Trojan.MSIL.Agent.AFB
Threat Scorecard
EnigmaSoft Threat Scorecard
EnigmaSoft Threat Scorecards are assessment reports for different malware threats which have been collected and analyzed by our research team. EnigmaSoft Threat Scorecards evaluate and rank threats using several metrics including real-world and potential risk factors, trends, frequency, prevalence, and persistence. EnigmaSoft Threat Scorecards are updated regularly based on our research data and metrics and are useful for a wide range of computer users, from end users seeking solutions to remove malware from their systems to security experts analyzing threats.
EnigmaSoft Threat Scorecards display a variety of useful information, including:
Popularity Rank: The ranking of a particular threat in EnigmaSoft’s Threat Database.
Severity Level: The determined severity level of an object, represented numerically, based on our risk modeling process and research, as explained in our Threat Assessment Criteria.
Infected Computers: The number of confirmed and suspected cases of a particular threat detected on infected computers as reported by SpyHunter.
See also Threat Assessment Criteria.
| Threat Level: | 80 % (High) |
| Infected Computers: | 5 |
| First Seen: | January 14, 2023 |
| Last Seen: | January 17, 2023 |
| OS(es) Affected: | Windows |
Table of Contents
Analysis Report
General information
| Family Name: | Trojan.MSIL.Agent.AFB |
|---|---|
| Signature status: | No Signature |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
e34744c9a752f1ff22c8f87f5af67481
SHA1:
5368b3c74b75667cdb859d3c92fe6827f9844c06
SHA256:
B63F9A4188F1491DEA00F604121221BE2A4ACE6F6074EABADDCCBC07BF3BEE93
File Size:
10.75 KB, 10752 bytes
|
|
MD5:
eb2db5c500cb3c262ac628a0ab039352
SHA1:
9f133ede4d9ec140230e623160afb18dd01bd408
SHA256:
BD3D1C87FA2CFEB5B09A7AA891D4D8F89727563F86E740B36333C3E41DF14BEB
File Size:
10.75 KB, 10752 bytes
|
|
MD5:
aff3e4d005bacf7ab2e0870f8695788e
SHA1:
dbb0c0a6fa4b3e3fe9e6a2ad9e576271fc868283
SHA256:
88813C62E3FB248EE121061B6CC7671CEA80C43CEF81A0C107F5A68F74E6A043
File Size:
10.75 KB, 10752 bytes
|
|
MD5:
5d84c8df9f5360512e81c6f3db7f484d
SHA1:
9a90049bf11a31e57609693bcf94d4412d311e25
SHA256:
E319B13CD27298BF5D3930FCD507923D996C50729DDDD7C378FC1E24DA28C681
File Size:
10.75 KB, 10752 bytes
|
|
MD5:
6b2026a882bae42dc5da6083dd420987
SHA1:
758c8ef4f9922907548fa4fddcfb5fb22ccf6bee
SHA256:
F85AD7DDE030B7C1E6EDB516D5CD28B592A58E3BA9F4C89F3940B780DCA7DD30
File Size:
10.75 KB, 10752 bytes
|
Show More
|
MD5:
0e286250369b99594343a1a20b40bb9c
SHA1:
5255ec00f6564f38828ebda8578caceffd03f042
SHA256:
D38EDD9D496559D2C9370CDE75051F74E2B7A6C7972909FEE69F01CCA0ABDEC1
File Size:
10.75 KB, 10752 bytes
|
|
MD5:
1bf003405a1cfc0540e4c7b5e4acbcc2
SHA1:
2799b165d6e956d6dae1d3d8679dfbddf62d4a1a
SHA256:
F94F8B435C97A4BEA4502E0A5F8CFADCB7EDB284C9CDD70853943317FF891395
File Size:
10.75 KB, 10752 bytes
|
|
MD5:
1833abfa0117a48b2490b0bcd9a633b3
SHA1:
b7e923d6243384ac48d83913d354fe4664a34ca2
SHA256:
3C8BF01564B73781F63384FDD5510E37908043F959F65421BB3C0A42F975EFF6
File Size:
10.75 KB, 10752 bytes
|
|
MD5:
6e4e587c1f852ccdde78422e64ba9732
SHA1:
f3c2a2de57ce210f820172054f46fb6c33f7642c
SHA256:
F3B7B98196CDD46D6FBC82FC3EB2F5C46E944D906D223778C74EB2AEBD8C9615
File Size:
10.75 KB, 10752 bytes
|
|
MD5:
591b43c4064ac5442c1f797cd60408e6
SHA1:
1c2f005c2b1519b01e56e1b11f5c76eb330033ca
SHA256:
7E62F1FBDF3D00A5129A8E13428FB2462001618A6D73BBFC5D464C8243F6D62E
File Size:
10.75 KB, 10752 bytes
|
|
MD5:
f764e9e945260335a9f8d7f2bf533b7c
SHA1:
93c396e5f8ce10161935b32ce857017e0a5073a7
SHA256:
60DE41C87373C609DF444F7E0107D7DD86B2543471AAF2669B98C5E7A8F61F74
File Size:
10.75 KB, 10752 bytes
|
|
MD5:
7c10873ad354b2ac3f65b1e38d85edbf
SHA1:
9316f9d4f3be4ab97d4e7f963cb2c335581cb9e1
SHA256:
38E2E1FDDFECB4B983FB123C01CC387033999FC4A662C2EA7BA6333E2DA46419
File Size:
10.75 KB, 10752 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have debug information
- File doesn't have exports table
- File doesn't have security information
- File is .NET application
- File is 32-bit executable
- File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
- File is either console or GUI application
- File is not packed
- IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
Windows PE Version Information
Windows PE Version Information
This section displays values and attributes that have been set in the Windows file version information data structure for samples within this family. To mislead users, malware actors often add fake version information mimicking legitimate software.| Name | Value |
|---|---|
| Assembly Version | 0.0.0.0 |
| File Version | 0.0.0.0 |
| Internal Name |
Show More
|
| Original Filename |
Show More
|
| Product Version | 0.0.0.0 |
File Traits
- .NET
- dll
- x86
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 20 |
|---|---|
| Potentially Malicious Blocks: | 10 |
| Whitelisted Blocks: | 10 |
| Unknown Blocks: | 0 |
Visual Map
? - Unknown Block
x - Potentially Malicious Block
Similar Families
Similar Families
This section lists other families that share similarities with this family, based on EnigmaSoft’s analysis. Many malware families are created from the same malware toolkits and use the same packing and encryption techniques but uniquely extend functionality. Similar families may also share source code, attributes, icons, subcomponents, compromised and/or invalid digital signatures, and network characteristics. Researchers leverage these similarities to rapidly and effectively triage file samples and extend malware detection rules.- MSIL.Agent.AFB
Registry Modifications
Registry Modifications
This section lists registry keys and values that were created, modified and/or deleted by samples in this family. Windows Registry activity can provide valuable insight into malware functionality. Additionally, malware often creates registry values to allow itself to automatically start and indefinitely persist after an initial infection has compromised the system.| Key::Value | Data | API Name |
|---|---|---|
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | �n ' |