Trojan.Agent.DYI
Threat Scorecard
EnigmaSoft Threat Scorecard
EnigmaSoft Threat Scorecards are assessment reports for different malware threats which have been collected and analyzed by our research team. EnigmaSoft Threat Scorecards evaluate and rank threats using several metrics including real-world and potential risk factors, trends, frequency, prevalence, and persistence. EnigmaSoft Threat Scorecards are updated regularly based on our research data and metrics and are useful for a wide range of computer users, from end users seeking solutions to remove malware from their systems to security experts analyzing threats.
EnigmaSoft Threat Scorecards display a variety of useful information, including:
Popularity Rank: The ranking of a particular threat in EnigmaSoft’s Threat Database.
Severity Level: The determined severity level of an object, represented numerically, based on our risk modeling process and research, as explained in our Threat Assessment Criteria.
Infected Computers: The number of confirmed and suspected cases of a particular threat detected on infected computers as reported by SpyHunter.
See also Threat Assessment Criteria.
| Popularity Rank: | 1,193 |
| Threat Level: | 80 % (High) |
| Infected Computers: | 198 |
| First Seen: | June 4, 2026 |
| Last Seen: | August 30, 2026 |
| OS(es) Affected: | Windows |
Table of Contents
Analysis Report
General information
| Family Name: | Trojan.Agent.DYI |
|---|---|
| Signature status: | No Signature |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
a6139e244fa360a95a0582b28b39ee3b
SHA1:
ce37c0e59cc7f6f90f7ffb2a874151e38ab269f6
SHA256:
A50538403C4F7BC3FFC78B5CA8A1AA6EC50D985346C3B4569333C7A85B7B1F4B
File Size:
195.58 KB, 195584 bytes
|
|
MD5:
d56cda5aad56503927d9f1caee5ac9ea
SHA1:
fd38ece2a716eb36b9bbde330ef2d03220c6f3d3
SHA256:
021E5E12220872BC0ADE898EEBF47A1F15D10706A7FACE4EC7E659BD40CBA109
File Size:
195.58 KB, 195584 bytes
|
|
MD5:
df1be32ded2bd46d830e407c0bd1d0be
SHA1:
a927db8c850b9f88a9a3a84e4f631c21509fd96c
SHA256:
6F2272B7048D1E41E8FA6DC4204F9543401122D56BBB3296C5913125D14C2DC9
File Size:
195.58 KB, 195584 bytes
|
|
MD5:
4a3b89e2bd5e52230a6a861491c44bf5
SHA1:
076fdb0146a0471f8e07457ee668a195d37fba4d
SHA256:
A8E7C77A2C0BA9103466EDC19DB1427FC49FDF989CC601210D545DF09D004196
File Size:
195.58 KB, 195584 bytes
|
|
MD5:
e28d2870406b550f7c597fc7c7c30b91
SHA1:
d333bf759fb7a4768dbd944226861e2a15648c6a
SHA256:
C06E44CBD584F47ED7558A4DC19EA2CE2BC035724C75AE50749299450B2973F7
File Size:
195.58 KB, 195584 bytes
|
Show More
|
MD5:
2263b8594da2ca44fc62f7cd78ad2233
SHA1:
d155c1c7243b608cda47cb287010b446a4f1fd3d
SHA256:
9DF0D50936C56C70E8BCF7119C07051F1367A1405AAE3F276785187053D671AA
File Size:
195.58 KB, 195584 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have security information
- File has exports table
- File is 64-bit executable
- File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
- File is either console or GUI application
- File is Native application (NOT .NET application)
- File is not packed
- IMAGE_FILE_DLL is not set inside PE header (Executable)
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
File Traits
- dll
- fptable
- x64
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 719 |
|---|---|
| Potentially Malicious Blocks: | 12 |
| Whitelisted Blocks: | 683 |
| Unknown Blocks: | 24 |
Visual Map
? - Unknown Block
x - Potentially Malicious Block
Registry Modifications
Registry Modifications
This section lists registry keys and values that were created, modified and/or deleted by samples in this family. Windows Registry activity can provide valuable insight into malware functionality. Additionally, malware often creates registry values to allow itself to automatically start and indefinitely persist after an initial infection has compromised the system.| Key::Value | Data | API Name |
|---|---|---|
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | �n $ �v����Bx (�1`1�1HO @V� A��H[uN$b"hk`k�ql(�{b��P� ��!����� ��3�� ��� ������m� Ù� �V ����$�8წ���l� �&M �~ �=�SB1_ T�Vw���%�������� �AE��D��&��$���L A *�" C ��| | RegNtPreCreateKey |
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API usage analysis is a valuable tool that can help identify malicious activity, such as keylogging, security privilege escalation, data encryption, data exfiltration, interference with antivirus software, and network request manipulation.| Category | API |
|---|---|
| Syscall Use |
Show More
|