Threat Database Trojans Trojan.MSIL.Agent.MYC

Trojan.MSIL.Agent.MYC

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 12,395
Threat Level: 80 % (High)
Infected Computers: 6
First Seen: August 12, 2026
Last Seen: September 12, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.MSIL.Agent.MYC
Signature status: No Signature

Known Samples

MD5: c3886a4278e19da33483309820b74f58
SHA1: 25c072e0e0701eb46ccd06f5c46958b9ef3a2ef2
SHA256: 25A631BEB7A26A042EAD9089F10A06C531B368CA7565470EAD92ACCCAAFA0167
File Size: 2.21 MB, 2211840 bytes
MD5: 6a08fcd91dfd0e8355827541d768bd61
SHA1: 91460dfaaca4aceef1117484f82ee02a03adbcb0
SHA256: E4D1E14579A48356458A7A1900876CB0364826DEA1CCA2353FB990A6F0E0F7A7
File Size: 809.49 KB, 809491 bytes
MD5: fe73cf6f0e40182a2424f596d6240ef9
SHA1: 1a8435751a489c5852c3bbb5bf2aa9442462b6f5
SHA256: 3DBE8A699E64202133FAF58FA2389F2E4132DD1E19A17F23059FD07D1C64953D
File Size: 311.30 KB, 311296 bytes
MD5: 4555c39281757e163f203611728f134f
SHA1: 1c11d754816337db33ed8129fe4625a8967e9d2b
SHA256: F24B2472A22C60F3F348C19994E36051AE96A77297787573B730D3E9FCC2CBB2
File Size: 143.12 KB, 143117 bytes
MD5: 81f0f0505b32f600678a619bd83e8ae3
SHA1: 414e92f1f49082dd7ad236e7924eef257e28a70a
SHA256: 4B90EA42C4FDE204281D83D78A52FA66D6699D8E3ACC23042C2F4820C9213F78
File Size: 263.70 KB, 263699 bytes
Show More
MD5: 7c570568287496af7627cc3e9048ea23
SHA1: 1e7edc7cd87e9bd007892ccb6ecf04cd9f0c5171
SHA256: DDA50922F1F6208B5F87EF3C6BA25A45261184AD099FE555C8DD6D44BEB02D63
File Size: 1.72 MB, 1718204 bytes
MD5: 6bd6e6d3cc9734f7610ef9618dbbc241
SHA1: c6a208a7fccc5e3f7d397ede445f4ab89fde23d8
SHA256: 94C2ACA5E611DA1E20D58A4605C8F8679B50F4EDCC3259B1B0B0289CA97D6B89
File Size: 345.67 KB, 345672 bytes
MD5: afff92b462835d19fc5d1f7d25e90f45
SHA1: 4b07cc8fb7078067593e64214e138745ee44fa3d
SHA256: 7B6A03A548649B977035D4080D1A418BAE26344BF7962C1A86A4BEB932FE519C
File Size: 81.83 KB, 81830 bytes
MD5: 404ced5b7958a804ff0a389feaef6dad
SHA1: 1833a24f411bfb1213b56213a2ae6c6f8b3e7825
SHA256: 94BDC4D963720A2F52475B56DD37700B7D1A6A5F32A3A0140C39AE23BDE872EA
File Size: 2.57 MB, 2572288 bytes
MD5: 65f9cd1eb89abaff93794cf248201731
SHA1: c8a3502bbbd768f4cc5fa20090f0bd10cdf9fdc1
SHA256: 569798CB9877EFE7746091B6A5455EF5B05F2058CB73698DE3CFA37730516B28
File Size: 1.22 MB, 1221565 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 0.0.0.0
Company Name Epic Games, Inc.
File Description Epic Games Launcher Installer
File Version 2026.0709.1935.0
Internal Name EpicInstallerWrapper.exe
Original Filename EpicInstallerWrapper.exe
Product Name Epic Games Launcher
Product Version 20260709.1935-10ef0f1

File Traits

  • .NET
  • big overlay
  • Installer Manifest
  • Installer Version
  • x86

Block Information

Total Blocks: 66
Potentially Malicious Blocks: 63
Whitelisted Blocks: 3
Unknown Blocks: 0

Visual Map

x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Agent.MYC

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateThreadEx
Show More
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
User Data Access
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Other Suspicious
  • AdjustTokenPrivileges