Threat Database Trojans Trojan.Agent.DRS

Trojan.Agent.DRS

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 26,343
Threat Level: 80 % (High)
Infected Computers: 1
First Seen: December 9, 2024
Last Seen: January 30, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Agent.DRS
Signature status: No Signature

Known Samples

MD5: 39033d6c5d28c09ee24d4d1b57a3b581
SHA1: d9392f4ef2c9891c7e6bc3254a230adc423b795e
SHA256: A7DA906D721E11C6203FBCA350D4F1204352C1B49A94597C9A0B84B3C290CB89
File Size: 282.11 KB, 282112 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
File Description 复制粘贴
File Version 1.1.1.11
Legal Copyright DXVM x1105110683
Product Name 复制粘贴
Product Version 1.1.1.1

File Traits

  • dll
  • x86

Block Information

Total Blocks: 276
Potentially Malicious Blocks: 114
Whitelisted Blocks: 162
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 x 0 x x x x x x x 0 x x x x x x x x x x x x 0 x x x x 0 x 0 x x 0 x x x 0 0 0 0 x 0 x x x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x 0 0 x 0 0 x 0 x x 0 0 x x x x x x 0 x x x x x x x x x x x x x x x x x 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 x x x 0 0 x x 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x x 0 0 0 0 0 0 x 0 0 x x x x x 0 0 x 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Jeefo.A
  • Parite.F
  • Parite.FA
  • Parite.W

Files Modified

File Attributes
c:\users\user\downloads\d9392f4ef2c9891c7e6bc3254a230adc423b795e_0000282112 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\d9392f4ef2c9891c7e6bc3254a230adc423b795e_0000282112 Generic Write,Read Attributes
c:\users\user\downloads\d9392f4ef2c9891c7e6bc3254a230adc423b795e_0000282112 Synchronize,Write Attributes
c:\windows\svchost.exe Generic Write,Read Attributes

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Service Control
  • StartServiceCtrlDispatcher
Network Info Queried
  • GetAdaptersAddresses
Network Winsock2
  • WSASocket
  • WSAStartup
Network Winsock
  • bind
  • inet_addr
  • recvfrom
  • setsockopt
  • socket
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
  • OpenClipboard

Shell Command Execution

"C:\WINDOWS\svchost.exe" "c:\users\user\downloads\d9392f4ef2c9891c7e6bc3254a230adc423b795e_0000282112"
"c:\users\user\downloads\d9392f4ef2c9891c7e6bc3254a230adc423b795e_0000282112"

Trending

Most Viewed

Loading...