Threat Database Trojans Trojan.Agent.NTC

Trojan.Agent.NTC

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 0
First Seen: July 24, 2023
OS(es) Affected: Windows

The detection of Trojan.Agent.NTC on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the security of your computer, allowing unauthorized access and potentially leading to further malicious activities. It is essential to understand the nature of this threat and take prompt action to remove it and protect your system.

What Is Trojan.Agent.NTC?

Trojan.Agent.NTC is a type of Trojan horse malware, which is a broad category of threats that disguise themselves as legitimate software to gain unauthorized access to a computer system. The name "Trojan.Agent.NTC" suggests that it is a generic detection for a Trojan-type threat, and its specific capabilities and behaviors may vary. Trojans are known for their ability to open backdoors, allowing remote access to the infected system, and can lead to a range of malicious activities, including data theft, spyware installation, and further malware distribution.

How Trojan.Agent.NTC Operates

Once installed on a system, Trojan.Agent.NTC can operate in various ways, depending on its intended purpose. It may attempt to communicate with its command and control servers to receive instructions or send stolen data. Trojans often exploit vulnerabilities in software or use social engineering tactics to trick users into installing them. They can also be designed to evade detection by traditional antivirus software, making them particularly dangerous. Understanding how Trojans operate is crucial for developing effective strategies to combat them.

Symptoms of Infection

The symptoms of a Trojan infection can be subtle and may not always be immediately apparent. However, common indicators include unusual system behavior, such as unexpected pop-ups, slow performance, or unfamiliar programs running in the background. Users may also notice changes in their browser settings or the presence of unwanted toolbars. In some cases, Trojans can lead to more severe issues, such as data loss or the compromise of sensitive information. Being vigilant and monitoring system activity can help in early detection.

How to Remove Trojan.Agent.NTC

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for easier removal.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all traces of the Trojan.
  3. Uninstall any suspicious programs or applications that you do not recognize or that were installed around the time the malware was detected.
  4. Reset your web browsers (Chrome, Firefox, Edge) to their default settings to remove any malicious extensions or settings changes made by the Trojan.
  5. Reboot your computer and perform another full scan with your anti-malware tool to ensure that all remnants of the Trojan have been removed.

Conclusion

Removing Trojan.Agent.NTC from your system requires careful and thorough action to ensure that all components of the malware are eliminated. By following the steps outlined above and maintaining good cybersecurity practices, such as keeping your operating system and software up to date, using strong antivirus protection, and being cautious with emails and downloads, you can significantly reduce the risk of future infections. Remember, vigilance and proactive measures are key to protecting your digital security in today's evolving threat landscape.

Analysis Report

General information

Family Name: Trojan.Agent.NTC
Signature status: No Signature

Known Samples

MD5: caaac21d2b311352de9452e1b2bed12c
SHA1: 0d27809c83d23a981d3b61557833144df5e881d9
SHA256: 44ED515B0884ADC020EAA6E5B302A25A61640195B157233D9727E1ED3138D6A8
File Size: 457.34 KB, 457340 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • No Version Info
  • x86

Block Information

Total Blocks: 70
Potentially Malicious Blocks: 2
Whitelisted Blocks: 67
Unknown Blocks: 1

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • BadJoke.XA
  • BadJoke.XF
  • BadJoke.XH
  • KillMBR.BC
  • KillMBR.BH
Show More
  • MSIL.BadJoke.HE

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ⁡氞猈ǜ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 ��( xy* �/��Y�d�kP~� ��ރ����p4��^�o۴������z}�FVs}kP~�)���1q��7 ��׸�׸���D�ﺃ RegNtPreCreateKey
Show More
HKCU\software\microsoft\internet explorer\main::operationaldata  RegNtPreCreateKey

Windows API Usage

Category API
Network Urlomon
  • URLDownloadToFile
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • ShellExecute
  • WriteConsole
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAccessCheckByType
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAllocateUuids
  • ntdll.dll!NtAlpcAcceptConnectPort
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreatePort
  • ntdll.dll!NtAlpcQueryInformation
Show More
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtAlpcSetInformation
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeleteValueKey
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtImpersonateAnonymousToken
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenPrivateNamespace
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtPowerInformation
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtQueryWnfStateNameInformation
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetSecurityObject
  • ntdll.dll!NtSetSystemInformation
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSetTimerEx
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtUpdateWnfStateData
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Process Terminate
  • TerminateProcess

Shell Command Execution

open cmd.exe /C c:\devgru\7zika.exe e c:\devgru\inrtefunsb.zip -p102030 -oc:\devgru\ *.* -r
open c:\devgru\inrtefunsb.exe
open C:\progra~1\intern~1\iexplore.exe http://www.web-promocoes.net/novogast/
WriteConsole: 'c:\devgru\7zika

Trending

Most Viewed

Loading...