Threat Database Trojans Trojan.MSIL.Agent.AYJ

Trojan.MSIL.Agent.AYJ

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.MSIL.Agent.AYJ
Signature status: Hash Mismatch

Known Samples

MD5: 5f416ebe7e78010a0ca0d5f7f0de24b7
SHA1: 4a9417d52aa9054a77509dcbde261eda49e1fabb
SHA256: 8918E3B71E21D4F0EFF005DC201290235D38069D992670039FFD97C227985C3E
File Size: 2.20 MB, 2202624 bytes
MD5: 2469c2caeaa91ef9d5ae6d8ebba9c804
SHA1: b3e53e7832ff153417b94bbc3770135d3244ffe9
SHA256: ACF26A022E36A917E42D02D313CC0B52F1BFD12960FF3DDCA48430D1E5FCC867
File Size: 508.93 KB, 508928 bytes
MD5: ab39ae303fb4ae0243629f24606173a0
SHA1: dccb25962260be2085c84fb99835d40b38409162
SHA256: A60D45D706C0583B5D45DBAD53C4665242E950C068B57E6D94A48A53E43B565B
File Size: 521.12 KB, 521120 bytes
MD5: 6ee9edd9d8bc2ccd5353b0638873dfd3
SHA1: abba123115cf917af56a664127460df2f0b5e400
SHA256: 1370F3806F222C0C3C839710B87706532827AEC5D857DAAFC306B56D1995540C
File Size: 581.67 KB, 581672 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 10.0.19041.1
  • 4.7.3081.0
  • 1.0.0.0
Comments %NameExe%
Company Name Microsoft Corporation
File Description
  • Bootstrapper
  • Dropper
  • Microsoft Search Host
  • Microsoft® Windows® Operating System
File Version
  • 10.0.19041.1
  • 4.7.3081.0
  • 1.0.0.0
Internal Name
  • Bootstrapper.exe
  • Dropper.exe
  • NDP472-KB4054531-Web.exe
  • svchost.exe
Legal Copyright
  • Copyright © 2024
  • © Microsoft Corporation. All rights reserved.
Legal Trademarks Microsoft® is a registered trademark of Microsoft Corporation
Original Filename
  • Bootstrapper.exe
  • Dropper.exe
  • NDP472-KB4054531-Web.exe
  • svchost.exe
Product Name
  • Bootstrapper
  • Dropper
  • Microsoft Search Host
  • Windows Host Process
Product Version
  • 10.0.19041.1
  • 4.7.3081.0
  • 1.0.0.0

Digital Signatures

Signer Root Status
Oracle America, Inc. DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Hash Mismatch
Crystal Future OÜ GlobalSign Code Signing Root R45 Hash Mismatch

File Traits

  • .NET
  • HighEntropy
  • x86

Block Information

Total Blocks: 2,612
Potentially Malicious Blocks: 2,263
Whitelisted Blocks: 5
Unknown Blocks: 344

Visual Map

0 0 0 x x 0 ? ? ? ? ? ? ? x x ? ? x x x x x x x x x x x x x x x x x ? x ? x x x x x x x x x x x x ? ? x x ? ? ? ? ? x x x x x x x x x x ? x x x x x x x x x x x x x x x x ? ? x ? ? ? ? ? ? ? ? ? ? x ? ? x ? ? ? x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x ? ? ? ? ? ? ? ? ? ? ? ? x x x x x x x x x x x x x x x x x x x x x x x x x x x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x x x x x x x x x x x x x x x x x x ? ? x ? ? x ? ? ? x ? ? ? ? ? ? x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x ? ? ? x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x ? x ? ? 0 x x x x x x x x x x x x x x x x x x x x x x x x x ? x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x ? x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x ? x x x x x x x x x x x x x x x x x x x x x x ? x x x x ? x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x ? x x x x x ? x x x x x x ? x x x x x ? x x x x x ? x x x x x x x ? x x x x x x x x x x ? x x x x x x x x ? x x x x x x ? x x x x x ? x x x x ? x x x x x x x x ? x x x x x x ? x x x x x x x x ? x x x x x ? x x x ? x x x x x x x x x ? x x x x x x ? x x x ? x x x x x x ? x x x x x ? x x x x x ? x x x x x ? x x x x x x x ? x x x x x x x x ? x x x x x x x x ? x x x x x x x ? x x x x x ? x x x x ? x x x x x x ? x x x x ? x x x x x x x ? x x x x x x x ? x x x x x ? x x x x x x ? x x x x x x x x x x ? x x x x x ? x x x x x x ? x x x x x x x x x ? x x x x x ? x x x x x x x ? x x x x x ? x x x x x x ? x x x x x x x x x ? x x x x x x x x x ? x x x x x x ? x x x x x x ? x x x x x ? x x x x x x ? x x x x x x x ? x x x x x x x ? x x x x x ? x x x x x x ? x x x x x x x x x x ? x x x x x x ? x x x x x x ? x x x x x x x ? x x x x x ? x x x x ? x x x x x ? x x x x x x ? x x x x ? x x x x x x x x ? x x x x ? x x x x x ? x x x x x x x ? x x x x x x ? x x x x x x x ? x x x x ? x x ? x x x x x ? x ? x x x x x x x ? x x x x x x x x ? x x x x x x ? x x x x x x x ? x x x x x x x x ? x x x x x x ? x x x x x x x ? x x x x x x ? x x x x x ? x x x x x x x x ? x x x x x x ? x x ? x x x x x ? x x x x x ? x x x x x x x ? x x x x x ? x x x x x x ? x x x x x x ? x x x x x x ? x x x x ? x x x x x x x x x x x x x x ? x x x x x x x ? x x x x x x x x x ? x x ? x x x x x x x ? x x x x x x x ? x x x x x x ? x x x x x x x x x ? x x x x x x x ? x x x x x x x x ? x x x x ? x x x x x ? x x x x x x x x ? x x x x x x x x ? x x x x x x ? x x x x x ? x x x x x x ? x x x x x ? x x x ? x x x x x x x ? x x x x x x x ? x x x x x ? x x x x x x ? x x x x x ? x x x x x x ? x x x x x ? x x x x x ? x x x x x x x x ? x x x x x x x ? x x x x ? x x x x x x x ? x x x x x x x x x ? x x x x ? x x x x x x x x ? x x x x x ? x x x x x ? x x x x x x x x ? x x x x x x ? x x x x x ? x x x x x x x x ? x x x x x x x ? x x x x x x ? x x x x x ? x x x x x x ? x x x x x x x x ? x x x ? x x x x x ? x x x x x x x x x ? x x ? x x x x x x x ? x x x x x x ? x x x x x ? x x x x x x ? x x x ? x x x x x x x x ? x x x x x x x ? x x x x x x x x x ? x x x ? x x x x x x x x ? x x x x x x x x x x x x x x x x ? x x x x x x x x x ? x x x x x x ? x x x x ? x x x ? x x x x x x ? x x x ? x x x x x x ? x x x x x x x ? x x x x x ? x x x x x x x ? x x x x x ? x x x x ? x x x x x ? x x x x x x x x ? x x x x x ? x x x x x x ? x x x x x x x ? x x x x x x x x x ? x x x x x ? x x x x x x x ? x x x x x ? x x x x x x ? x x x x x x x x x x x x x x ? x x x x x x x ? x x x x x x ? x x x x x x ? x x x x x x x ? x x x x x ? x x x x x x x x x ? x x x x x x x ? x x x x x x x ? x x x x x x x ? x x x x x x ? x x x x x x ? x x x x x ? x x x x x x ? x x x x x x ? x x x x x ? x x x x x ? x x x x
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Agent.AYB
  • MSIL.Agent.AYJ
  • MSIL.Jalapeno.J
  • MSIL.Jalapeno.L
  • MSIL.Krypt.YAGC
Show More
  • MSIL.Krypt.YAGD

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
Show More
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtYieldExecution
  • UNKNOWN
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
Other Suspicious
  • AdjustTokenPrivileges

Trending

Most Viewed

Loading...