Threat Database Trojans Trojan.MSIL.Agent.KPV

Trojan.MSIL.Agent.KPV

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.MSIL.Agent.KPV
Signature status: No Signature

Known Samples

MD5: 68e3b63c2487b6f604c2fcd099ee1703
SHA1: 1140e1b27987c98494018a3ee2a7e4278f9f3b87
SHA256: A9E1EA5BF6CC1059360D608063140A0EEEFB916620AE5E4F8D4E157021A5F789
File Size: 1.06 MB, 1064960 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 5.8.2.0
Comments Advanced Windows Forms parsing and analysis engine
Company Name UIAnalytics Pro
File Description FormParser Advanced
File Version 5.8.2.2947
Internal Name pYFq.exe
Legal Copyright Copyright © UIAnalytics Pro
Original Filename pYFq.exe
Product Name FormParser Advanced
Product Version 5.8.2.2947

File Traits

  • .NET
  • HighEntropy
  • x86

Block Information

Total Blocks: 28
Potentially Malicious Blocks: 18
Whitelisted Blocks: 10
Unknown Blocks: 0

Visual Map

x x x x x x x x x 0 x 0 x 0 x 0 0 0 0 x 0 x x x 0 x 0 x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
User Data Access
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation

Trending

Most Viewed

Loading...