威胁数据库 特洛伊木马 Trojan.Agent.Gen.FMT

Trojan.Agent.Gen.FMT

Trojan.Agent.Gen.FMT是一个通用的检测名称,用于识别木马威胁。由于它是“通用”检测名称,因此通常涵盖一系列具有相似代码模式或行为的恶意文件,而不是针对单个特定的恶意软件。关于此特定变种的详细技术细节,例如其确切来源、开发者或发现日期,并未公开记录,但其被归类为木马意味着它旨在悄无声息地在受感染的系统中运行,并在未经用户同意的情况下执行有害操作。

这种威胁会造成什么影响?

与大多数木马类威胁一样,Trojan.Agent.Gen.FMT 旨在伪装成合法或无害的文件,以欺骗用户和安全工具。一旦在系统中激活,此类木马通常会尝试执行以下操作:

  • 在受感染的设备上下载并安装其他恶意文件或有效载荷。
  • 修改系统设置或配置文件以保持持久性并避免被删除。
  • 收集敏感信息,例如登录凭证、浏览习惯或系统详细信息,并将其发送到攻击者控制的远程服务器。
  • 打开后门,使网络犯罪分子能够远程访问或控制被入侵的计算机。
  • 禁用或干扰安全软件以避免被检测和移除。

由于通用木马检测可以代表多种变体,因此这些行为的具体组合可能因受感染的机器而异。

它通常如何传播

此类木马通常通过常见的感染方式入侵计算机,包括:

  • 恶意电子邮件附件或链接伪装成发票、收据或其他看似重要的文件。
  • 从不可信的网站下载的虚假软件更新或破解/盗版软件。
  • 捆绑安装程序中除了看似合法的免费程序外,还包含不需要的或恶意组件。
  • 被入侵或恶意访问的网站会触发恶意下载。
  • 受感染的移动存储设备,例如U盘。

用户面临的风险

Trojan.Agent.Gen.FMT 等恶意软件感染会危及个人数据和系统稳定性。潜在后果包括身份盗窃、因银行或账户凭证被盗而造成的经济损失、其他恶意软件感染、系统性能下降以及未经授权的远程访问设备。在某些情况下,受感染的系统还可能在用户不知情的情况下,成为用于进一步恶意活动的更大网络的一部分。

感染迹象

用户应注意木马病毒感染的常见警告信号,例如:

  • 意外的运行速度下降或崩溃。
  • 后台运行着不熟悉的程序或进程。
  • 网络活动或数据使用量无故增加。
  • 安全软件被禁用或无法更新。
  • 异常弹出窗口、重定向或浏览器设置更改。

如何做好防护

为降低感染风险,用户应保持操作系统和所有软件更新,避免从未知或不可信来源下载程序或附件,谨慎对待电子邮件中的链接和附件,并定期备份重要文件。使用信誉良好的安全软件并定期进行系统扫描也有助于在 Trojan.Agent.Gen.FMT 等威胁造成重大损害之前将其检测并清除。

分析报告

一般信息

姓: Trojan.Agent.Gen.FMT
签名状态: No Signature

已知样本

MD5: e5a01504f0e286736111ffe685ce5965
SHA1: 5c5d912a501ede6da3ffd3dedb5a88564a6572b0
SHA256: 3972463DD46BE677E12F76B58A8C00FD5C00856522442360A1C91A6EE7A52C7D
文件大小: 158.72 KB,158720字节

Windows 可移植可执行文件属性

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

文件特征

  • fptable
  • No Version Info
  • x64

区块信息

总区块数: 548
潜在恶意块: 25
白名单区块: 521
未知区块: 2

可视化地图

0 0 0 0 0 0 ? x x x x x x x x x x x x x x x x x x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 2 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 x
0 - 可能的保险箱
? - 未知区块
x - 潜在恶意拦截

相似家庭

  • Kryptik.BGT
  • Trojan.Kryptik.Gen.KBQ
  • Trojan.Kryptik.Gen.KFZ

文件已修改

文件 属性
\device\namedpipe\gmdasllogger Generic Write,Read Attributes

Windows API 使用情况

类别 API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateToken
显示更多
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation