Threat Database Trojans Trojan.Downloader.Agent.CT

Trojan.Downloader.Agent.CT

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 1
First Seen: March 2, 2022
Last Seen: March 2, 2022
OS(es) Affected: Windows

The detection of Trojan.Downloader.Agent.CT on your system indicates a potential security threat. This type of malware is designed to download and install additional malicious software on your computer, which can lead to a range of problems, including data theft, system crashes, and unauthorized access to your personal information. It is essential to take immediate action to remove the threat and prevent further damage.

What Is Trojan.Downloader.Agent.CT?

Trojan.Downloader.Agent.CT is a type of Trojan horse malware that is designed to download and install additional malicious software on your computer. The name "Trojan" refers to the fact that this type of malware disguises itself as a legitimate program or file, allowing it to bypass your system's security defenses. The "Downloader" part of the name indicates that this malware is designed to download and install additional malicious software, which can include viruses, spyware, adware, and other types of malware.

How Trojan.Downloader.Agent.CT Operates

Trojan.Downloader.Agent.CT operates by exploiting vulnerabilities in your system's security defenses. This can include exploiting weaknesses in your operating system, browser, or other software applications. Once the malware has gained access to your system, it can download and install additional malicious software, which can include keyloggers, ransomware, and other types of malware. The malware can also communicate with its creators, allowing them to remotely control your system and steal your personal information.

Symptoms of Infection

The symptoms of a Trojan.Downloader.Agent.CT infection can vary, but common indicators include slow system performance, frequent system crashes, and unusual pop-ups or advertisements. You may also notice that your system is behaving erratically, or that your personal information is being stolen. In some cases, the malware may not exhibit any noticeable symptoms, making it difficult to detect without the use of specialized security software.

  • Slow system performance
  • Frequent system crashes
  • Unusual pop-ups or advertisements
  • Erratic system behavior
  • Theft of personal information

How to Remove Trojan.Downloader.Agent.CT

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow you to download and install security software.
  2. Download and install a reputable anti-malware tool, such as SpyHunter, and perform a full scan of your system to detect and remove the malware.
  3. Uninstall any suspicious programs or applications that may be related to the malware.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform a follow-up scan to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.Downloader.Agent.CT from your system requires immediate attention and a comprehensive approach. By following the steps outlined above, you can help to ensure that the malware is completely removed and that your system is protected from future infections. It is essential to remain vigilant and to regularly scan your system for malware to prevent similar threats from occurring in the future. By taking proactive steps to protect your system, you can help to safeguard your personal information and prevent the potential consequences of a malware infection.

Analysis Report

General information

Family Name: Trojan.Downloader.Agent.CT
Signature status: No Signature

Known Samples

MD5: 406913f048652a351220cb0e8fa45225
SHA1: 5e28f310b53c6dd91c7344c036dd71f00dd939c4
SHA256: DA0716DA61C0EA53CE44A8465C53930E1F9B24D698D64FC739238F4254F19755
File Size: 688.64 KB, 688640 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Microsoft Corporation
File Description Win32 Cabinet Self-Extractor
File Version 11.00.17763.1 (WinBuild.160101.0800)
Internal Name Wextract
Legal Copyright © Microsoft Corporation. All rights reserved.
Original Filename WEXTRACT.EXE .MUI
Product Name Internet Explorer
Product Version 11.00.17763.1

File Traits

  • HighEntropy
  • No Version Info
  • x86

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\users\user\appdata\local\temp\925e7e99c5\pdates.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\ixp000.tmp\e3834400.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\e3834400.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\tmp4351$.tmp Generic Write,Read Attributes,Delete
c:\users\user\appdata\local\temp\ixp000.tmp\v4522327.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\v4522327.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp001.tmp\d3479739.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp001.tmp\d3479739.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp001.tmp\tmp4351$.tmp Generic Write,Read Attributes,Delete
Show More
c:\users\user\appdata\local\temp\ixp001.tmp\v4321128.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp001.tmp\v4321128.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp002.tmp\c0286554.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp002.tmp\c0286554.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp002.tmp\c0286554.exe_deleted_ Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp002.tmp\tmp4351$.tmp Generic Write,Read Attributes,Delete
c:\users\user\appdata\local\temp\ixp002.tmp\v6042614.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp002.tmp\v6042614.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp002.tmp\v6042614.exe_deleted_ Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp003.tmp\a1597186.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp003.tmp\a1597186.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp003.tmp\a1597186.exe_deleted_ Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp003.tmp\b2598216.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp003.tmp\b2598216.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp003.tmp\b2598216.exe_deleted_ Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp003.tmp\tmp4351$.tmp Generic Write,Read Attributes,Delete

Registry Modifications

Key::Value Data API Name
HKLM\software\wow6432node\microsoft\windows\currentversion\runonce::wextract_cleanup0 rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Yvowviuh\AppData\Local\Temp\IXP000.TMP\" RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\runonce::wextract_cleanup1 rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Yvowviuh\AppData\Local\Temp\IXP001.TMP\" RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\runonce::wextract_cleanup2 rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Yvowviuh\AppData\Local\Temp\IXP002.TMP\" RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\runonce::wextract_cleanup3 rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Yvowviuh\AppData\Local\Temp\IXP003.TMP\" RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
Show More
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 -k8��8tXz��B�8 �6 �v z 5� �Z xy ��T�B�������������5����ee +��Bx�<5 � �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�^*�h+�[,��/9�/��0P%1`1�1HO RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 ��3 xy* �/��Y�d�kP~��� ��ރ�p��^�o���zee)Vs} kP~ ��1���7 ���ﺃee����1��fe��h RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 .k8��8tXz��B�8 �6 �v z 5� �Z xy ��T�B�������������5����ee +��Bx�<5 � �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�^*�h+�[,��/9�/��0P%1`1�1HO RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 /k8��8tXz��B�8 �6 �v z 5� �Z xy ��T�B�������������5����ee +��Bx�<5 � �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�^*�h+�[,��/9�/��0P%1`1�1HO RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\explorer\user shell folders::startup C:\Users\Yvowviuh\AppData\Local\Temp\925e7e99c5\ RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
  • ShellExecute
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDuplicateObject
Show More
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWriteFile
  • UNKNOWN
User Data Access
  • GetUserName
  • GetUserObjectInformation
Service Control
  • OpenSCManager
  • OpenService
  • StartService
Other Suspicious
  • AdjustTokenPrivileges

Shell Command Execution

C:\Users\Yvowviuh\AppData\Local\Temp\IXP000.TMP\v4522327.exe
C:\Users\Yvowviuh\AppData\Local\Temp\IXP001.TMP\v4321128.exe
C:\Users\Yvowviuh\AppData\Local\Temp\IXP002.TMP\v6042614.exe
C:\Users\Yvowviuh\AppData\Local\Temp\IXP003.TMP\a1597186.exe
C:\Users\Yvowviuh\AppData\Local\Temp\IXP003.TMP\b2598216.exe
Show More
C:\Users\Yvowviuh\AppData\Local\Temp\925e7e99c5\pdates.exe
C:\Users\Yvowviuh\AppData\Local\Temp\IXP002.TMP\c0286554.exe

Trending

Most Viewed

Loading...