Trojan.Rootkit.Agent.XC
Trojan.Rootkit.Agent.XC is a detection name used to identify a malicious program that falls into the rootkit category of threats. Rootkits are a particularly dangerous class of malware because they are designed to hide their presence and the presence of other malicious components on an infected computer. When a threat is detected under this name, it typically indicates that a program is attempting to gain unauthorized, hidden access to a system while avoiding detection by security tools and the user alike.
Because specific technical details about this particular detection are not available, the following description is based on the typical behavior of rootkit-family threats in general, which this detection is associated with.
Table of Contents
What This Threat Does
Like other members of the rootkit category, Trojan.Rootkit.Agent.XC is typically designed to embed itself deeply within an operating system so that it can operate with elevated privileges while remaining concealed from the user. Rootkits commonly modify or intercept system processes, hide files, folders, running processes, or registry entries associated with themselves, and can disable or interfere with security software to avoid removal. Many rootkits act as a foundation for other malware, allowing attackers to install additional threats such as spyware, ransomware, or backdoors without the user's knowledge. Some rootkits are also used to give remote attackers persistent, unauthorized control over the infected machine.
How It Usually Gets onto Computers
Rootkit-type infections typically spread through common malware distribution methods. These include bundled downloads from untrustworthy or pirated software sources, malicious email attachments or links, fake software updates, cracked applications, and exploit kits that take advantage of unpatched security vulnerabilities in the operating system or installed programs. In many cases, users unknowingly install rootkits themselves by downloading free software from unreliable websites or by clicking on deceptive advertisements and pop-ups.
Risks for the User
Because rootkits are built to operate stealthily, infections like this one can pose serious risks. Attackers may use the hidden access to steal sensitive personal or financial information, log keystrokes, capture screenshots, or monitor online activity. The compromised system may also be used as a launching point for further attacks, such as distributing spam, participating in botnets, or downloading additional malicious payloads. Because rootkits actively work to avoid detection, infections can persist for long periods without the user noticing any obvious problems, increasing the potential damage over time.
Signs of Infection
Rootkit infections are, by design, difficult to detect through normal observation. However, users may notice general warning signs typical of rootkit activity, such as unusual system slowdowns, unexpected crashes or freezes, security software that stops working properly or fails to update, changes to system settings that were not made by the user, and unusual network activity that could indicate unauthorized communication with remote servers. In some cases, there may be no visible symptoms at all, which is part of what makes this category of threat so dangerous.
How to Stay Protected
To reduce the risk of rootkit infections, users should keep their operating system and all installed software up to date, since attackers often exploit unpatched vulnerabilities. Avoid downloading software from unofficial or untrustworthy sources, and be cautious with email attachments and links from unknown senders. Using reputable, up-to-date security software and performing regular system scans can help detect and prevent rootkit infections before they take hold. Because rootkits are designed to be hard to remove once installed, prevention through safe browsing habits and cautious downloading is one of the most effective defenses available to regular computer users.
Analysis Report
General information
| Family Name: | Trojan.Rootkit.Agent.XC |
|---|---|
| Signature status: | No Signature |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
e80503abeed95309ab805f06de28491c
SHA1:
968c8a8b0d475654c905dcfeb4ba611e39891a79
SHA256:
336300B3AE0EB565AD0A96E7ED018CBA3C4E45C4BA42F0498E1179221DE651B6
File Size:
1.53 MB, 1525248 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have exports table
- File doesn't have security information
- File has TLS information
- File is 64-bit executable
- File is either console or GUI application
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is Native application (NOT .NET application)
- File is not packed
- IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
File Icons
File Icons
This section displays icon resources found within family samples. Malware often replicates icons commonly associated with legitimate software to mislead users into believing the malware is safe.Windows PE Version Information
Windows PE Version Information
This section displays values and attributes that have been set in the Windows file version information data structure for samples within this family. To mislead users, malware actors often add fake version information mimicking legitimate software.| Name | Value |
|---|---|
| Company Name | GBTGAME |
| File Description | GBTGAME Launcher v3.0.10 |
| File Version | 3.0.10.0 |
| Internal Name | GBTGAME-Launcher-v3 |
| Legal Copyright | GBTGAME.ME |
| Original Filename | GBTGAME-Launcher-v3.exe |
| Product Name | GBTGAME Launcher v3.0.10 |
| Product Version | 3.0.10.0 |
File Traits
- 2+ executable sections
- No Version Info
- x64
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 1,773 |
|---|---|
| Potentially Malicious Blocks: | 18 |
| Whitelisted Blocks: | 1,458 |
| Unknown Blocks: | 297 |
Visual Map
? - Unknown Block
x - Potentially Malicious Block
Files Modified
Files Modified
This section lists files that were created, modified, moved and/or deleted by samples in this family. File system activity can provide valuable insight into how malware functions on the operating system.| File | Attributes |
|---|---|
| \device\namedpipe | Generic Read,Write Attributes |
| \device\namedpipe | Generic Write,Read Attributes |
| \device\namedpipe\gmdasllogger | Generic Write,Read Attributes |
| \device\namedpipe\local\mojo.5304.9080.10448436914773022828 | Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288 |
| c:\users\user\appdata\local\temp\gbt_ui_trace_5304.log | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\gbt_ui_trace_5304.log | Generic Write,Read Attributes |
| c:\users\user\downloads\.gbtgame-v3-runtime\launcher.log | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\downloads\.gbtgame-v3-runtime\launcher.log | Generic Write,Read Attributes |
Registry Modifications
Registry Modifications
This section lists registry keys and values that were created, modified and/or deleted by samples in this family. Windows Registry activity can provide valuable insight into malware functionality. Additionally, malware often creates registry values to allow itself to automatically start and indefinitely persist after an initial infection has compromised the system.| Key::Value | Data | API Name |
|---|---|---|
| HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe | 춀ꛤ䳡ǝ | RegNtPreCreateKey |
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API usage analysis is a valuable tool that can help identify malicious activity, such as keylogging, security privilege escalation, data encryption, data exfiltration, interference with antivirus software, and network request manipulation.| Category | API |
|---|---|
| Syscall Use |
Show More
|
| Other Suspicious |
|
| Anti Debug |
|
| Network Winhttp |
|
| Process Manipulation Evasion |
|
| Process Shell Execute |
|
| User Data Access |
|
| Process Terminate |
|
Shell Command Execution
Shell Command Execution
This section lists Windows shell commands that are run by the samples in this family. Windows Shell commands are often leveraged by malware for nefarious purposes and can be used to elevate security privileges, download and launch other malware, exploit vulnerabilities, collect and exfiltrate data, and hide malicious activity.
C:\Windows\System32\manage-bde.exe "C:\Windows\System32\manage-bde.exe" -status
|