Trojan.MSIL.Agent.VVF
Threat Scorecard
EnigmaSoft Threat Scorecard
EnigmaSoft Threat Scorecards are assessment reports for different malware threats which have been collected and analyzed by our research team. EnigmaSoft Threat Scorecards evaluate and rank threats using several metrics including real-world and potential risk factors, trends, frequency, prevalence, and persistence. EnigmaSoft Threat Scorecards are updated regularly based on our research data and metrics and are useful for a wide range of computer users, from end users seeking solutions to remove malware from their systems to security experts analyzing threats.
EnigmaSoft Threat Scorecards display a variety of useful information, including:
Popularity Rank: The ranking of a particular threat in EnigmaSoft’s Threat Database.
Severity Level: The determined severity level of an object, represented numerically, based on our risk modeling process and research, as explained in our Threat Assessment Criteria.
Infected Computers: The number of confirmed and suspected cases of a particular threat detected on infected computers as reported by SpyHunter.
See also Threat Assessment Criteria.
| Popularity Rank: | 6,288 |
| Threat Level: | 80 % (High) |
| Infected Computers: | 77 |
| First Seen: | February 3, 2025 |
| Last Seen: | May 25, 2026 |
| OS(es) Affected: | Windows |
Table of Contents
Analysis Report
General information
| Family Name: | Trojan.MSIL.Agent.VVF |
|---|---|
| Signature status: | No Signature |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
1209962ff5b906e61e370dd4657527f2
SHA1:
f83067783396721fb50b6d764d4c228bed1a6d4d
SHA256:
C26806F9D67D651EFFD50D40F4F275AC27DEF9F1EE31AE1F8C289D3ED16FB150
File Size:
486.91 KB, 486912 bytes
|
|
MD5:
6dee6a8cc89a0a00a43db074535803d5
SHA1:
9582354ec1b77e62453d4ac68c0c686e25dd9e08
SHA256:
8983AC6BA515D20C49A2482C57500B02376A088E057B7B3F9F8E7618EAEB28E2
File Size:
2.41 MB, 2409472 bytes
|
|
MD5:
aeb91d5371bf9af7bf73bf4f6d98381f
SHA1:
f6dc981ed012428f5398096ea0dde72aeee4e349
SHA256:
24AA36005806B28E46E0D4DD434B80B011E0054B61DC67292B859CB5F7F05330
File Size:
3.55 MB, 3554304 bytes
|
|
MD5:
6b31d6f8e00d3b18c0c72aa186623cf8
SHA1:
ef3c2b332ea9668a95f59cfa7b89d7c8ae0d116d
SHA256:
4CEB8804D5998FEE1E9845250CA40754D616A68C1D0EED09C2239A48B2C642FE
File Size:
2.44 MB, 2439168 bytes
|
|
MD5:
c66793089feddb6184ac8c2b650ebcc0
SHA1:
fe4e3a12bb6e8c3e0ff419aa65c726f6466f28f4
SHA256:
4399E23D23135BCB6A2CAE35D3D212ED007EDA1FA27C363BFD62E0AA3D46D7B3
File Size:
4.66 MB, 4661248 bytes
|
Show More
|
MD5:
ca3c47dbe417494a0ef127f99cfbcd42
SHA1:
38ac4acee5044c4f2f3c06c01d0186a56eb633f3
SHA256:
4A677A34456D8A9A033252A3A77E7C36E25C1B9092333B357BFD016C3A31004B
File Size:
944.67 KB, 944672 bytes
|
|
MD5:
5b475937e8af9749c0c4b986573bd9f3
SHA1:
eacb43b68bc76552e8568aa30062a9194b12286a
SHA256:
05050FA330B593AC5E3B71E08EEE27A41E077B5686FFECDC517D063086D3C370
File Size:
1.83 MB, 1827328 bytes
|
|
MD5:
7dfd536f80ccbdda5428e0be995c7fb6
SHA1:
3ab35ff9c72e58e13d6336a4363fb631cfd76fd7
SHA256:
1B9D3D2169740E3C51BBC296883D3EBCA91B373C5C0FA861EAB36F1E5DBE9179
File Size:
3.77 MB, 3768352 bytes
|
|
MD5:
03a0f2ad16c7796058141d32c3154f38
SHA1:
33c4def2edb751f37eaa0c4026eba29c4876218f
SHA256:
4D81423A8E96E54566504946A6BFD500F47D0FC0D57C874AFD2CFD1B517AE34D
File Size:
3.69 MB, 3691008 bytes
|
|
MD5:
7cba34386c4a0802a7b8c945572e79b8
SHA1:
8f49b4cfacdf5903352aa9b9d9e6d96ba90b6168
SHA256:
3E1AE4D08610C49E2E43E1149A428846C7C98DA313C22772EE95B65AE20B9A55
File Size:
1.26 MB, 1259520 bytes
|
|
MD5:
2d832a62a14b3943b4236cd5137e29a4
SHA1:
9e39466267733bf9301d4bc35b1139ea5b8ba26f
SHA256:
4C80940B8A4AF46B4A8B1F55548D36F779420E41F02A4B374E0BA49AA9E3FA16
File Size:
701.95 KB, 701952 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have debug information
- File doesn't have exports table
- File doesn't have relocations information
- File doesn't have security information
- File has TLS information
- File is .NET application
- File is 32-bit executable
- File is 64-bit executable
- File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
Show More
- File is either console or GUI application
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is Native application (NOT .NET application)
- File is not packed
- IMAGE_FILE_DLL is not set inside PE header (Executable)
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
File Icons
File Icons
This section displays icon resources found within family samples. Malware often replicates icons commonly associated with legitimate software to mislead users into believing the malware is safe.Windows PE Version Information
Windows PE Version Information
This section displays values and attributes that have been set in the Windows file version information data structure for samples within this family. To mislead users, malware actors often add fake version information mimicking legitimate software.| Name | Value |
|---|---|
| Assembly Version |
|
| Comments | xiaomiauth.orh |
| Company Name |
|
| File Description |
|
| File Version |
|
| Internal Name |
|
| Legal Copyright |
|
| Original Filename |
|
| Product Name |
|
| Product Version |
|
File Traits
- .NET
- 00 section
- 2+ executable sections
- Agile.net
- dll
- Fody
- HighEntropy
- ntdll
- RijndaelManaged
- x64
Show More
- x86
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.Similar Families
Similar Families
This section lists other families that share similarities with this family, based on EnigmaSoft’s analysis. Many malware families are created from the same malware toolkits and use the same packing and encryption techniques but uniquely extend functionality. Similar families may also share source code, attributes, icons, subcomponents, compromised and/or invalid digital signatures, and network characteristics. Researchers leverage these similarities to rapidly and effectively triage file samples and extend malware detection rules.- MSIL.Agent.VVF
Files Modified
Files Modified
This section lists files that were created, modified, moved and/or deleted by samples in this family. File system activity can provide valuable insight into how malware functions on the operating system.| File | Attributes |
|---|---|
| \device\namedpipe | Generic Read,Write Attributes |
| \device\namedpipe | Generic Write,Read Attributes |
| \device\namedpipe\dav rpc service | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| \device\namedpipe\pshost.134127142200690859.5076.defaultappdomain.powershell | Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288 |
| \device\namedpipe\wkssvc | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\__psscriptpolicytest_dwl0olr5.yoi.psm1 | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\__psscriptpolicytest_dx3ri4ny.0rx.ps1 | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\autb79d.tmp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\autb82a.tmp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\guardian_src_466a61b761fc4e3a9df750a421b6183c.cs | Generic Write,Read Attributes |
Show More
| c:\users\user\appdata\local\temp\guardian_src_5cebd16bb1b94be6ae5b0bbd98a25280.cs | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\guardian_src_e7ccc59cd6614f98a671b376dc3af842.cs | Generic Write,Read Attributes |
| c:\users\user\downloads\modified_scripts.ps1 | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\downloads\modified_scripts.ps1 | Generic Write,Read Attributes |
| c:\users\user\downloads\modified_scripts.ps1 | Synchronize,Write Attributes |
| c:\users\user\downloads\mohamed_soft_kirin.exe | Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144 |
| c:\users\user\downloads\mohamed_soft_kirin.exe | Generic Write,Read Attributes |
| c:\users\user\downloads\mohamed_soft_kirin.exe | Synchronize,Write Attributes |
Registry Modifications
Registry Modifications
This section lists registry keys and values that were created, modified and/or deleted by samples in this family. Windows Registry activity can provide valuable insight into malware functionality. Additionally, malware often creates registry values to allow itself to automatically start and indefinitely persist after an initial infection has compromised the system.| Key::Value | Data | API Name |
|---|---|---|
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe | ꉭ䮦仚ǜ | RegNtPreCreateKey |
| HKCU\software\xtrial::start | 潗㆜裞 | RegNtPreCreateKey |
| HKCU\software\xtrial::end | 꽗愳㵦裞 | RegNtPreCreateKey |
| HKCU\software\xtrial::days | RegNtPreCreateKey | |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe | 싑掅ǜ | RegNtPreCreateKey |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe | RegNtPreCreateKey | |
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe | RegNtPreCreateKey |
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API usage analysis is a valuable tool that can help identify malicious activity, such as keylogging, security privilege escalation, data encryption, data exfiltration, interference with antivirus software, and network request manipulation.| Category | API |
|---|---|
| User Data Access |
|
| Other Suspicious |
|
| Anti Debug |
|
| Process Shell Execute |
|
| Syscall Use |
Show More
26 additional items are not displayed above. |
| Encryption Used |
|
| Network Winsock2 |
|
| Network Winsock |
|
| Process Manipulation Evasion |
|
Shell Command Execution
Shell Command Execution
This section lists Windows shell commands that are run by the samples in this family. Windows Shell commands are often leveraged by malware for nefarious purposes and can be used to elevate security privileges, download and launch other malware, exploit vulnerabilities, collect and exfiltrate data, and hide malicious activity.
"C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /target:exe /out:"C:\Users\Bcqllmnm\AppData\Local\Temp\f83067783396721fb50b6d764d4c228bed1a6d4d_0000486912.exe" "C:\Users\Bcqllmnm\AppData\Local\Temp\guardian_src_e7ccc59cd6614f98a671b376dc3af842.cs"
|
"C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /target:exe /out:"C:\Users\Arfqkkxx\AppData\Local\Temp\f6dc981ed012428f5398096ea0dde72aeee4e349_0003554304.exe" "C:\Users\Arfqkkxx\AppData\Local\Temp\guardian_src_466a61b761fc4e3a9df750a421b6183c.cs"
|
powershell.exe -NoProfile -ExecutionPolicy Bypass -WindowStyle Hidden -File "c:\Users\user\downloads\Modified_Scripts.ps1"
|
"C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /target:exe /out:"C:\Users\Npvydebq\AppData\Local\Temp\3ab35ff9c72e58e13d6336a4363fb631cfd76fd7_0003768352.exe" "C:\Users\Npvydebq\AppData\Local\Temp\guardian_src_5cebd16bb1b94be6ae5b0bbd98a25280.cs"
|