Threat Database Trojans Trojan.MSIL.Spy.Agent.GGA

Trojan.MSIL.Spy.Agent.GGA

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 4,350
First Seen: December 5, 2022
Last Seen: March 29, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Spy.Agent.GGA indicates that your system has been compromised by a potentially malicious program. This type of threat is designed to secretly gather sensitive information from your computer, which can then be used for nefarious purposes. It's essential to take immediate action to remove this threat and prevent further damage.

What Is Trojan.MSIL.Spy.Agent.GGA?

Trojan.MSIL.Spy.Agent.GGA is a type of spyware that can infect your system and steal sensitive information, such as login credentials, credit card numbers, and personal data. The name "Trojan" refers to the fact that this malware disguises itself as a legitimate program, allowing it to bypass security measures and infiltrate your system. The "MSIL" part of the name suggests that the malware is written in Microsoft Intermediate Language, which is a programming language used by the .NET Framework.

How Trojan.MSIL.Spy.Agent.GGA Operates

Once Trojan.MSIL.Spy.Agent.GGA has infected your system, it can operate in various ways to gather sensitive information. It may install keyloggers to record your keystrokes, capture screenshots, or even turn on your webcam and microphone to spy on you. This malware can also communicate with its command and control servers to transmit stolen data and receive updates or instructions. Additionally, it may attempt to disable security software or exploit vulnerabilities in your system to maintain its presence and continue its malicious activities.

Symptoms of Infection

If your system is infected with Trojan.MSIL.Spy.Agent.GGA, you may notice some suspicious activity. Your computer may slow down or become unresponsive, and you may see unfamiliar programs or icons on your desktop. You may also receive unexpected pop-ups or alerts, or notice that your browser is being redirected to strange websites. In some cases, you may not notice any symptoms at all, which is why it's essential to regularly scan your system for malware and keep your security software up to date.

How to Remove Trojan.MSIL.Spy.Agent.GGA

  1. Restart your computer in Safe Mode with Networking to prevent the malware from loading and to allow you to download and install removal tools.
  2. Download and install a reputable anti-malware tool, such as SpyHunter, and perform a full scan of your system to detect and remove the malware.
  3. Uninstall any suspicious programs or applications that you don't recognize or that were installed without your knowledge.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your computer and perform another scan with your anti-malware tool to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.MSIL.Spy.Agent.GGA from your system requires careful attention to detail and a thorough understanding of the malware's behavior. By following the steps outlined above and taking proactive measures to protect your system, you can help prevent future infections and keep your sensitive information safe. Remember to always keep your security software up to date, use strong passwords, and be cautious when downloading and installing programs from the internet. By staying vigilant and taking the necessary precautions, you can reduce the risk of malware infections and maintain the security and integrity of your system.

Analysis Report

General information

Family Name: Trojan.MSIL.Spy.Agent.GGA
Signature status: No Signature

Known Samples

MD5: f35bdabbafaf0cb6c3b5fc47cfdb0e52
SHA1: e37294967be60437c9e31bc3e66a31a6f0e13a62
SHA256: 9F6C7F4DBCBF9E55B979DB02814B1C69A73D5E543F9D1B855E3DBBCCFE568583
File Size: 1.57 MB, 1570304 bytes
MD5: be3a92ea85e1df043238dc7412ce0f20
SHA1: 25cd03ec54f25c977d756e0117fb2fcb29fdf7eb
SHA256: 8D8BDEDA202B3BDB0427B8669B978B83D707D9E2C41A7126F458506C2FB0DEAF
File Size: 126.46 KB, 126464 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
File Description
  • DestinyClient
  • Stealerium
File Version 1.0.0.0
Internal Name
  • DestinyClient.exe
  • stub.exe
Legal Copyright
  • Copyright © 2024
  • Copyright © https://github.com/kgnfth 2022
Original Filename
  • DestinyClient.exe
  • stub.exe
Product Name
  • DestinyClient
  • Stealerium
Product Version 1.0.0.0

File Traits

  • .NET
  • Agile.net
  • CryptUnprotectData
  • Fody
  • HighEntropy
  • No CryptProtectData
  • RijndaelManaged
  • Run
  • x86

Block Information

Total Blocks: 269
Potentially Malicious Blocks: 84
Whitelisted Blocks: 92
Unknown Blocks: 93

Visual Map

x 0 x x x ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? x x x ? x ? x x x x ? ? ? x x 0 x x 0 x x x ? x x x x x x x x x 0 0 0 0 0 x ? 0 0 0 x 0 0 x 0 0 ? 0 0 0 x x 0 x x x x x x 0 x x x ? x x ? x ? x x x x 0 x x x x ? x x x x ? x x ? ? ? x 0 x ? 0 ? ? x x x x ? x ? ? x ? 0 ? x ? ? ? ? ? 0 x ? ? ? ? ? 0 0 ? 0 0 0 0 0 0 ? ? 0 x x ? 0 ? 0 ? ? 0 0 ? 0 ? 0 x ? 0 ? 0 0 x ? 0 ? 0 x x x x ? x 0 ? ? 0 ? ? ? ? ? x ? ? x x ? ? ? ? x ? 0 0 x 0 ? 0 ? 0 ? ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? ? x 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Registry Modifications

Key::Value Data API Name
HKLM\software\wow6432node\microsoft\tracing::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enablefiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enableautofiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::maxfilesize  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::filedirectory %windir%\tracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enablefiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enableautofiletracing RegNtPreCreateKey
Show More
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::maxfilesize  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::filedirectory %windir%\tracing RegNtPreCreateKey

Windows API Usage

Category API
User Data Access
  • GetComputerName
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
Other Suspicious
  • AdjustTokenPrivileges
Network Winsock2
  • WSAConnect
  • WSASocket
  • WSAStartup
  • WSAttemptAutodialName
Network Winsock
  • closesocket
  • freeaddrinfo
  • getaddrinfo
  • recv
  • send
  • setsockopt
Network Winhttp
  • WinHttpOpen
Network Info Queried
  • GetAdaptersAddresses
  • GetNetworkParams

Related Posts

Trending

Most Viewed

Loading...