Threat Database Trojans Trojan.Agent.AID

Trojan.Agent.AID

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 18,666
Threat Level: 80 % (High)
Infected Computers: 9
First Seen: October 29, 2021
Last Seen: June 12, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Agent.AID
Signature status: No Signature

Known Samples

MD5: 93ea7f95e8583cbfbdaa65079d2f01c9
SHA1: 3c6b43315b8a1932881036e2c8ea10c22f729188
SHA256: 5E4CDBF1C4AD91948755B28306F7F1F89ADAB6F84E4099BCAFA08788773FC9CF
File Size: 139.26 KB, 139264 bytes
MD5: d1269e31489911b914af48bde78ea7c6
SHA1: eb6d271065a4a13908ff12dbfc67495f94c7f131
SHA256: A0C72BF0C1403557D81D7AC9F8FD7F79BFEF31C3C73FCFEF8F0989933829529B
File Size: 126.46 KB, 126464 bytes
MD5: 328142bc3252407c1bce07f04cd2ca0e
SHA1: 4ff913bb10d29d5063043c6f6b6d17692aac3664
SHA256: 593BE0063E3209580CA4CA6FCBD9A94F6B98EF221C3E8898620F6C50A7C5FC75
File Size: 918.53 KB, 918528 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
File Description AppXor
File Version 1.0.0.0
Internal Name AppXor.exe
Legal Copyright Copyright © 2013
Original Filename AppXor.exe
Product Name AppXor
Product Version 1.0.0.0

File Traits

  • dll
  • x86

Block Information

Total Blocks: 81
Potentially Malicious Blocks: 11
Whitelisted Blocks: 70
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x 0 x 0 0 0 0 x x 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Gamehack.JUA

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\3c6b43315b8a1932881036e2c8ea10c22f729188_0000139264.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\eb6d271065a4a13908ff12dbfc67495f94c7f131_0000126464.,LiQMAxHB

Related Posts

Trending

Most Viewed

Loading...