Threat Database Trojans Trojan.Agent.Gen.CWI

Trojan.Agent.Gen.CWI

By CagedTech in Trojans
Published:
Last updated:

Threat Scorecard

Popularity Rank: 13,160
Threat Level: 80 % (High)
Infected Computers: 5
First Seen: June 12, 2026
Last Seen: September 29, 2026
OS(es) Affected: Windows

Trojan.Agent.Gen.CWI is a generic detection name used to identify a Trojan horse program. Because detections labeled "Agent.Gen" are created using generic scanning signatures and behavioral patterns rather than a single, specific piece of malware, this threat may refer to one of several related malicious files that share common traits. Like other Trojans, it is designed to infiltrate a computer without the user's knowledge or consent and to carry out harmful actions in the background.

What Trojan.Agent.Gen.CWI Does

As with most threats in the Trojan category, the exact behavior of Trojan.Agent.Gen.CWI can vary depending on the specific variant detected under this generic name. However, Trojans of this type typically share a core set of malicious capabilities, which may include:

  • Running quietly in the background without visible windows or obvious signs of activity
  • Modifying system settings or startup entries so that it launches automatically when the computer boots
  • Connecting to remote servers controlled by cybercriminals to receive commands or download additional malicious components
  • Collecting information from the infected device, such as system details or stored data
  • Acting as a gateway for other malware, including ransomware, spyware, or additional Trojans

Because this is a generic detection, it is typical for security tools to flag a range of files exhibiting similar suspicious behavior under this same name, rather than pointing to one specific, fixed piece of code.

How It Usually Gets Onto Computers

Trojans in this category commonly spread through methods that rely on tricking the user rather than exploiting a single vulnerability. Typical infection routes include:

  • Email attachments or links disguised as invoices, receipts, or official documents
  • Bundled installers for free or pirated software downloaded from untrustworthy websites
  • Fake software updates or cracked versions of popular applications
  • Malicious advertisements or compromised websites that prompt automatic downloads
  • Infected removable drives, such as USB sticks, shared between computers

Risks for the User

An infection involving a Trojan like this one can expose users to a range of serious risks, including loss of personal data, financial information theft, unauthorized remote access to the system, and degraded computer performance. Because Trojans often operate silently, they can remain active for extended periods, giving attackers continued access to the compromised device.

Signs of Infection

Common warning signs associated with Trojan infections, which may apply here as well, include:

  • Noticeable slowdowns in system performance
  • Unexpected pop-ups, error messages, or crashes
  • Unfamiliar programs or processes running in the background
  • Changes to browser settings or new toolbars appearing without permission
  • Increased network activity even when the computer is idle

How to Stay Protected

To reduce the risk of encountering threats like Trojan.Agent.Gen.CWI, users should avoid downloading software from unverified sources, refrain from opening email attachments or links from unknown senders, keep their operating system and applications updated, and use reputable security software to scan and monitor their systems regularly. Practicing caution online and maintaining regular backups of important data can also help minimize the potential damage caused by this type of threat.

Analysis Report

General information

Family Name: Trojan.Agent.Gen.CWI
Signature status: No Signature

Known Samples

MD5: 52e0b5cde8a8e9b296d3f60f61cf88b5
SHA1: ffb5cb3c6fd79f2370aa7ec049f3e1288fa88b1f
SHA256: B407B721214FA6C5512A5D7EA7126573647D09A5ED6D1F7A8DE710058162BC58
File Size: 658.43 KB, 658432 bytes
MD5: 3467538b39676a2335cb06cc1890e7c5
SHA1: 099872a75a1c5855dafd25e3ffd3b68590267447
SHA256: 8BF2B7817D37AFE443BD3BDEF638236DCE38E3C296141543424985668916DB02
File Size: 1.44 MB, 1437696 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have resources
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • 2+ executable sections
  • fptable
  • HighEntropy
  • No Version Info
  • upx
  • x64

Block Information

Total Blocks: 1,694
Potentially Malicious Blocks: 265
Whitelisted Blocks: 1,284
Unknown Blocks: 145

Visual Map

0 0 0 0 0 0 0 0 0 ? ? x x x 0 0 0 0 0 0 0 x x ? 0 ? x 0 0 x x 0 x 0 ? x 0 x ? x 0 x 0 0 0 x x 0 0 x 0 0 0 x 0 0 ? 0 0 0 ? x x 0 ? x ? ? x 0 0 ? ? ? ? 0 0 x x 0 0 ? ? ? ? x 0 ? ? ? ? x 0 0 ? ? ? 0 x x 0 x x ? x x ? 0 ? ? x ? ? x 0 x x ? x x ? x x 0 0 ? ? x ? x 0 x x x ? ? ? 0 0 0 x ? 0 ? 0 0 0 1 x x ? x x x ? x ? 0 x 0 0 0 0 0 ? ? ? ? x x 0 x 0 0 x 0 ? x 0 x x x x 0 x x 0 x x 0 x x 0 x x 0 x x 0 x x 0 x x 0 x x 0 x x x 0 0 ? x 0 ? ? 0 0 ? 0 0 x ? 0 ? x 0 ? ? ? 0 0 ? x x x x x x 0 x 0 x 0 0 0 0 0 0 0 0 0 x x 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 ? ? x 0 x x 0 0 x 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 x x 0 x 0 x x x x x x x x 0 x 0 x x 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 x x 0 0 x 0 x 0 x ? ? 0 x 0 x ? ? x ? ? ? x ? ? ? ? x x ? ? ? 0 0 0 0 x x x x x x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x ? ? ? ? ? ? ? ? ? 0 ? ? 0 x ? ? x ? ? ? ? x x x x ? 0 x x x x 0 ? x x ? 0 0 0 0 x 0 0 0 0 x 0 x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 x x x x 0 0 x x x x x x x x x x x ? 0 x x 0 x 0 x x x x ? x ? 0 0 0 x x 0 0 x 0 x x x 0 0 0 0 0 0 0 0 0 ? 0 x 0 ? ? ? ? x ? ? ? ? ? x 0 x ? x 0 x 0 0 0 0 ? x ? 0 ? ? x ? ? 0 0 0 0 ? x x ? x ? ? ? x ? x 0 x x ? x ? 0 0 ? ? x 0 x 0 0 0 0 0 0 x x 0 0 0 0 0 x 0 0 ? x 0 0 0 ? ? 0 0 0 x x ? x ? 0 ? x 0 ? x 0 x 0 0 x ? x x x x x 0 x 0 x x 0 x x x x 0 0 0 x x 0 0 0 x 0 x x x x x x x x x x x x ? x x ? 0 0 0 ? x x x x x ? ? ? x ? 0 x x x x ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 2 0 0 0 0 ? 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 x x x x 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Trojan.Agent.Gen.FYS

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreateResourceReserve
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcQueryInformationMessage
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtAlpcSetInformation
  • ntdll.dll!NtApphelpCacheControl
Show More
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtGetCompleteWnfStateSubscription
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
User Data Access
  • GetComputerName
  • GetUserName
Network Wininet
  • HttpOpenRequest
  • HttpQueryInfo
  • HttpSendRequest
  • InternetConnect
  • InternetOpen
  • InternetSetOption
Network Winhttp
  • WinHttpOpen