Threat Database Hacktool Hacktool.Agent.ZG

Hacktool.Agent.ZG

By CagedTech in Hacktool

Threat Scorecard

Popularity Rank: 18,347
Threat Level: 50 % (Medium)
Infected Computers: 88
First Seen: September 15, 2021
Last Seen: June 15, 2026
OS(es) Affected: Windows

The detection of Hacktool.Agent.ZG on your system indicates a potential security threat that requires immediate attention. This detection name suggests that the malware is a type of hacktool, which is a category of malicious software designed to compromise the security of a computer system or network. Hacktools are often used to gain unauthorized access, steal sensitive information, or disrupt system operations.

What Is Hacktool.Agent.ZG?

Hacktool.Agent.ZG is a type of malware that falls under the broader category of hacktools. While the specific details of this threat are not available, hacktools in general are designed to exploit vulnerabilities in software or hardware to achieve malicious goals. They can be used for a variety of purposes, including password cracking, network scanning, and remote access. The presence of a hacktool on a system can indicate a significant security risk, as it may allow attackers to bypass security measures and gain control over the system or steal sensitive data.

How Hacktool.Agent.ZG Operates

Malware like Hacktool.Agent.ZG typically operates by exploiting weaknesses in system security or user behavior. This can include taking advantage of unpatched vulnerabilities in software, using social engineering tactics to trick users into installing the malware, or exploiting poor security practices such as weak passwords. Once installed, the malware can operate in various ways, including running in the background to avoid detection, communicating with command and control servers to receive instructions, and executing tasks designed to compromise system security or steal data.

Symptoms of Infection

The symptoms of an infection can vary widely depending on the specific goals and design of the malware. Common indications of a malware infection include unexpected changes in system behavior, such as sudden slowdowns, appearance of unfamiliar programs or icons, and unusual network activity. Users may also notice that their system is behaving erratically, such as crashing frequently, or that they are being redirected to unwanted websites. In some cases, there may be no noticeable symptoms at all, as the malware is designed to operate stealthily.

How to Remove Hacktool.Agent.ZG

  1. Boot your computer in Safe Mode with Networking to limit the malware's ability to interfere with the removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. This can help identify and remove all components of the malware.
  3. Uninstall any suspicious programs that were installed around the time of the infection. Be cautious and only remove programs that you are certain are malicious or unnecessary.
  4. Reset your web browsers (Chrome, Firefox, Edge) to their default settings to remove any malicious extensions or settings that the malware may have installed.
  5. Reboot your computer and perform another scan with your anti-malware tool to ensure that all components of the malware have been removed.

Conclusion

The removal of Hacktool.Agent.ZG requires careful and thorough action to ensure that all components of the malware are eliminated from the system. By following the steps outlined above and maintaining good security practices, such as keeping software up to date, using strong and unique passwords, and being cautious when clicking on links or installing software, you can significantly reduce the risk of future infections. Remember, the key to protecting your system and data is vigilance and proactive security measures.

Analysis Report

General information

Family Name: Hacktool.Agent.ZG
Signature status: No Signature

Known Samples

MD5: b38666d729ed51b195baaf02dcdc69d0
SHA1: 2042aeec1cab131ab5075172f0055bbb23963d51
SHA256: 2218E813F8484187633B5339507F0FB2362A5A0B348641BFA3B7A87F4D24DE7C
File Size: 401.92 KB, 401920 bytes
MD5: ea570fd73ec30d733f3ffa3051fd6435
SHA1: 0643b167fa951a21a13b6e2cf11cbd9e83f9453c
SHA256: C58FA4870E2A77DDF89AB4E72923484D3B0FE8BB556ED2DC15E7D16F0AA49088
File Size: 80.90 KB, 80896 bytes
MD5: 86ba33230845a99bcf443bb4c204f40e
SHA1: 66c35856eb2b50f4f282a47ca31b4fcc8ff27aec
SHA256: DCFC70A1C595743A7C3856A54A4193B5D30080DD661DBFFF92F32CE38A141759
File Size: 102.40 KB, 102400 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • No Version Info
  • packed
  • x86

Block Information

Total Blocks: 503
Potentially Malicious Blocks: 73
Whitelisted Blocks: 408
Unknown Blocks: 22

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x x 0 0 ? 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 x x x x x x x 0 x ? x x x x 0 0 0 0 0 0 x x x x x x x ? x 0 x x x 0 0 0 x x x x x 0 x 0 x x 0 0 x x x x x x x x x 0 0 x 0 0 ? 0 ? ? 0 0 x 0 x 0 x x ? x x ? 0 x 0 0 0 0 0 x 0 0 ? 0 x 0 0 0 x x 0 0 0 ? 0 x 0 ? 0 x 0 0 0 0 x 0 ? 0 x 0 0 ? 0 ? x x 0 0 ? ? 0 0 ? ? ? 0 0 ? 0 0 ? 0 0 x x 0 ? 0 0 x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Kryptik.KLE

Files Modified

File Attributes
\device\namedpipe Generic Read,Write Attributes
\device\namedpipe Generic Write,Read Attributes
c:\windowsnt Synchronize,Write Attributes
c:\windowsnt\services Synchronize,Write Attributes

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Process Shell Execute
  • CreateProcess
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
Show More
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • win32u.dll!NtGdiAnyLinkedFonts
  • win32u.dll!NtGdiBitBlt
  • win32u.dll!NtGdiCreateBitmap
  • win32u.dll!NtGdiCreateCompatibleBitmap
  • win32u.dll!NtGdiCreateCompatibleDC
  • win32u.dll!NtGdiCreateDIBitmapInternal
  • win32u.dll!NtGdiCreateRectRgn
  • win32u.dll!NtGdiCreateSolidBrush
  • win32u.dll!NtGdiDeleteObjectApp
  • win32u.dll!NtGdiDoPalette
  • win32u.dll!NtGdiDrawStream
  • win32u.dll!NtGdiExtGetObjectW
  • win32u.dll!NtGdiExtTextOutW
  • win32u.dll!NtGdiFontIsLinked
  • win32u.dll!NtGdiGetCharABCWidthsW
  • win32u.dll!NtGdiGetDCDword
  • win32u.dll!NtGdiGetDCforBitmap
  • win32u.dll!NtGdiGetDCObject
  • win32u.dll!NtGdiGetDeviceCaps
  • win32u.dll!NtGdiGetDIBitsInternal
  • win32u.dll!NtGdiGetEntry
  • win32u.dll!NtGdiGetFontData
  • win32u.dll!NtGdiGetGlyphIndicesW
  • win32u.dll!NtGdiGetOutlineTextMetricsInternalW
  • win32u.dll!NtGdiGetRandomRgn
  • win32u.dll!NtGdiGetRealizationInfo
  • win32u.dll!NtGdiGetTextFaceW
  • win32u.dll!NtGdiGetTextMetricsW
  • win32u.dll!NtGdiGetWidthTable
  • win32u.dll!NtGdiHfontCreate
  • win32u.dll!NtGdiIntersectClipRect
  • win32u.dll!NtGdiQueryFontAssocInfo
  • win32u.dll!NtGdiRestoreDC
  • win32u.dll!NtGdiSaveDC
  • win32u.dll!NtGdiSelectBitmap
  • win32u.dll!NtGdiSetDIBitsToDeviceInternal
  • win32u.dll!NtGdiSetLayout
  • win32u.dll!NtGdiStretchDIBitsInternal
  • win32u.dll!NtUserBeginPaint

60 additional items are not displayed above.

Process Terminate
  • TerminateProcess

Shell Command Execution

cmd.exe /c echo y|cacls.exe C:\ /P ���:F
C:\WINDOWS\system32\cmd.exe C:\WINDOWS\system32\cmd.exe /S /D /c" echo y"
C:\WINDOWS\system32\cacls.exe cacls.exe C:\ /P Âñå:F
cmd.exe /c echo y|cacls.exe C:\WindowsNT /P ���:N

Related Posts

Trending

Most Viewed

Loading...