Threat Database Trojans Trojan.MSIL.Agent.SFD

Trojan.MSIL.Agent.SFD

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 27,732
Threat Level: 80 % (High)
Infected Computers: 32
First Seen: October 23, 2023
Last Seen: January 4, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.MSIL.Agent.SFD
Signature status: No Signature

Known Samples

MD5: 2efd9b23be5892b942833a4adab4e362
SHA1: fc301f314c7d0d1c89c0a605865df98502668c1d
SHA256: E91ED7FFB7ABB6B62A8A8DC24240AEF8AEB0B1B95A148CC1CFCF044106914829
File Size: 46.59 KB, 46592 bytes
MD5: 4fda60fb43f1294582c2ce05ea063229
SHA1: f437a384ecfb83033e95efee4611e43749e003b5
SHA256: B86F82493C3F834779586C30C79A9EC5D26E25E6F991121F8A13D58EC0A0A096
File Size: 2.12 MB, 2121728 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 1.2.3.0
  • 1.0.0.0
Company Name Xeno
File Description
  • csrss
  • xeno rat server
File Version
  • 3.2.1.0
  • 1.0.0.0
Internal Name
  • xeno rat client.exe
  • xeno rat server.exe
Legal Copyright
  • Copyright © 2023
  • Copyright © 2025
Legal Trademarks Xeno
Original Filename
  • xeno rat server.exe
  • Xeno_manager.exe
Product Name
  • Xeno-manager
  • xeno rat server
Product Version
  • 1.2.3.0
  • 1.0.0.0

File Traits

  • .NET
  • Agile.net
  • Fody
  • HighEntropy
  • ntdll
  • Run
  • x86

Block Information

Total Blocks: 677
Potentially Malicious Blocks: 18
Whitelisted Blocks: 308
Unknown Blocks: 351

Visual Map

x x x x ? 0 ? 0 0 ? 0 0 ? ? ? ? ? ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? 0 0 ? ? 0 ? ? 0 0 0 ? 0 0 x ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 0 ? ? 0 0 x ? 0 0 0 ? ? ? x x 0 0 0 x 0 0 ? 0 0 0 0 0 ? ? ? ? ? ? x 0 ? 0 0 0 0 ? x x x x 0 0 ? ? ? ? 0 ? ? 0 ? ? 0 0 0 ? ? ? ? 0 0 0 0 ? 0 0 0 0 0 0 ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 ? 0 ? ? x ? ? ? 0 0 ? ? 0 ? 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 ? ? ? 0 ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 ? 0 0 ? ? 0 ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? 0 ? 0 ? 0 ? 0 ? 0 ? ? ? ? ? ? 0 0 0 ? 0 ? 0 0 0 ? ? 0 ? ? 0 ? ? ? 0 0 ? 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? 0 ? ? ? ? 0 0 0 0 ? ? 0 0 0 0 0 0 ? ? ? 0 0 0 0 ? x ? ? ? ? ? ? ? 0 0 ? ? 0 ? ? ? ? 0 ? 0 0 ? 0 0 0 0 ? 0 0 ? ? ? ? ? ? 0 0 0 0 ? 0 ? 0 ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 ? 0 x 0 0 ? ? ? ? ? ? ? ? ? ? ? 0 0 ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 ? 0 ? ? ? ? ? ? ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Agent.SFI

Files Modified

File Attributes
c:\users\user\appdata\roaming\xenomanager\fc301f314c7d0d1c89c0a605865df98502668c1d_0000046592 Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144

Windows API Usage

Category API
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Encryption Used
  • BCryptOpenAlgorithmProvider

Trending

Most Viewed

Loading...