Threat Database Trojans Trojan.MSIL.Spy.Agent.GFB

Trojan.MSIL.Spy.Agent.GFB

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 21,518
Threat Level: 80 % (High)
Infected Computers: 2
First Seen: April 18, 2026
Last Seen: May 9, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.MSIL.Spy.Agent.GFB
Signature status: No Signature

Known Samples

MD5: 4c682d82940d3a31b8c8eb00c81f3a9e
SHA1: 535a7565c0107a08093945599b4a89fd8e46e8e0
SHA256: BC18012194F4EB06D3217D25C524F1B99A34590F40B4E3A8F5FA84822D2DE022
File Size: 48.64 KB, 48640 bytes
MD5: ffaf989b3f60ee6dfea834c0fdbc5e87
SHA1: 292de020a3dad1c6fad991bb541202e0e6114135
SHA256: FBBA9E5859C643AE662DF0A40C8D341B1BFE5086984849ECBD405DC00F1123A2
File Size: 43.01 KB, 43008 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
Company Name System.Spy.Lib
File Description System.Spy.Lib
File Version 1.0.0.0
Internal Name System.Spy.Lib.dll
Original Filename System.Spy.Lib.dll
Product Name System.Spy.Lib
Product Version 1.0.0

File Traits

  • .NET
  • dll
  • ntdll
  • x86

Block Information

Total Blocks: 91
Potentially Malicious Blocks: 42
Whitelisted Blocks: 49
Unknown Blocks: 0

Visual Map

x 0 x 0 x 0 0 0 0 0 0 x x 0 x 0 x 0 x 0 0 0 0 x x x 0 x 0 0 0 x 0 x 0 0 0 0 x 0 x 0 x 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 x x 0 0 0 x 0 x 0 x 0 x 0 0 x 0 x x x x x x x x x x x x x 0 x x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Spy.Agent.GFB

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
Show More
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Trending

Most Viewed

Loading...