Threat Database Trojans Trojan.MSIL.Agent.GGB

Trojan.MSIL.Agent.GGB

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.MSIL.Agent.GGB
Signature status: No Signature

Known Samples

MD5: 5ff8878c034a618a26f594cd5fad1fe4
SHA1: 6d36be2606ea1d1491375e674eb122a2435dd7df
SHA256: CE373E0AC565225A89DA769A61E5043D841C6F3514E1C5BA9A373F7A8DE239E0
File Size: 11.78 KB, 11776 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 0.0.0.0
File Version 0.0.0.0
Internal Name dlink.exe
Original Filename dlink.exe
Product Version 0.0.0.0

File Traits

  • .NET
  • x86

Block Information

Total Blocks: 14
Potentially Malicious Blocks: 4
Whitelisted Blocks: 10
Unknown Blocks: 0

Visual Map

0 0 0 x 0 0 0 0 0 x x 0 0 x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Agent.GGB

Files Modified

File Attributes
\device\namedpipe\dav rpc service Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\pshost.134150284172398097.8796.defaultappdomain.6d36be2606ea1d1491375e674eb122a2435dd7df_0000011776 Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
\device\namedpipe\wkssvc Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\__psscriptpolicytest_3yydmrbh.lkg.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_ji2eclwk.rx4.psm1 Generic Write,Read Attributes

Windows API Usage

Category API
User Data Access
  • GetUserDefaultLocaleName
  • GetUserName
  • GetUserNameEx
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
Anti Debug
  • NtQuerySystemInformation
Other Suspicious
  • AdjustTokenPrivileges

Trending

Most Viewed

Loading...