Threat Database Trojans Trojan.MSIL.Downloader.Agent.FG

Trojan.MSIL.Downloader.Agent.FG

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 2
First Seen: July 21, 2021
Last Seen: July 23, 2021
OS(es) Affected: Windows

The detection of Trojan.MSIL.Downloader.Agent.FG on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the security and integrity of your computer, and if left unchecked, it can lead to serious consequences, including data theft, system crashes, and unauthorized access to your personal information.

What Is Trojan.MSIL.Downloader.Agent.FG?

Trojan.MSIL.Downloader.Agent.FG is a type of Trojan horse malware that is designed to download and install additional malicious software on your computer. The name "Trojan.MSIL" suggests that it is written in Microsoft Intermediate Language (MSIL), which is a platform-agnostic intermediate representation of code. This type of malware can be particularly dangerous because it can evade detection by traditional antivirus software and can download new malware components, making it a persistent threat to your system's security.

How Trojan.MSIL.Downloader.Agent.FG Operates

Trojan.MSIL.Downloader.Agent.FG operates by exploiting vulnerabilities in your system's security to gain unauthorized access to your computer. Once inside, it can download and install additional malware components, including keyloggers, ransomware, and other types of malicious software. This malware can also communicate with its command and control servers to receive updates and instructions, making it a potentially persistent threat to your system's security.

The exact mechanisms used by Trojan.MSIL.Downloader.Agent.FG to operate are not fully understood, but it is believed to use a combination of social engineering tactics and exploits to gain access to your system. This can include phishing emails, infected software downloads, and exploited vulnerabilities in your system's software.

Symptoms of Infection

The symptoms of a Trojan.MSIL.Downloader.Agent.FG infection can vary, but common indicators include slow system performance, unexpected pop-ups and advertisements, and unfamiliar programs or icons on your desktop. You may also notice that your system is crashing or freezing frequently, or that your antivirus software is detecting and blocking suspicious activity.

  • Unexplained changes to your system's settings or configuration
  • Unfamiliar programs or icons on your desktop
  • Slow system performance or frequent crashes
  • Unexpected pop-ups and advertisements
  • Antivirus software detecting and blocking suspicious activity

How to Remove Trojan.MSIL.Downloader.Agent.FG

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow you to download and install removal tools.
  2. Download and install a reputable anti-malware tool, such as SpyHunter, and perform a full scan of your system to detect and remove the malware.
  3. Uninstall any suspicious programs or software that you do not recognize or that were installed recently.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform a follow-up scan with your anti-malware tool to ensure that the malware has been fully removed.

Conclusion

The detection of Trojan.MSIL.Downloader.Agent.FG on your system is a serious security threat that requires immediate attention. By following the removal steps outlined above, you can help to protect your system and prevent further damage. It is also important to take steps to prevent future infections, including keeping your operating system and software up to date, using strong antivirus software, and being cautious when opening email attachments or downloading software from the internet.

Analysis Report

General information

Family Name: Trojan.MSIL.Downloader.Agent.FG
Signature status: No Signature

Known Samples

MD5: 5a323c7d5f9d74b796325afdc57414fd
SHA1: d3a81053f8c182b1ca37abf49006036baa633156
SHA256: 340F639693DD7FA9AF153EA89995CB21A937A5A7EAFF305DEEBD82587FE56E59
File Size: 176.13 KB, 176128 bytes
MD5: 19ef2cbd3935fb56e694538d92acdbb4
SHA1: 47cfbfefdf637bf18904c2a1a12c5daf46f0f7f0
SHA256: C9FD88494237587C317299C9DE08F41493E76C0A60F0E57CC574A6F1EE2F0BB3
File Size: 196.10 KB, 196096 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 5.3.2.0
  • 2.1.6.0
Company Name
  • JCommerce SA
  • S&T Services Polska Sp. z o.o.
File Description GWOPApp
File Version
  • 5.3.2.0
  • 2.1.6.0
Internal Name GWOPApp.exe
Legal Copyright
  • Copyright © JCommerce 2010
  • Copyright © S&T 2009
Original Filename GWOPApp.exe
Product Name GWOPApp
Product Version
  • 5.3.2.0
  • 2.1.6.0

File Traits

  • .NET
  • HighEntropy
  • x86

Block Information

Total Blocks: 116
Potentially Malicious Blocks: 4
Whitelisted Blocks: 45
Unknown Blocks: 67

Visual Map

0 ? 0 ? ? x ? ? ? ? ? 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? x ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? ? ? 0 0 ? 0 0 ? 0 x 0 0 0 ? ? 0 0 ? 0 0 ? 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\windows\appcompat\programs\amcache.hve Read Data,Read Control,Write Data
c:\windows\appcompat\programs\amcache.hve Write Attributes

Registry Modifications

Key::Value Data API Name
HKLM\system\software\microsoft\tip\aggregateresults::data 馐ʊ耀ŚT隞̃뤁耀꧌ьČ RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAdjustPrivilegesToken
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcDeleteSecurityContext
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
Show More
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeleteValueKey
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtLoadKeyEx
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
User Data Access
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
Process Shell Execute
  • CreateProcess
Encryption Used
  • BCryptOpenAlgorithmProvider
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory

Shell Command Execution

C:\Windows\Microsoft.NET\Framework64\v2.0.50727\\dw20.exe dw20.exe -x -s 708
C:\Windows\Microsoft.NET\Framework\v2.0.50727\\dw20.exe dw20.exe -x -s 788

Related Posts

Trending

Most Viewed

Loading...