Threat Database Trojans Trojan.Go.Agent.F

Trojan.Go.Agent.F

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 9,510
Threat Level: 80 % (High)
Infected Computers: 55
First Seen: February 6, 2023
Last Seen: January 19, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Go.Agent.F
Signature status: Hash Mismatch

Known Samples

MD5: 5eda99ce780d95e2abc95d4aca34376e
SHA1: 49c31f17c89df90cd2ce0c9b7a2a0d04165f99c8
File Size: 1.73 MB, 1732696 bytes
MD5: 273edc08cd1a0ad55c114fe279b9306f
SHA1: 5ac9ff804517c2cfcc267a9a8c4a689ca5a44b9c
SHA256: 25B089AFE7C63A09D42643511DC400D96F6F39318A609DC7FDFF82539A34F975
File Size: 1.78 MB, 1778544 bytes
MD5: 92b7f7532e35c565869d6c7aabf3a854
SHA1: 1bc658aed19e1d342baaa9e04277950d2d707798
SHA256: 469F90462E164ACA083750A916BB223CA0B7F6285185C987C6234DE0D457BFC8
File Size: 1.37 MB, 1367984 bytes
MD5: 6888f859d1ed3dcd66ebdce5dc361f2e
SHA1: 7cc15ef4caa62e0556ffce748641de6c68fef48e
SHA256: A31E894CA60E0E15F7C16558E7FA9401EA4EDBB48C7015EE841F58C101A5A880
File Size: 1.49 MB, 1485800 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • Rockstar Games
  • Siber Systems
  • Zoom Communications, Inc.
File Description
  • RoboForm Installer and Uninstaller
  • Rockstar Games Launcher Redirector
  • Zoom Meetings Installer
File Version
  • 9.7.8.8
  • 6.5.0
  • 1.0.0.98
Internal Name
  • rfwipeout
  • RockstarRedirector.exe
  • Zoom Meetings Installer
Legal Copyright
  • Copyright (C) 1999-2025 Siber Systems Inc.
  • Rockstar Games Inc. (C) 2005-2024 Take Two Interactive. All rights reserved.
  • © Zoom Communications, Inc. All rights reserved.
Original Filename
  • rfwipeout.exe
  • RockstarRedirector.exe
  • Zoom Meetings Installer
Product Name
  • RoboForm
  • Rockstar Games Launcher Redirector
  • Zoom Meetings Installer
Product Version
  • 9.7.8.8
  • 6.5.0
  • 1.0.0.98

Digital Signatures

Signer Root Status
Rockstar Games, Inc. DigiCert Trusted Root G4 Hash Mismatch
VideoLAN DigiCert Trusted Root G4 Hash Mismatch
Zoom Video Communications, Inc. DigiCert Trusted Root G4 Hash Mismatch
Siber Systems Sectigo Public Code Signing Root R46 Hash Mismatch

File Traits

  • golang
  • Installer Version
  • No Version Info
  • x64

Block Information

Total Blocks: 918
Potentially Malicious Blocks: 1
Whitelisted Blocks: 917
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • CobaltStrike.XA
  • EternityLog.A
  • GO.GoCLR.B
  • Go.Agent.F
  • Hive.A
Show More
  • Redline.AI
  • ShellcodeRunner.TA

Files Modified

File Attributes
c:\users\user\downloads\data.db Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\soul.db Generic Read,Write Data,Write Attributes,Write extended,Append data

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcSetInformation
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
Show More
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRemoveIoCompletionEx
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetIoCompletion
  • ntdll.dll!NtSetTimerEx
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • ntdll.dll!NtYieldExecution
  • UNKNOWN
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState
Network Winsock2
  • WSAStartup

Trending

Most Viewed

Loading...