Trojan.Agent.MTGB
Trojan.Agent.MTGB is a detection name used to identify a malicious program classified as a Trojan horse. Unlike viruses or worms, Trojans like Trojan.Agent.MTGB do not self-replicate. Instead, they rely on deception, disguising themselves as legitimate or harmless files to trick users or security tools into allowing them to run. Because detection names in the "Agent" family are often generic labels applied to a range of related malicious files, the exact capabilities of any specific sample detected as Trojan.Agent.MTGB can vary, but it generally falls into the broad and dangerous category of backdoor or data-stealing Trojans.
Table of Contents
What Trojan.Agent.MTGB Does
Once active on a system, threats detected under generic Trojan.Agent names typically perform a range of harmful actions in the background without the user's knowledge or consent. These commonly include establishing a connection to a remote server controlled by cybercriminals, allowing attackers to send commands to the infected machine. Typical behavior for this type of Trojan includes downloading and installing additional malicious payloads, collecting system information, logging keystrokes, stealing saved credentials, modifying system settings, and disabling security software to avoid detection and removal. Some variants may also use the infected computer's resources for other malicious purposes, such as participating in larger networks of compromised machines.
How It Usually Gets Onto Computers
Trojans like this one typically spread through deceptive means rather than exploiting vulnerabilities on their own. Common infection methods include malicious email attachments disguised as invoices, receipts, or other urgent documents; bundled downloads from untrustworthy or pirated software sites; fake software updates or cracked program installers; and malicious links shared through spam messages or compromised websites. Because the Trojan relies on tricking the user into executing it, cautious online behavior plays a major role in prevention.
Risks for the User
An infection involving a Trojan of this nature can carry serious consequences. Potential risks include theft of personal and financial information, unauthorized access to online accounts, installation of additional malware such as ransomware or spyware, degraded system performance, and loss of privacy due to ongoing surveillance of the user's activity. In more severe cases, the infected computer could be fully controlled remotely by attackers, putting both the user's data and the integrity of the entire system at risk.
Signs of Infection
Trojans are designed to operate quietly, so signs of infection are not always obvious. However, users may notice certain warning signals, including:
- Unexpected slowdowns or freezes, even when running few programs
- Unusual network activity or increased data usage
- Unfamiliar processes running in the Task Manager
- Security software being disabled or unable to update
- Unexpected pop-ups, browser redirects, or new toolbars
- Unauthorized changes to system or browser settings
How to Stay Protected
To reduce the risk of infection from Trojan.Agent.MTGB and similar threats, users should avoid opening email attachments or clicking links from unknown or unexpected senders, download software only from official and reputable sources, keep the operating system and installed applications updated with the latest security patches, and use reliable security tools to scan downloads before running them. Maintaining regular backups of important data also helps minimize damage in case of an infection. Staying alert to suspicious behavior and avoiding pirated or cracked software further reduces exposure to this type of threat.
Analysis Report
General information
| Family Name: | Trojan.Agent.MTGB |
|---|---|
| Signature status: | No Signature |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
60efd433a8415f00f4afc81d54547a3f
SHA1:
1a55c0194a2b3f409406537c63e98251297824a8
SHA256:
5FC793CC6C5EB028078B6C05E61C8EE764F02A5BAF1D7E89A2962F06FD65C718
File Size:
5.39 MB, 5386389 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have debug information
- File doesn't have exports table
- File doesn't have security information
- File has TLS information
- File is 32-bit executable
- File is either console or GUI application
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is Native application (NOT .NET application)
- File is not packed
Show More
- IMAGE_FILE_DLL is not set inside PE header (Executable)
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
Windows PE Version Information
Windows PE Version Information
This section displays values and attributes that have been set in the Windows file version information data structure for samples within this family. To mislead users, malware actors often add fake version information mimicking legitimate software.| Name | Value |
|---|---|
| Comments | Task relay helper for scheduled work. |
| Company Name | Copper Hill Apps |
| File Description | Device coordination utility |
| File Version | 2.0.75.3466 |
| Internal Name | Session Aid |
| Legal Copyright | Copyright (C) 2021-2024 Copper Hill Apps |
| Legal Trademarks | Proprietary. |
| Original Filename | Session Aid.exe |
| Private Build | 2.0.75 build 3466 |
| Product Name | Session Aid |
| Product Version | 2.0.75.3466 |
| Special Build | Release |
File Traits
- HighEntropy
- x86
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 1,084 |
|---|---|
| Potentially Malicious Blocks: | 103 |
| Whitelisted Blocks: | 981 |
| Unknown Blocks: | 0 |
Visual Map
? - Unknown Block
x - Potentially Malicious Block
Similar Families
Similar Families
This section lists other families that share similarities with this family, based on EnigmaSoft’s analysis. Many malware families are created from the same malware toolkits and use the same packing and encryption techniques but uniquely extend functionality. Similar families may also share source code, attributes, icons, subcomponents, compromised and/or invalid digital signatures, and network characteristics. Researchers leverage these similarities to rapidly and effectively triage file samples and extend malware detection rules.- Agent.MTGB
Files Modified
Files Modified
This section lists files that were created, modified, moved and/or deleted by samples in this family. File system activity can provide valuable insight into how malware functions on the operating system.| File | Attributes |
|---|---|
| c:\users\user\appdata\local\microsoft\windows\settingsync\tgp5dg.exe | Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144 |
| c:\users\user\appdata\local\temp\mpwo-rtg.tmp | Generic Write,Read Attributes |
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API usage analysis is a valuable tool that can help identify malicious activity, such as keylogging, security privilege escalation, data encryption, data exfiltration, interference with antivirus software, and network request manipulation.| Category | API |
|---|---|
| Process Manipulation Evasion |
|
| Process Shell Execute |
|
Shell Command Execution
Shell Command Execution
This section lists Windows shell commands that are run by the samples in this family. Windows Shell commands are often leveraged by malware for nefarious purposes and can be used to elevate security privileges, download and launch other malware, exploit vulnerabilities, collect and exfiltrate data, and hide malicious activity.
C:\Users\Mhhskwke\AppData\Local\Microsoft\Windows\SettingSync\tgp5dg.exe "C:\Users\Mhhskwke\AppData\Local\Microsoft\Windows\SettingSync\tgp5dg.exe"
|