威胁数据库 特洛伊木马 Trojan.MSIL.Agent.GDSK

Trojan.MSIL.Agent.GDSK

通过CagedTech在 特洛伊木马
发布时间:
最后更新:

威胁评分卡

人气排名: 24,641
威胁级别: 80 % (高的)
受感染的计算机: 2
初见: June 28, 2025
最后一次露面: September 25, 2026
受影响的操作系统: Windows

Trojan.MSIL.Agent.GDSK是一种针对运行 Windows 操作系统的计算机的木马程序。与此类威胁中的大多数一样,它使用 Microsoft 中间语言 (MSIL) 构建,这意味着它是为 .NET 框架编译的,这使其轻量级、适应性强,并且能够被其创建者快速修改。此威胁已被标记为高风险感染,遇到此威胁的计算机用户应认真对待检测结果,并迅速采取措施将其清除。

Trojan.MSIL.Agent.GDSK 的作用

Trojan.MSIL.Agent.GDSK 一旦在系统中激活,通常会在后台静默安装,不会向用户显示任何明显的迹象。此类木马程序通常旨在使攻击者获得对受感染计算机的某种程度的未经授权的访问或控制权。根据操作者的配置方式,此类威胁可能被用于收集计算机上存储的信息、监视用户活动、下载并安装其他恶意组件,或未经许可修改系统设置。由于木马程序很少只执行单一操作,因此受感染的计算机可能会同时出现上述多种行为,而用户通常不会察觉到任何异常。

它通常是如何进入电脑的

这类木马程序通常通过欺骗手段传播,而不是像病毒或蠕虫那样通过自我复制。最常见的感染方式是将电子邮件附件伪装成合法文件,例如文档、图像或可执行程序。用户也可能通过从不可信的网站下载软件、点击恶意链接或安装捆绑软件(这些软件可能暗藏木马程序)而感染此类病毒。由于木马程序使用的文件扩展名和图标通常伪装成无害文件,用户很容易在不知不觉中打开它们。

用户面临的风险

系统中存在 Trojan.MSIL.Agent.GDSK 会带来严重风险。此类木马通常会获得对受感染计算机的高级控制权,从而导致密码被盗、个人或财务数据泄露、文件被删除或损坏,以及系统配置被未经授权更改。在某些情况下,该恶意软件还可能被用作进一步攻击的跳板,使网络犯罪分子能够安装其他恶意程序,或将受感染的计算机纳入更大的受感染设备网络。

感染迹象

由于木马程序旨在隐蔽运行,因此感染迹象并不总是显而易见。但是,用户可能会注意到系统运行速度异常变慢、意外崩溃、后台运行着陌生的进程、浏览器或系统设置被用户擅自更改,或者出现异常的网络活动。安全软件发出警报并标记可疑文件通常是系统已被入侵的最明显迹象。

如何做好防护

为降低感染风险,用户应避免打开来自未知或意外发件人的电子邮件附件或点击链接,仅从官方和可信来源下载软件,并及时更新操作系统和应用程序,安装最新的安全补丁。定期备份重要文件、谨慎下载以及使用信誉良好的安全工具扫描系统,也有助于在 Trojan.MSIL.Agent.GDSK 等威胁造成严重损害之前将其检测并清除。

分析报告

一般信息

姓: Trojan.MSIL.Agent.GDSK
签名状态: No Signature

已知样本

MD5: 0815539e99c6af573e16cbc0ff402342
SHA1: 7917994c52fb898e865e1f93b64c67e350fe47e8
SHA256: 068008C26DD532A06E14394EC3A31917906C797582CA9D7C7BEDF41A12740B09
文件大小: 1.63 MB,1633280字节

Windows 可移植可执行文件属性

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
显示更多
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE 版本信息

姓名 价值
Assembly Version 1.0.0.0
File Description Pastime
File Version 1.0.0.0
Internal Name Pastime.dll
Legal Copyright Copyright © 2022
Original Filename Pastime.dll
Product Name Pastime
Product Version 1.0.0.0

文件特征

  • .NET
  • dll
  • NewLateBinding
  • RijndaelManaged
  • x86

区块信息

总区块数: 46
潜在恶意块: 2
白名单区块: 44
未知区块: 0

可视化地图

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0
0 - 可能的保险箱
? - 未知区块
x - 潜在恶意拦截

相似家庭

  • Occamy.B

Windows API 使用情况

类别 API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
显示更多
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN