Trojan.MSIL.Agent.MYC
Threat Scorecard
EnigmaSoft Threat Scorecard
EnigmaSoft Threat Scorecards are assessment reports for different malware threats which have been collected and analyzed by our research team. EnigmaSoft Threat Scorecards evaluate and rank threats using several metrics including real-world and potential risk factors, trends, frequency, prevalence, and persistence. EnigmaSoft Threat Scorecards are updated regularly based on our research data and metrics and are useful for a wide range of computer users, from end users seeking solutions to remove malware from their systems to security experts analyzing threats.
EnigmaSoft Threat Scorecards display a variety of useful information, including:
Popularity Rank: The ranking of a particular threat in EnigmaSoft’s Threat Database.
Severity Level: The determined severity level of an object, represented numerically, based on our risk modeling process and research, as explained in our Threat Assessment Criteria.
Infected Computers: The number of confirmed and suspected cases of a particular threat detected on infected computers as reported by SpyHunter.
See also Threat Assessment Criteria.
| Popularity Rank: | 12,395 |
| Threat Level: | 80 % (High) |
| Infected Computers: | 6 |
| First Seen: | August 12, 2026 |
| Last Seen: | September 12, 2026 |
| OS(es) Affected: | Windows |
Table of Contents
Analysis Report
General information
| Family Name: | Trojan.MSIL.Agent.MYC |
|---|---|
| Signature status: | No Signature |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
c3886a4278e19da33483309820b74f58
SHA1:
25c072e0e0701eb46ccd06f5c46958b9ef3a2ef2
SHA256:
25A631BEB7A26A042EAD9089F10A06C531B368CA7565470EAD92ACCCAAFA0167
File Size:
2.21 MB, 2211840 bytes
|
|
MD5:
6a08fcd91dfd0e8355827541d768bd61
SHA1:
91460dfaaca4aceef1117484f82ee02a03adbcb0
SHA256:
E4D1E14579A48356458A7A1900876CB0364826DEA1CCA2353FB990A6F0E0F7A7
File Size:
809.49 KB, 809491 bytes
|
|
MD5:
fe73cf6f0e40182a2424f596d6240ef9
SHA1:
1a8435751a489c5852c3bbb5bf2aa9442462b6f5
SHA256:
3DBE8A699E64202133FAF58FA2389F2E4132DD1E19A17F23059FD07D1C64953D
File Size:
311.30 KB, 311296 bytes
|
|
MD5:
4555c39281757e163f203611728f134f
SHA1:
1c11d754816337db33ed8129fe4625a8967e9d2b
SHA256:
F24B2472A22C60F3F348C19994E36051AE96A77297787573B730D3E9FCC2CBB2
File Size:
143.12 KB, 143117 bytes
|
|
MD5:
81f0f0505b32f600678a619bd83e8ae3
SHA1:
414e92f1f49082dd7ad236e7924eef257e28a70a
SHA256:
4B90EA42C4FDE204281D83D78A52FA66D6699D8E3ACC23042C2F4820C9213F78
File Size:
263.70 KB, 263699 bytes
|
Show More
|
MD5:
7c570568287496af7627cc3e9048ea23
SHA1:
1e7edc7cd87e9bd007892ccb6ecf04cd9f0c5171
SHA256:
DDA50922F1F6208B5F87EF3C6BA25A45261184AD099FE555C8DD6D44BEB02D63
File Size:
1.72 MB, 1718204 bytes
|
|
MD5:
6bd6e6d3cc9734f7610ef9618dbbc241
SHA1:
c6a208a7fccc5e3f7d397ede445f4ab89fde23d8
SHA256:
94C2ACA5E611DA1E20D58A4605C8F8679B50F4EDCC3259B1B0B0289CA97D6B89
File Size:
345.67 KB, 345672 bytes
|
|
MD5:
afff92b462835d19fc5d1f7d25e90f45
SHA1:
4b07cc8fb7078067593e64214e138745ee44fa3d
SHA256:
7B6A03A548649B977035D4080D1A418BAE26344BF7962C1A86A4BEB932FE519C
File Size:
81.83 KB, 81830 bytes
|
|
MD5:
404ced5b7958a804ff0a389feaef6dad
SHA1:
1833a24f411bfb1213b56213a2ae6c6f8b3e7825
SHA256:
94BDC4D963720A2F52475B56DD37700B7D1A6A5F32A3A0140C39AE23BDE872EA
File Size:
2.57 MB, 2572288 bytes
|
|
MD5:
65f9cd1eb89abaff93794cf248201731
SHA1:
c8a3502bbbd768f4cc5fa20090f0bd10cdf9fdc1
SHA256:
569798CB9877EFE7746091B6A5455EF5B05F2058CB73698DE3CFA37730516B28
File Size:
1.22 MB, 1221565 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have debug information
- File doesn't have exports table
- File doesn't have security information
- File is .NET application
- File is 32-bit executable
- File is either console or GUI application
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is not packed
- IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
Windows PE Version Information
Windows PE Version Information
This section displays values and attributes that have been set in the Windows file version information data structure for samples within this family. To mislead users, malware actors often add fake version information mimicking legitimate software.| Name | Value |
|---|---|
| Assembly Version | 0.0.0.0 |
| Company Name | Epic Games, Inc. |
| File Description | Epic Games Launcher Installer |
| File Version | 2026.0709.1935.0 |
| Internal Name | EpicInstallerWrapper.exe |
| Original Filename | EpicInstallerWrapper.exe |
| Product Name | Epic Games Launcher |
| Product Version | 20260709.1935-10ef0f1 |
File Traits
- .NET
- big overlay
- Installer Manifest
- Installer Version
- x86
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 66 |
|---|---|
| Potentially Malicious Blocks: | 63 |
| Whitelisted Blocks: | 3 |
| Unknown Blocks: | 0 |
Visual Map
? - Unknown Block
x - Potentially Malicious Block
Similar Families
Similar Families
This section lists other families that share similarities with this family, based on EnigmaSoft’s analysis. Many malware families are created from the same malware toolkits and use the same packing and encryption techniques but uniquely extend functionality. Similar families may also share source code, attributes, icons, subcomponents, compromised and/or invalid digital signatures, and network characteristics. Researchers leverage these similarities to rapidly and effectively triage file samples and extend malware detection rules.- MSIL.Agent.MYC
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API usage analysis is a valuable tool that can help identify malicious activity, such as keylogging, security privilege escalation, data encryption, data exfiltration, interference with antivirus software, and network request manipulation.| Category | API |
|---|---|
| Syscall Use |
Show More
|
| User Data Access |
|
| Other Suspicious |
|