Threat Database Trojans Trojan.MSIL.AgentTesla.RGA

Trojan.MSIL.AgentTesla.RGA

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.MSIL.AgentTesla.RGA
Signature status: Self Signed

Known Samples

MD5: d50ddba3bcbba88e0fda7477704d9ff3
SHA1: 505e87048aecb45bef961845ab64607ba0de9659
SHA256: 29DAC151FFDD656E37BAD80B61868A6D66FDDC35E38EC866CF5177A0EF66B4FD
File Size: 4.99 MB, 4987944 bytes
MD5: 6ea63e7786d59e740722358a70bdd10d
SHA1: c5bd713c64c4a56c82a8a4fb62b993a433c267ec
SHA256: 2E406343CFDE030E4BCEC8C8C11A48BB8385E054F2413FD3270B9A5FF4DBF5EA
File Size: 4.16 MB, 4158504 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 0.13.2.0
  • 0.11.12.0
Comments Компактный чат для стриминга.
File Description MiniChat
File Version
  • 0.13.2.0
  • 0.11.12.0
Internal Name MiniChat.exe
Legal Copyright
  • Copyright © MegaXa 2018-2022
  • Copyright © MegaXa 2018-2025
Original Filename MiniChat.exe
Product Name MiniChat
Product Version
  • 0.13.2.0
  • 0.11.12.0

Digital Signatures

Signer Root Status
MegaXa MegaXa Self Signed

File Traits

  • .NET
  • HighEntropy
  • x86

Block Information

Total Blocks: 4,890
Potentially Malicious Blocks: 1,101
Whitelisted Blocks: 3,789
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x x x x x x x x x x x 0 x x x 0 0 x x x x x x 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 x x x x x x x x x x x x 0 0 x x 0 x 0 0 0 x x 0 x 0 x 0 0 0 0 0 0 0 x x x x x 0 x x 0 0 0 0 0 0 0 0 x 0 0 0 x 0 x x 0 x x x x x 0 x 0 x x 0 x x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x x 0 x x x x 0 0 0 x 0 x 0 0 x 0 0 0 x x 0 0 x 0 0 0 x 0 0 x x x x x x x 0 x x 0 0 x 0 x x 0 x x x x x x 0 x 0 x x x 0 x x 0 x 0 x 0 x 0 x 0 x 0 x x x x 0 0 0 x 0 0 x 0 x 0 x 0 0 0 0 0 0 x x x x x x x x x 0 x 0 0 0 0 0 x x x 0 x x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x x x x x 0 0 0 0 x 0 0 0 0 x 0 0 x x 0 x x x x x x x x x x x x x x x x 0 x x x x x 0 0 0 x 0 0 x 0 x x x x x x 0 0 x 0 x x x x x x x x x x x 0 x x 0 0 x x 0 0 0 0 0 x 0 x x x 0 0 0 0 x x 0 x 0 0 0 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x x 0 x x 0 0 0 x 0 0 x 0 x 0 x x x x x 0 0 0 0 x x 0 0 x 0 x 0 x 0 x 0 x 0 x 0 0 x x 0 x 0 x 0 x 0 0 0 x 0 x 0 x 0 0 0 x 0 0 x 0 0 0 x x x x x 0 x x 0 x 0 0 0 x 0 0 x 0 0 0 0 x x x x 0 x x x x 0 x 0 x 0 x 0 0 0 x 0 0 0 x x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x x 0 x 0 x x x x 0 0 0 0 0 0 0 x x x x x 0 x x x x 0 0 x 0 x 0 0 0 0 0 0 0 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 0 x 0 0 0 x x 0 0 x x x x x x x x x x 0 x 0 x 0 x 0 x 0 x 0 x 0 0 0 0 x x x 0 x x x x x x x x 0 0 0 0 x x 0 x 0 x 0 0 0 0 x 0 x 0 x 0 x 0 x 0 0 x 0 0 x x x x x x x x x 0 x 0 0 x x x 0 x 0 x 0 0 x x x x x x x x 0 0 x 0 x x x 0 x x x x 0 x x 0 x x x 0 x x x x x x 0 x x 0 0 0 x x x 0 0 0 x 0 x 0 x 0 0 0 0 0 0 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 0 0 x 0 x x x x 0 x x x 0 x 0 0 x 0 x 0 x 0 0 0 0 0 x x x 0 x x x 0 0 0 x 0 0 x 0 x 0 0 0 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 0 0 x 0 0 x 0 0 x x x x x x x x x x x x 0 0 x 0 0 x 0 0 0 x x 0 0 x x x x x 0 x 0 x 0 0 0 x 0 0 x 0 x x x x x x 0 x x x x x 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x 0 0 0 0 0 0 0 0 0 x x x x 0 x 0 x 0 x 0 x x 0 x x 0 0 x 0 0 x 0 0 0 0 0 x x x x x x x x x x x x x x x x x 0 0 0 0 0 x 0 x 0 x 0 x 0 x 0 x 0 x x x 0 0 x x 0 x x x x x x x x x 0 x 0 0 x 0 0 x x x x x x x x x 0 0 0 0 x x 0 x x 0 x x x x x x x x x x 0 0 0 0 x x x x x x x x x x x x x x x x 0 0 0 0 x 0 x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 x 0 x x 0 x 0 0 x 0 0 x 0 0 0 0 0 0 x 0 x x x x 0 0 0 0 0 0 x x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x x x 0 0 x x 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 x 0 0 0 x x 0 0 0 x 0 x 0 0 0 0 x x x 0 0 0 x 0 0 0 x 0 0 x 0 0 0 x 0 0 x 0 0 0 x x x 0 0 0 0 0 x 0 x 0 x x x 0 0 x x x x x x x x x x x x x x x x x x 0 0 x x 0 x x x 0 x 0 0 x x x x x x 0 0 0 0 0 0 x 0 x 0 0 x x 0 x x x x 0 x 0 x 0 0 x x x x x 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x 0 x x x 0 x x x 0 0 x x x 0 0 x 0 0 0 0 0 0 x x 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x 0 0 x x 0 0 0 0 0 x x 0 0 0 0 x 0 x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 x 0 0 0 0 x 0 0 0 0 0 x 0 0 x 0 0 0 x x x x x 0 0 x 0 0 x x x x x x x 0 x x x 0 0 x 0 0 x x 0 0 0 0 x 0 x x x 0 0 x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x x x 0 x 0 x 0 x 0 x 0 0 x 0 x 0 0 0 0 0 x x 0 x x x x x 0 x 0 0 x 0 x x x x x 0 0 0 0 0 x 0 0 0 0 0 0 0 x x x x x x x x x x x x x x x x x 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 x 0 x 0 x 0 x 0 x x x 0 x x x x 0 0 x x x x x x x x x 0 x 0 0 0 x 0 x 0 0 x x x x x 0 0 x 0 0 x 0 x 0 x x x x x x 0 0 0 0 0 x 0 x 0 0 x 0 x 0 x 0 x 0 x 0 x 0 0 x 0 x 0 0 x 0 0 0 0 0 0 0 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 0 0 0 x 0 x 0 x 0 0 x x x 0 0 x x 0 0 0 0 0 0 x 0 0 x 0 0 0 0 x 0 x x x x x x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 0 x 0 x 0 x 0 0 0 0 0 x 0 0 0 0 0 0 x 0 x 0 0 0 x 0 x 0 x 0 x 0 x 0 x 0 0 0 0 0 0 x 0 x 0 x 0 0 0 x 0 x 0 x 0 x 0 0 0 x x x x x 0 0 0 x 0 0 0 x 0 x 0 x 0 0 0 0 x x 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.AgentTesla.RGA

Files Modified

File Attributes
c:\users\user\appdata\local\temp\costura\5439b1aab3959fb09730968bda77774b\32\microsoft.web.webview2.core.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\costura\5439b1aab3959fb09730968bda77774b\32\microsoft.web.webview2.wpf.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\costura\5439b1aab3959fb09730968bda77774b\32\webview2loader.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\costura\9334811f760fc567cab929919d223346\32\microsoft.web.webview2.core.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\costura\9334811f760fc567cab929919d223346\32\microsoft.web.webview2.wpf.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\costura\9334811f760fc567cab929919d223346\32\webview2loader.dll Generic Write,Read Attributes

Windows API Usage

Category API
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation

Trending

Most Viewed

Loading...