Threat Database Trojans Trojan.Agent.DFCL

Trojan.Agent.DFCL

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.Agent.DFCL
Signature status: No Signature

Known Samples

MD5: 59344f04a55dac6cdda21a6b00e2b452
SHA1: 93e0206c0bbb4c452c6f0e5952b6f1ec1b751934
SHA256: 20765CE9D402AA9A83A1496EC58806A7D6FB8861CCE4388AD1712BAD2E4CB7E8
File Size: 186.37 KB, 186368 bytes
MD5: e30396dd0021be211e68d0b379dde285
SHA1: 55164809eebeb75d62935b9614ee02df64267bcb
SHA256: 548FA9921D910ACC94E754E1850156D1FB174677EB6EE33715E12BAFBC6C47CE
File Size: 185.86 KB, 185856 bytes
MD5: 5220350bba1616006994808ed293460e
SHA1: e75e8dada72d3920443a1eb9f6eee8d5300a692f
SHA256: 1C348E51129A5601757F7AAB1868E688EE45840F3DBA8F5F63D26CECA04D9210
File Size: 185.86 KB, 185856 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Godot Engine
File Description Godot Engine (Console)
File Version 4.0.3
Info https://godotengine.org
Legal Copyright Copyright (c) 2007-2023 Juan Linietsky, Ariel Manzur and contributors
Licence MIT
Product Name Godot Engine (Console)
Product Version 4.0.3.stable.official

File Traits

  • x64

Block Information

Total Blocks: 370
Potentially Malicious Blocks: 3
Whitelisted Blocks: 367
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.DFCL
  • Agent.TMG
  • Kryptik.FTSA
  • Trojan.Agent.Gen.PF
  • Trojan.Agent.Gen.TU

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
Show More
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTerminateProcess
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Trending

Most Viewed

Loading...