Threat Database Trojans Trojan.Downloader.Agent.NC

Trojan.Downloader.Agent.NC

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.Downloader.Agent.NC
Signature status: No Signature

Known Samples

MD5: 8c4b0ad95b25fea8dfff7c39e05a459f
SHA1: dbcf6f8532b3f75b0c68e6b6d7693ac440ff84b6
SHA256: 9138D1F820BA950A0229996FB94F76A39DC8FF48ACC4392124B9273DC143EDC1
File Size: 1.79 MB, 1786880 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name Microsoft Corporation
File Description AgentService EXE
File Version 10.0.17763.1007 (WinBuild.160101.0800)
Internal Name AgentService EXE
Legal Copyright © Microsoft Corporation. All rights reserved.
Original Filename AgentService.exe
Product Name Microsoft® Windows® Operating System
Product Version 10.0.17763.1007

File Traits

  • 2+ executable sections
  • HighEntropy
  • ntdll
  • x64

Block Information

Total Blocks: 2,978
Potentially Malicious Blocks: 669
Whitelisted Blocks: 2,108
Unknown Blocks: 201

Visual Map

0 0 0 0 0 0 0 0 x 0 0 ? 0 ? 0 0 0 x 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 x 0 0 0 0 1 0 0 ? ? ? 0 0 0 1 0 x ? ? 0 0 0 0 x 0 ? 0 x ? x x x 0 0 0 0 0 0 0 x 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 x 0 1 0 1 0 0 ? x ? 0 1 0 0 0 1 0 0 0 1 0 ? ? 0 0 x 0 x ? x 0 x x 0 0 x ? ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 ? 0 0 0 0 0 1 0 1 0 0 0 1 ? 0 0 0 x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? 0 ? 0 ? 0 x x x 0 0 0 x 0 0 x 0 x 0 x x ? ? ? 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 x ? x x 0 x 0 ? ? 0 x 0 0 0 ? 0 x x 0 0 0 0 0 0 0 0 0 1 0 x 0 x 1 1 x 0 0 x 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 x 0 0 x 0 0 0 1 x 0 0 0 0 0 x 0 0 0 0 x 0 0 x x 0 ? 0 x x x 0 x x ? 0 ? x ? 0 0 0 0 0 ? 0 0 x 0 x 1 0 1 1 0 0 ? x x x x 0 0 0 x x x 0 0 0 x 1 x x 0 0 0 0 x 0 x 0 x 0 x 0 0 0 x 0 x 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 1 x ? x 0 0 0 0 0 0 x ? ? 0 0 0 0 1 0 1 0 x ? x 0 0 0 0 0 0 ? ? x x 0 x 1 ? 1 0 0 0 0 ? x 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x x 0 0 0 0 x x x 0 x 0 0 0 x 0 x 0 0 0 0 0 0 0 1 0 0 0 0 0 x 0 x 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 x 0 0 x x 0 0 x 0 0 ? 0 0 0 0 x 0 0 0 1 x 0 0 x x ? x x ? ? 0 x 0 ? 0 0 x 0 0 0 0 x 0 ? x x 0 0 0 x 0 0 0 x 1 x 0 0 x 0 0 0 x 0 0 0 0 0 0 x 0 0 0 x 0 x 0 0 x 0 0 1 0 0 0 0 x 0 x 1 0 ? x ? ? x 0 x ? 0 0 0 0 ? 0 x 0 0 x 0 x 1 1 0 0 x 1 1 1 0 0 1 0 0 x 0 0 0 x 0 0 ? 0 0 0 0 x 1 ? 0 ? 0 ? ? ? 0 0 0 0 x x 1 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 1 ? 0 x x x x x x 0 0 x x x 0 0 0 x 0 0 0 x x x ? 0 x x x x 0 0 0 0 x 0 0 0 0 ? 0 x 0 0 0 0 x x 0 0 0 0 x x 0 0 0 x x ? ? 0 0 0 0 0 x x ? x x x 0 x x 0 x 0 x 0 x x 0 x x x 0 0 x 0 x x x 0 1 0 1 0 1 0 1 0 1 0 1 0 0 x 0 0 0 0 1 ? 0 x 0 x x 0 ? x x 0 0 0 0 0 1 1 1 x 0 0 0 x 0 x x x 1 x x x ? 0 0 0 ? x ? ? ? 0 0 0 0 x 0 0 1 x 0 0 0 1 0 0 0 x ? 0 0 0 x x 0 0 0 0 x x x x x x x 0 x 0 x 0 0 x x ? 0 0 0 0 0 ? 0 0 x 0 0 0 0 x x 0 0 0 x 0 0 ? x ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 1 0 0 0 x x 0 x 0 0 0 0 0 0 0 x 1 ? 0 0 1 x 0 x 0 x x x x 0 x 0 0 x 0 0 ? 0 0 x x 0 ? ? x 0 x 0 0 0 0 x x x x 0 0 0 0 0 ? 0 x x 0 0 ? ? x x 0 x ? x x x ? x ? ? x 0 ? 0 x ? ? 0 x ? 0 x 0 0 x x ? ? 0 x x 0 x ? 0 ? x 0 x 1 0 ? 1 ? ? 0 0 0 0 x x 0 x 0 x x x 0 0 x 0 0 x x 1 0 1 0 0 x 0 x ? 1 1 0 x x 0 x x 0 0 0 0 0 x 0 0 0 0 ? 0 0 1 1 0 1 0 1 1 0 0 x 0 x 1 0 x 0 0 1 0 0 0 0 x 0 0 ? 0 ? ? ? ? ? ? ? 1 ? 0 ? 0 0 0 ? 0 0 x ? ? x 0 x x 0 ? x 0 x x ? 0 0 0 0 0 0 0 0 0 0 0 0 x 1 x x x x x ? 0 0 0 0 0 0 0 0 0 x x x 0 ? x 0 0 0 0 0 x x x 0 x x ? x ? ? ? x x x x 0 x x ? 0 x x 0 x 0 x x x 0 0 0 x 0 0 x 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 x 0 0 x 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 x 0 0 x 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 1 ? ? ? x 0 0 0 0 x x x x ? x x 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 ? x x 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 ? x x 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 x ? x 0 0 x x x x x 0 x 0 x ? ? ? x ? ? ? x ? ? ? 0 0 0 0 0 x x 0 0 ? ? ? x x x x 0 x 0 x x 0 0 0 x x x ? 1 0 x 1 x 0 0 0 x 0 1 x x 0 x x ? 1 0 x ? x 0 0 x 1 x 0 0 x ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x 0 x x x x x x 0 0 0 x x x x x x 0 0 0 x x x x x x x x x 0 x x x x x x x x x x 0 x 0 x ? 0 x ? ? ? x x ? x x 0 x ? 0 x 0 x 0 x ? 0 x x 0 0 ? 1 x 0 ? ? ? 0 x x 0 0 0 0 x x x x 0 x x x 0 0 x 0 x x x x x x x x 0 x x x x x 0 x 0 x 0 x 0 0 1 1 1 1 1 1 x 0 x 0 x 0 0 x x ? 0 0 0 x x 0 0 0 x 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x x x 0 0 0 0 0 x 0 0 0 0 0 0 0 x x 0 x 0 x x 0 x x x x x x x 0 x 0 x x x 0 x 0 x x x x x x x 0 x x x 0 x x x x x x x x x x x x x 0 0 0 0 x x 0 0 x x x x x x x x x x x x x x 0 0 x 0 x 0 0 x x 0 0 0 0 0 0 x x x x x x x x x x x x x 0 0 0 ? 0 ? ? x ? 0 x 0 ? 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 x 0 x ? 0 x 0 0 0 ? 0 ? x x x x x x x x x 0 0 0 0 0 0 ? ? x 0 0 0 0 0 0 0 x ? ? x x x 0 0 0 0 0 ? 0 x 0 0 0 x 0 0 0 x 0 x x x x x 1 0 x x 0 x 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x ? ? 0 0 ? x x x ? x 0 x ? ? x x 0 ? 1 0 0 x 0 0 x 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Downloader.Agent.NC
  • Expiro.LA
  • Expiro.LC

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenSection
Show More
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN