威胁数据库 特洛伊木马 Trojan.PSW.Agent.AA

Trojan.PSW.Agent.AA

Trojan.PSW.Agent.AA是一种木马型威胁,属于 PSW(密码窃取软件)家族。与该家族的大多数威胁一样,其主要目的是从受感染的计算机中秘密窃取敏感信息,特别是存储的凭据,并将这些数据发送给远程攻击者。由于关于此特定变种的详细技术数据有限,以下信息描述了密码窃取木马的典型行为,预计此威胁也将具有这些行为。

这种威胁会造成什么影响?

PSW.Agent 系列木马通常设计为在用户不知情的情况下静默运行于后台。它们通常会扫描系统,查找已保存的密码、登录凭据、浏览器存储的数据以及其他敏感信息,例如自动填充条目或缓存的帐户详细信息。一旦收集到这些数据,它们通常会被传输到网络犯罪分子控制的远程服务器,然后网络犯罪分子可以利用这些数据进行身份盗窃、金融诈骗或未经授权访问受害者的在线帐户。此类木马的某些变种可能还具有其他功能,例如下载更多恶意组件、修改系统设置或允许远程攻击者控制受感染计算机的部分功能。

它通常是如何进入电脑的

此类木马通常通过欺骗手段传播,而非直接利用系统漏洞。常见的感染方式包括:伪装成合法文档或发票的恶意电子邮件附件、来自不可信网站的捆绑下载、虚假软件更新、破解或盗版软件,以及通过钓鱼邮件或被入侵网站传播的链接。用户往往会被诱骗手动执行恶意文件,误以为它是无害或有用的程序。

用户面临的风险

密码窃取木马的存在对个人和财务安全构成严重威胁。如果电子邮件、银行、社交媒体或其他在线服务的登录凭证被窃取,攻击者即可访问这些账户,导致经济损失、身份盗窃,甚至进一步入侵其他关联账户。在某些情况下,被盗数据还可能被用于对受害者的联系人或雇主发起进一步攻击,尤其是在工作相关的凭证泄露的情况下。

感染迹象

窃取密码的木马程序通常设计成难以检测,因此可能几乎没有或根本没有明显的症状。但是,用户应该注意与此类恶意软件相关的常见警告信号,例如系统运行速度异常变慢、网络活动异常、后台运行着陌生的进程、浏览器设置被更改,或者在线帐户出现未经授权的登录和活动。安全软件发出的关于可疑文件或行为的警报也应引起重视。

如何做好防护

为了降低感染此类木马病毒的风险,用户应避免打开来自未知或意外发件人的电子邮件附件或点击链接,不要从非官方或盗版来源下载软件,并保持操作系统和已安装应用程序的更新。为不同的账户使用强密码且密码各不相同,并在条件允许的情况下启用多因素身份验证,也能在凭证被盗时最大限度地减少损失。定期使用信誉良好的安全软件扫描系统并备份重要数据,也是有助于最大限度降低此类威胁影响的有效措施。

分析报告

一般信息

姓: Trojan.PSW.Agent.AA
签名状态: No Signature

已知样本

MD5: c91ff68d17e69c4408a5bf5a35ba3801
SHA1: 0f06a52939fffba54c9eaaa088a966464c344131
SHA256: 0CB6B6F151CD1D69FE0122E9AC242794FA5DD229BBA3F04DD6B1380326BA0260
文件大小: 157.18 KB,157184字节

Windows 可移植可执行文件属性

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

文件特征

  • CryptUnprotectData
  • dll
  • x64

区块信息

总区块数: 549
潜在恶意块: 14
白名单区块: 528
未知区块: 7

可视化地图

0 x x x x x 0 x x 0 0 x ? x x x 0 0 x ? x x 0 2 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 1 0 0 0 0 ? 0 ? 1 ? 0 1 1 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1
0 - 可能的保险箱
? - 未知区块
x - 潜在恶意拦截

Windows API 使用情况

类别 API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
显示更多
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN