Threat Database Trojans Trojan.MSIL.Agent.DFBT

Trojan.MSIL.Agent.DFBT

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 5,886
Threat Level: 80 % (High)
Infected Computers: 55
First Seen: September 4, 2024
Last Seen: April 1, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.MSIL.Agent.DFBT
Signature status: No Signature

Known Samples

MD5: 81d51adc1067e977b29d461075091b2f
SHA1: 744e71bcf0e7187ce947f0088b108b47a8a09d6a
SHA256: 33B83A32E17806140E2E99397974D210DB7C94560F8803F73B97BF5FEF98D6D5
File Size: 8.28 MB, 8282984 bytes
MD5: f679ae28d32f3bb14c8cb5020725e9a5
SHA1: 0befd07485a56738436e9ad934019d0f8c0fbfa1
SHA256: 5C14003550212647545BCB85B4216F2724AAEC5955053E2B1292378D80B691A2
File Size: 356.35 KB, 356352 bytes
MD5: 2975494480b7b60382400bc88405db93
SHA1: 6ca6695028837e8719416e690b7e67125071236c
SHA256: B2CD625F472B59C1E340FED80291A7BC7E24C42088A7E1D544B3C6D597CA2B9E
File Size: 356.35 KB, 356352 bytes
MD5: bd1647fad75490031a8dae1a74118f9c
SHA1: c4f3eeda32d983dfe13e5c9365c7494086f78668
SHA256: 328E9D4BD8B41DA5A82744EE197FCA16207AEACC2E5F78595B0A1620F486FD3A
File Size: 356.35 KB, 356352 bytes
MD5: fe51eec5ec596cfc31fb4b3dc37a441f
SHA1: c588cb2f2522d57958c327a98d3d40a03546b882
SHA256: 2595333E4294FB73CA5AA5DCE8DD672E941712EF6690966569102E8E0451FFA9
File Size: 356.35 KB, 356352 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File has exports table
  • File is .NET application
  • File is 32-bit executable
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
Show More
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version
  • 1.3.0.0
  • 1.1.0.0
File Version
  • 1.3.0.0
  • 1.1.0.0
Internal Name
  • Client.exe
  • vstdlib_s64.dll
Original Filename
  • Client.exe
  • vstdlib_s64.dll
Product Version
  • 1.3.0.0
  • 1.1.0.0

Digital Signatures

Signer Root Status
Valve Corp. DigiCert Trusted Root G4 Hash Mismatch

File Traits

  • .NET
  • dll
  • ntdll
  • RijndaelManaged
  • Run
  • x64
  • x86

Block Information

Total Blocks: 762
Potentially Malicious Blocks: 312
Whitelisted Blocks: 371
Unknown Blocks: 79

Visual Map

? x x x ? x 0 0 0 x x ? x x x x x x 0 x 0 0 0 x x 0 x x 0 0 0 0 x 0 0 ? 0 0 0 0 0 x x x 0 0 0 x x x 0 0 0 0 x 0 0 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x x 0 0 x 0 x 0 0 x x x 0 0 0 0 0 0 0 0 0 0 x x x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x x x x 0 0 x x x 0 0 0 x 0 x x x 0 x x x 0 x x 0 0 ? ? x ? 0 x x x x x 0 0 x 0 x 0 x 0 0 ? x x ? x ? x x x x x x x x 0 0 x x x x 0 x x x 0 0 0 ? ? ? ? x x x x x 0 x x x x x x x x x x ? ? ? ? 0 0 x x ? ? x x x x x ? ? ? 0 ? x x 0 x 0 0 0 0 0 x x 0 0 0 0 0 0 x x 0 0 0 0 0 0 x x x x x ? 0 ? ? x ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 x x x x 0 0 x x 0 0 0 x 0 0 0 0 x 0 0 x x x x 0 x x 0 x 0 x 0 0 0 0 x 0 x x 0 0 x x x 0 0 0 0 0 x 0 0 0 0 0 x 0 x x ? ? ? x x x x ? x 0 x 0 x x x x 0 0 x 0 x 0 0 0 x 0 x x x x x 0 x x 0 0 0 0 x 0 x x 0 x x 0 x x x 0 x 0 0 0 0 0 x x x x x 0 x ? x x x 0 0 0 0 0 0 x 0 x x x x x 0 0 0 x 0 x x 0 0 0 x 0 x x x x x 0 x 0 0 0 0 x 0 x 0 x 0 x x 0 0 x 0 0 0 x x x 0 0 0 0 x ? ? ? ? x x 0 x 0 x x x x x 0 ? ? ? x x x x 0 x x ? x x x 0 x x x x x ? x x x x 0 x x 0 0 x x x x x x x x x x x x 0 x x ? 0 x x 0 x x ? ? ? 0 x ? ? ? ? ? ? ? ? ? x x x x x ? ? ? ? 0 ? x ? ? x ? ? x ? ? ? x x 0 ? ? ? ? ? ? x x x ? x 0 x 0 x 0 x ? 0 x 0 0 ? x ? 0 0 0 0 0 0 x x 0 x x 0 0 x 0 x x 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x 0 0 0 0 x x x x x x x x x x x x x x x 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
Show More
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • win32u.dll!NtGdiBitBlt
  • win32u.dll!NtGdiCreateBitmap
  • win32u.dll!NtGdiCreateCompatibleDC
  • win32u.dll!NtGdiCreateDIBitmapInternal
  • win32u.dll!NtGdiCreateSolidBrush
  • win32u.dll!NtGdiDeleteObjectApp
  • win32u.dll!NtGdiExtGetObjectW
  • win32u.dll!NtGdiGetDCforBitmap
  • win32u.dll!NtGdiGetDCObject
  • win32u.dll!NtGdiGetDeviceCaps
  • win32u.dll!NtGdiRestoreDC
  • win32u.dll!NtGdiSaveDC
  • win32u.dll!NtGdiSelectBitmap
  • win32u.dll!NtGdiSetDIBitsToDeviceInternal
  • win32u.dll!NtUserBuildHwndList
  • win32u.dll!NtUserCallTwoParam
  • win32u.dll!NtUserCreateEmptyCursorObject
  • win32u.dll!NtUserCreateWindowEx
  • win32u.dll!NtUserDestroyWindow
  • win32u.dll!NtUserFindExistingCursorIcon
  • win32u.dll!NtUserGetAncestor
  • win32u.dll!NtUserGetClassInfoEx
  • win32u.dll!NtUserGetClassName
  • win32u.dll!NtUserGetDC
  • win32u.dll!NtUserGetGUIThreadInfo
  • win32u.dll!NtUserGetIconInfo
  • win32u.dll!NtUserGetIconSize
  • win32u.dll!NtUserGetImeInfoEx
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetObjectInformation
  • win32u.dll!NtUserGetProcessWindowStation
  • win32u.dll!NtUserGetProp
  • win32u.dll!NtUserGetThreadDesktop
  • win32u.dll!NtUserGetThreadState
  • win32u.dll!NtUserGetWindowCompositionAttribute
  • win32u.dll!NtUserIsNonClientDpiScalingEnabled
  • win32u.dll!NtUserIsTopLevelWindow
  • win32u.dll!NtUserMessageCall
  • win32u.dll!NtUserRegisterClassExWOW
  • win32u.dll!NtUserRegisterWindowMessage
  • win32u.dll!NtUserReleaseDC
  • win32u.dll!NtUserRemoveProp
  • win32u.dll!NtUserSelectPalette
  • win32u.dll!NtUserSetCursorIconData
  • win32u.dll!NtUserSetWindowFNID
  • win32u.dll!NtUserSetWindowLongPtr
  • win32u.dll!NtUserSetWindowPos
  • win32u.dll!NtUserUpdateInputContext
User Data Access
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext

Trending

Most Viewed

Loading...