Threat Database Trojans Trojan.MSIL.Agent.XX

Trojan.MSIL.Agent.XX

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.MSIL.Agent.XX
Signature status: No Signature

Known Samples

MD5: 74d261132d23b665c01d4cf2351c72b9
SHA1: acbc3454d83f91585d8c882da75fafad8a1aea3a
SHA256: EDBBAFDC66D4FEA961FFCE580D0F16EF088C77E83888CBCB6BE9AFE2197ACE9E
File Size: 2.26 MB, 2264064 bytes
MD5: bf7e7b3253f21e61fd13f60f151edc6f
SHA1: 75ee87c39db0aef020c11ee646c345d1ff989a7f
SHA256: 16E674F4E3C12F76D2AF8C492FC5725A69CA25685FB3FB2F0EFC3044A9837F83
File Size: 4.08 MB, 4075008 bytes
MD5: ac4616b48476d1521c037d732d931138
SHA1: 159cc00996ba3707f33c3384542d81e3f37ace1c
SHA256: 531D154BAFA90654B25ACCDA0B01C84D0164FAF1C3A8990DA0E38DEAE3EAD01C
File Size: 587.39 KB, 587392 bytes
MD5: 2b676a3defe3a109fe1fea0be16e2a8b
SHA1: a605a0f9a1908d2f1518ecb17665851c25d02639
SHA256: 6A1E05FFDBEECD401EC8A1824148D013A9D788D3C85D079CE38E81F427080591
File Size: 2.40 MB, 2402532 bytes
MD5: bc6ee84c00f47698616a3066d5bcaae9
SHA1: 91662b7f097df74f992dda455716f18c78239997
SHA256: 77963C2256C2AA9A131DEAA6825551BDA351902382F266DAACF3F1BE0C780DFD
File Size: 2.44 MB, 2441216 bytes
Show More
MD5: 96f5317da460d5e56492ec95665feaae
SHA1: 68831ec794b09b207b17af929edcbbe8f6bf524c
SHA256: 99301CF302BED8B8994C12D681EB87713960D20BFABD43E1D2EAEAA1C70725A1
File Size: 80.38 KB, 80384 bytes
MD5: c01d1e86bcedca5a887aeb1af9bf3d0b
SHA1: 29d3f688a6b783391f2b2ee52275dd2e71758556
SHA256: D1D16DF5304B3EA5DD5605C4A69CB6159CD15AB51B4C5CB628928E437A46BE75
File Size: 587.38 KB, 587382 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is .NET application
  • File is 32-bit executable
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
Show More
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
File Description
  • GSMSRINUTOOL
  • Hvnc
  • MDMFIXCARLCARE
File Version
  • 1.00
  • 1.0.0.0
Internal Name
  • GSMSRINUTOOL.exe
  • Hvnc.dll
  • MDMFIXCARLCARE.exe
  • TJprojMain
Legal Copyright
  • Copyright © 2023
  • Copyright © 2025
Original Filename
  • GSMSRINUTOOL.exe
  • Hvnc.dll
  • MDMFIXCARLCARE.exe
  • TJprojMain.exe
Product Name
  • GSMSRINUTOOL
  • Hvnc
  • MDMFIXCARLCARE
  • Project1
Product Version
  • 1.00
  • 1.0.0.0

File Traits

  • .NET
  • 2+ executable sections
  • Agile.net
  • dll
  • Fody
  • HighEntropy
  • ntdll
  • x86

Windows API Usage

Category API
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
Show More
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Other Suspicious
  • SetWindowsHookEx

Trending

Most Viewed

Loading...