Threat Database Trojans Trojan.Agent.Gen.CLB

Trojan.Agent.Gen.CLB

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.Agent.Gen.CLB
Signature status: No Signature

Known Samples

MD5: 9c04ee265a82db4ce7a4cde4d89d0055
SHA1: 5c8c62e7bf1eee0de6d2d3e9d7caca535896ba92
SHA256: D13D3DE76A86AB875C2ACD0D28C866928C842B206D1F83EB3CC5886811FD24D2
File Size: 40.96 KB, 40960 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name Silicon Graphics Inc.
File Description Perl Script Host
File Version 5.4.1270.12
Internal Name LuaVM
Legal Copyright 2024 Silicon Graphics Inc.. All rights reserved.
Original Filename node.exe
Product Name Perl Script Host
Product Version 5.4.1270.12

File Traits

  • WriteProcessMemory
  • x64

Block Information

Total Blocks: 42
Potentially Malicious Blocks: 34
Whitelisted Blocks: 1
Unknown Blocks: 7

Visual Map

x ? x x x x x x x x x x ? x x 0 ? x x ? x x x x x x x x x x x ? ? x ? x x x x x x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

Files Modified

File Attributes
c:\users\user\appdata\roaming\microsoft\windows\services\winhost.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\roaming\microsoft\windows\services\winhost.exe Read Attributes,Synchronize,Write Attributes
c:\users\user\appdata\roaming\microsoft\windows\services\winhost.exe Synchronize,Write Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\explorer\advanced::ictrlpath c:\users\user\downloads\5c8c62e7bf1eee0de6d2d3e9d7caca535896ba92_0000040960 RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\explorer\advanced::ictrldata ⼸痥當畵畱畵誊畵痍畵畵畵电畵畵畵畵畵畵畵畵畵畵畵畵畵畵畵畵畵疭畵橻篏셵롼쵔㥴咸ᴡ؜Օᨇܒ᠔ᙕᬔᨛ唁ဗݕᬀ᱕唛㨱唦ᨘထ硛罸畑畵畵畵恖钾Ē쟐Ē쟐Ē쟐聫웖ē쟐聫웑ę쟐Ē쟑Ř쟐語웕ē쟐語월Ę쟐語윯ē쟐語웒ē쟐ᰧᴖĒ쟐畵畵畵畵〥畵異䐼Ὑ畵畵畵畵疅畗睾䝻㥵畵❵畵畵畵 RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtCopyFileChunk
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
Show More
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtPowerInformation
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetSecurityObject
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Trending

Most Viewed

Loading...