Threat Database Trojans Trojan.Agent.Gen.ERP

Trojan.Agent.Gen.ERP

By CagedTech in Trojans
Published:
Last updated:

Threat Scorecard

Popularity Rank: 5,540
Threat Level: 80 % (High)
Infected Computers: 23
First Seen: August 13, 2026
Last Seen: September 23, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Agent.Gen.ERP
Signature status: No Signature

Known Samples

MD5: d04c416f7584da1e6090bd6a2a582048
SHA1: 06b886ce70dc9334ffc59e0c883005580d1deb4d
SHA256: F34B9744FAA8DD98D81A5165E640F0C0D7F2977853EEBD07110689E4E07D6EF1
File Size: 441.34 KB, 441344 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name Microsoft Corporation
File Description Accounts RT utilities for mail, contacts, calendar
File Version 10.0.17763.8641 (WinBuild.160101.0800)
Internal Name AccountsRT
Legal Copyright © Microsoft Corporation. All rights reserved.
Original Filename AccountsRT.dll
Product Name Microsoft® Windows® Operating System
Product Version 10.0.17763.8641

File Traits

  • dll
  • ntdll
  • x64

Block Information

Total Blocks: 2,050
Potentially Malicious Blocks: 248
Whitelisted Blocks: 1,612
Unknown Blocks: 190

Visual Map

x 0 ? 1 0 ? 0 ? ? 0 0 ? ? 0 0 0 ? ? 0 ? 0 0 0 0 1 0 0 ? 0 ? ? 0 0 0 0 ? 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 ? ? ? ? 0 0 0 1 ? 0 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? x ? ? x ? 0 0 0 0 ? 0 ? 0 ? ? 0 0 0 0 ? 0 0 0 ? ? 0 0 0 0 ? ? ? ? ? 0 0 0 x 0 0 0 1 0 ? ? ? ? ? ? ? ? ? ? x 0 0 x x x x 0 x 0 0 0 0 0 0 0 0 0 x 0 ? ? 0 ? ? ? ? 0 0 0 0 ? 0 ? ? 0 0 ? 1 0 0 0 1 ? 0 0 0 0 0 0 ? 0 0 0 1 ? 0 0 0 0 0 0 0 0 0 ? 0 0 ? ? ? 0 ? 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 x ? ? 0 ? 0 0 x ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 ? 0 ? 0 0 0 ? 0 ? ? 0 ? ? 0 0 x x x ? 0 0 ? 0 0 0 0 ? ? ? 0 ? 1 ? 1 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 1 0 0 1 0 0 x x ? ? x 0 0 0 0 0 0 x 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 2 0 0 0 0 0 0 0 0 1 0 1 1 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 1 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 1 1 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x 0 ? x 0 x 0 0 0 0 0 0 0 x x x 0 x 0 x x 0 0 0 0 0 0 0 0 0 x ? 0 0 0 0 0 0 0 0 0 1 1 1 1 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x ? 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 x ? ? ? 0 x x x x x x x x x 0 0 0 x x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 1 1 1 0 0 0 0 0 1 0 0 0 0 0 0 1 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 ? ? ? x x 0 0 0 x x 0 ? ? ? ? ? ? 0 x 0 0 0 0 x 0 0 0 0 x x 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 x ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x x x x x x x x x x x x x x x x x x x x x 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 ? ? 0 0 0 0 0 1 1 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 ? x 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 x x x x x 0 0 0 0 ? ? ? ? ? ? ? 0 0 0 0 0 ? x ? 0 ? 0 0 0 0 0 ? x ? x x 0 0 0 0 0 0 0 x 0 0 x 0 0 x 0 0 0 x 0 0 x 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 x 0 0 ? 0 0 0 ? 0 0 x x 0 0 0 0 0 ? x x ? x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x 0 0 0 0 0 0 0 0 0 ? 0 x x x 0 0 1 0 0 x 0 0 0 0 0 0 0 0 x x x x x x x x x x x x x x x x x x x x x 0 0 0 0 0 0 0 0 0 ? 0 x 0 0 0 0 0 x 0 0 ? x ? x 0 x x 0 0 ? ? x x 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 1 1 1 1 1 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? ? ? ? ? ? 0 0 ? 0 x 0 0 ? 0 0 0 0 0 ? ? ? 0 x 0 0 0 x 0 0 0 0 0 0 0 x x 0 ? ? ? 0 0 0 ? ? 0 0 ? ? 0 x x 0 0 0 0 0 0 0 ? x 0 0 ? 0 0 x ? 0 0 x 0 x 0 0 0 x 0 0 0 x x x x x x x x x x ? x 0 x ? 0 x x 0 x ? x x ? x x 0 0 0 x 0 0 x 0 x 0 0 x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x 0 0 0 0 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 x 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
Show More
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN