Threat Database Trojans Trojan.Win32.Agent.hwoo


By JubileeX in Trojans

Threat Scorecard

Ranking: 14,397
Threat Level: 10 % (Normal)
Infected Computers: 540
First Seen: March 15, 2013
Last Seen: September 18, 2023
OS(es) Affected: Windows

Trojan.Win32.Agent.hwoo is a backdoor Trojan that is downloaded and installed on the corrupted PC by other security threats. Trojan.Win32.Agent.hwoo connects to its C&C (Command and Control) server and requests further data using HTTP GET requests. The response from the server is expected to be a rather encrypted DLL, which is then loaded and called 'InfectFile' and 'GetWorkType'. For all the servers, Trojan.Win32.Agent.hwoo makes a request to '/news/show.asp', using a custom agent string of 'Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)'. All the URLS refer to the same IP address. The server is placed in China, in Shandong province. The web addresses '' and '' appear to have been registered by the same person, although with very small differences in the registration data.

File System Details

Trojan.Win32.Agent.hwoo may create the following file(s):
# File Name Detections
1. InfectFile.dll
2. clbcatq.dll
3. C:\Documents and Settings\\Local Settings\Temp\AcroRd32.exe
4. GetWorkType.dll


Trojan.Win32.Agent.hwoo may call the following URLs:


Most Viewed
