Trojan.PSW.Agent.AA
Trojan.PSW.Agent.AA is a Trojan-type threat belonging to the PSW (Password Stealing Ware) family. As with most threats classified under this family name, its primary purpose is to covertly harvest sensitive information from an infected computer, particularly stored credentials, and send that data to a remote attacker. Because detailed technical data about this specific variant is limited, the information below describes the typical behavior of password-stealing Trojans in general, which this threat is expected to share.
Table of Contents
What This Threat Does
Trojans in the PSW.Agent family are typically designed to run silently in the background without the user's knowledge. They commonly scan the system for saved passwords, login credentials, browser-stored data, and other sensitive information such as autofill entries or cached account details. Once collected, this data is usually transmitted to a remote server controlled by cybercriminals, who can then use it for identity theft, financial fraud, or to gain unauthorized access to the victim's online accounts. Some variants in this category may also have additional capabilities, such as downloading further malicious components, modifying system settings, or allowing remote attackers to control parts of the infected machine.
How It Usually Gets Onto Computers
Trojans of this type typically spread through deceptive means rather than exploiting system vulnerabilities directly. Common infection methods for this category of malware include malicious email attachments disguised as legitimate documents or invoices, bundled downloads from untrustworthy websites, fake software updates, cracked or pirated software, and links shared through phishing messages or compromised websites. Users are often tricked into manually executing the malicious file, believing it to be something harmless or useful.
Risks for the User
The presence of a password-stealing Trojan poses a serious risk to personal and financial security. If login credentials for email, banking, social media, or other online services are captured, attackers may gain access to those accounts, leading to financial loss, identity theft, or further compromise of other linked accounts. In some cases, stolen data can also be used to launch additional attacks against the victim's contacts or employer, especially if work-related credentials are exposed.
Signs of Infection
Password-stealing Trojans are typically built to avoid detection, so visible symptoms may be minimal or absent. However, users should watch for warning signs commonly associated with this category of malware, such as unusual system slowdowns, unexpected network activity, unfamiliar processes running in the background, changes to browser settings, or unauthorized logins and activity on online accounts. Security software alerts flagging suspicious files or behavior should also be taken seriously.
How to Stay Protected
To reduce the risk of infection from this and similar Trojans, users should avoid opening email attachments or clicking links from unknown or unexpected senders, refrain from downloading software from unofficial or pirated sources, and keep their operating system and installed applications up to date. Using strong, unique passwords for different accounts and enabling multi-factor authentication where possible can also limit the damage if credentials are ever stolen. Regularly scanning the system with reputable security software and maintaining backups of important data are additional practical steps that help minimize the impact of this type of threat.
Analysis Report
General information
| Family Name: | Trojan.PSW.Agent.AA |
|---|---|
| Signature status: | No Signature |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
c91ff68d17e69c4408a5bf5a35ba3801
SHA1:
0f06a52939fffba54c9eaaa088a966464c344131
SHA256:
0CB6B6F151CD1D69FE0122E9AC242794FA5DD229BBA3F04DD6B1380326BA0260
File Size:
157.18 KB, 157184 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have exports table
- File doesn't have security information
- File is 64-bit executable
- File is either console or GUI application
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is Native application (NOT .NET application)
- File is not packed
- IMAGE_FILE_DLL is not set inside PE header (Executable)
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
File Traits
- CryptUnprotectData
- dll
- x64
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 549 |
|---|---|
| Potentially Malicious Blocks: | 14 |
| Whitelisted Blocks: | 528 |
| Unknown Blocks: | 7 |
Visual Map
? - Unknown Block
x - Potentially Malicious Block
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API usage analysis is a valuable tool that can help identify malicious activity, such as keylogging, security privilege escalation, data encryption, data exfiltration, interference with antivirus software, and network request manipulation.| Category | API |
|---|---|
| Syscall Use |
Show More
|