Assurance EV Root CA Hash Mismatch

File Traits

  • dll
  • HighEntropy
  • imgui
  • x86

Block Information

Total Blocks: 35,780
Potentially Malicious Blocks: 12,731
Whitelisted Blocks: 23,049
Unknown Blocks: 0

Visual Map

x 0 0 0 0 x 0 0 x x 0 x 0 0 0 0 x x x x 0 0 0 0 0 x x x x 0 x 0 0 0 0 0 0 x 0 x x x 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 x x x x x x x 0 x 0 0 x 0 0 0 0 x 0 x 0 x x 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 x x x 0 x 0 0 x 0 0 0 0 0 x x x 0 x 0 0 0 x 0 x x x x x 0 0 0 x 0 0 0 0 0 0 0 x x 0 0 x 0 x 0 0 x x 0 0 0 0 0 0 x x 0 0 0 0 0 x x 0 0 x x x x 0 0 0 x x 0 x x x 0 0 x x x x x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x x x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x x x 0 x 0 x x x x 0 0 x x x x 0 0 0 x 0 x x x x x 0 x 0 0 0 x x x 0 x x 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 x 0 0 0 0 x 0 x 0 0 0 0 x 0 x 0 0 0 x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x x 0 0 0 x 0 x 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 x x x x 0 0 0 0 0 x x x x x 0 0 x 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 x 0 x x 0 0 x 0 x x x x x x x x x x x 0 0 x x 0 0 0 x x 0 0 0 0 0 0 0 x x x 0 0 x x x x x x x x 0 0 x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 x 0 x x 0 0 0 0 0 0 0 x x x 0 0 0 0 x 0 0 0 x 0 0 0 0 x 0 x 0 x 0 x 0 0 0 0 x x x 0 0 0 0 0 x 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 x x x 0 0 x x x x x x x x x x x 0 0 x 0 0 x x 0 x 0 x 0 0 0 x x x x x x x x x x x x 0 0 0 x 0 x 0 0 0 x x x x x x x x x x 0 x x 0 0 x x x x x x x 0 x x 0 x x x x x 0 x x x x x x x x x 0 x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 x x x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 x x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x 0 x x 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 0 0 0 0 x 0 0 x x x x x 0 x x x x x x x x x x 0 0 0 0 0 x x x x x x x x x 0 0 0 0 x x 0 x x x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 0 x 0 x x 0 0 0 x x 0 0 0 0 x x x 0 0 0 0 0 0 0 x x 0 0 0 x 0 x x 0 x 0 0 0 0 x x 0 0 0 0 0 x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 x 0 0 0 0 x 0 0 0 0 x 0 0 0 0 x x x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 x 0 0 x 0 0 0 0 x 0 0 x 0 x 0 0 0 0 x 0 0 0 0 0 x x 0 0 0 0 x x x 0 0 0 0 0 x 0 0 0 x x 0 0 0 0 0 0 x 0 x x 0 x 0 x 0 0 x 0 x x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x 0 x x 0 0 0 0 0 x x 0 x x x x x x x 0 0 0 x x x 0 x x 0 x 0 0 0 0 0 x x x x 0 x x 0 x x x x 0 0 0 x 0 0 x 0 x x x 0 0 x x 0 0 0 0 x 0 0 0 0 0 0 0 x x x x x x x 0 0 0 x x x 0 0 0 0 x 0 x 0 x x x 0 0 x x x 0 x 0 x x 0 x 0 x x 0 0 x x 0 0 x 0 0 0 0 0 x x x x 0 x x 0 x x 0 0 0 x 0 0 0 0 x x x x 0 0 x x 0 x x x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x x x x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x x x x 0 x 0 0 0 0 x x 0 0 x 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x x x x 0 0 0 0 x 0 x 0 0 0 0 0 x 0 x x x x x x 0 0 x x x x x x 0 x x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x x x 0 0 0 0 0 x 0 0 0 0 0 x 0 0 x x x 0 x 0 x 0 0 0 0 0 0 x 0 x x 0 0 0 0 x 0 0 0 0 0 0 x x x x x 0 x 0 0 0 0 x x 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 x 0 0 0 0 x x x x 0 0 0 0 0 x x x x x 0 x 0 0 x 0 0 0 0 0 0 0 x 0 x 0 0 0 0 x 0 0 0 x x x 0 0 0 0 0 0 x x x 0 x x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 x 0 x 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x x x x 0 x x x 0 0 0 0 0 x x x 0 0 0 x x x 0 x x x x x x x 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x x x x x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 x 0 x 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 x x 0 0 x x 0 x x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x x 0 0 x 0 0 0 x 0 0 0 x 0 0 x 0 x 0 x 0 x 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 x 0 0 0 x 0 0 0 0 x x 0 0 0 0 0 x x x x 0 0 x 0 0 0 0 x x 0 0 0 x 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 x 0 x 0 0 0 0 0 x x 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Downloader.Agent.CC
  • Rugmi.PC

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\42fa6f5f8259d07ff9450b27427b2a3f182af74e_0008009984.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\9c9019374f4de980d4f962c4a52c673999c7d2a0_0007994880.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\ed889dba56e81586e160abcac16452b967aaf6b0_0008009984.,LiQMAxHB

Related Posts

Trending

Most Viewed

Loading...