Threat Database Trojans Win32/Agent.SFM

Win32/Agent.SFM

By GoldSparrow in Trojans

Threat Scorecard

Popularity Rank: 11,695
Threat Level: 100 % (High)
Infected Computers: 1,415
First Seen: August 31, 2012
Last Seen: November 27, 2025
OS(es) Affected: Windows

Win32/Agent.SFM is a Trojan that targets credentials used to log into websites designed by cybercriminals. Win32/Agent.SFM does not send a lot of information on recent activities on the compromised machine, but is picky in transferring the gathered data. While being run, Win32/Agent.SFM drops and executes infected files on the corrupted PC from a remote server and/or the web. Win32/Agent.SFM also modifies the Windows Registry by creating Registry entries. Win32/Agent.SFM collects confidential information and various data linked to the infected computer system.

SpyHunter Detects & Remove Win32/Agent.SFM

File System Details

Win32/Agent.SFM may create the following file(s):
# File Name MD5 Detections
1. %RANDOM CHARACTERS1%.dll
2. %Temp%\­flash_player_update.exe
3. %Commonappdata%\­ur
4. %Commonappdata%\­ur%RANDOM CHARACTERS2%
5. %CommonAppData%\­cf
6. file.dll 4799e330f3bf548d48f691935628fdd9 0
7. file.exe 380ed56089198a1c5d53e237a0306bdb 0
More files

Registry Details

Win32/Agent.SFM may create the following registry entry or registry entries:
[HKEY_LOCAL_MACHINE\­SOFTWARE\­Microsoft\­Windows NT\­CurrentVersion\­Windows]

Analysis Report

General information

Family Name: Phobos.B Ransomware
Signature status: No Signature

Known Samples

MD5: 6782f4eea3be727a01ba115011e20012
SHA1: bceb8404e062954db8ce3d76ce889c17e0f52b76
SHA256: 567AC1BD56DEEA1C240366A9EE08255DA8B8FDDEB7CFBCA713B4064A67C72202
File Size: 50.69 KB, 50688 bytes
MD5: f04690482fdfc6353d8568b83f0773f2
SHA1: f418f866abba36a63ca42c0c7dd108bac19e7f60
SHA256: F33A3DBD989525C0DD02A29D2E98531476F7F3B8BCFCB13DEE959358EC890519
File Size: 50.18 KB, 50176 bytes
MD5: c386ccbd1b8b92646cf48797034ec15c
SHA1: e04204ef7eb6809b5676111bdca3bf5896d34b16
SHA256: 696090BB23B39AD905E9DED07D075EF145DCBBA1388700DF7FE432E815F20855
File Size: 50.18 KB, 50176 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • HighEntropy
  • nosig nsis
  • No Version Info
  • x86

Block Information

Total Blocks: 162
Potentially Malicious Blocks: 121
Whitelisted Blocks: 26
Unknown Blocks: 15

Visual Map

x x x 0 0 x x x 0 x x x x x 0 0 x x x x x x x x x x x x x x 0 0 x x x x ? x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x ? x x x 0 x 0 x x x 0 x x 0 x 0 0 0 x x 0 ? ? ? ? 0 x x x x x x x x x x x x x 0 x x 0 0 0 x 0 x x x ? x x ? ? x x x x x x ? ? ? ? ? x x x x x 0 x x x x x x x x x x x x x x x x ? 2 0 1 1
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Phobos.B

Windows API Usage

Category API
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
User Data Access
  • GetComputerName

Trending

Most Viewed

Loading...