Threat Database Trojans Trojan.Agent.GDGJ

Trojan.Agent.GDGJ

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 21,274
Threat Level: 80 % (High)
Infected Computers: 3
First Seen: March 23, 2026
Last Seen: May 28, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Agent.GDGJ
Signature status: Self Signed

Known Samples

MD5: 233bc78cc5264e684ab1c82bb0f55585
SHA1: a154124b946a7fe2c40498e2394a411bf2617acb
SHA256: 8CFBC5A992C24E73310A67DFF435022E8038BC958ECB7CFF6ACA57DD13FAFB46
File Size: 4.70 MB, 4695552 bytes
MD5: 312ea25cdf7468e3b5a796201ec2cd98
SHA1: 6f30e47b466ccc8cf3c85d50e76073ce71bf60bc
SHA256: 90C1D13CBDFD91321BD6B5E948E320CAEC3292174254A633D0BF3BBE3103E5CA
File Size: 4.74 MB, 4735488 bytes
MD5: 50be8359de1c8717af5183785efb47ce
SHA1: 9358e77f0593f626c22243da837fb4d02fb6ae7e
SHA256: CE63C289C2A5E51D3A4DC933CD428FA25B70E5B6420D7ACB6B2867559C7B2967
File Size: 8.42 MB, 8418760 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • Microsoft Corporation
  • NVIDIA Corporation
File Description
  • Host Process for Windows Services
  • NVIDIA Display Driver
  • OneDrive Setup
File Version 0.1.0
Internal Name
  • nvlddmkm
  • OneDriveSetup
  • svchost
Legal Copyright
  • © 2026 NVIDIA Corporation. All rights reserved.
  • © Microsoft Corporation. All rights reserved.
Original Filename
  • nvlddmkm.sys
  • OneDriveSetup.exe
  • svchost.exe
Product Name
  • Microsoft OneDrive
  • Microsoft® Windows® Operating System
  • NVIDIA Display Driver
Product Version 0.1.0

Digital Signatures

Signer Root Status
Figma, Inc., OU=Figma Desktop, O=Figma, Inc., L=San Francisco, S=California, C=US Figma, Inc., OU=Figma Desktop, O=Figma, Inc., L=San Francisco, S=California, C=US Self Signed

File Traits

  • fptable
  • HighEntropy
  • Installer Version
  • ntdll
  • x86

Block Information

Total Blocks: 1,109
Potentially Malicious Blocks: 87
Whitelisted Blocks: 1,020
Unknown Blocks: 2

Visual Map

x ? x x x x x x x x ? 0 x x x 0 x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 x x x 0 0 0 x 0 0 0 0 0 0 0 x x 0 0 x x 0 x 0 x 0 0 0 x 0 0 0 0 0 0 0 0 x 0 x x 0 x x 0 x 0 x 0 x x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 x x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 x 0 x 0 x x 0 x 0 x 0 0 x x x 0 x 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 x 0 x 0 0 x x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 1 1 1 0 0 0 0 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 0 3 1 1 1 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.GDGJ
  • Krypt.KBAL
  • Kryptik.LSB
  • Kryptik.OSBE
  • ShellcodeRunner.WB
Show More
  • Trojan.Kryptik.Gen.BFT

Files Modified

File Attributes
c:\programdata\svc_7114ca76.log Read Attributes,Synchronize,Read Control,Write Attributes,Write extended,Append data
c:\programdata\svc_9f8cd03f.log Read Attributes,Synchronize,Read Control,Write Attributes,Write extended,Append data
c:\programdata\svc_e8c1d7e0.log Read Attributes,Synchronize,Read Control,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\gpuservice_7fb0e8.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\gpuservice_7fb0e8.exe Synchronize,Write Attributes

Windows API Usage

Category API
Network Info Queried
  • GetAdaptersAddresses
  • GetAdaptersInfo
User Data Access
  • GetComputerName
  • GetComputerNameEx
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Network Winsock2
  • WSAGetOverlappedResult
  • WSARecvFrom
  • WSASendTo
  • WSASocket
  • WSAStartup
  • WSAttemptAutodialName
Network Winsock
  • bind
  • closesocket
  • freeaddrinfo
  • getaddrinfo
  • getsockname
  • setsockopt
  • socket

Shell Command Execution

C:\Users\Spxwqugd\AppData\Local\Temp\GpuService_7fb0e8.exe (NULL)

Trending

Most Viewed

Loading...