Trojan.Agent.OR
Threat Scorecard
EnigmaSoft Threat Scorecard
EnigmaSoft Threat Scorecards are assessment reports for different malware threats which have been collected and analyzed by our research team. EnigmaSoft Threat Scorecards evaluate and rank threats using several metrics including real-world and potential risk factors, trends, frequency, prevalence, and persistence. EnigmaSoft Threat Scorecards are updated regularly based on our research data and metrics and are useful for a wide range of computer users, from end users seeking solutions to remove malware from their systems to security experts analyzing threats.
EnigmaSoft Threat Scorecards display a variety of useful information, including:
Popularity Rank: The ranking of a particular threat in EnigmaSoft’s Threat Database.
Severity Level: The determined severity level of an object, represented numerically, based on our risk modeling process and research, as explained in our Threat Assessment Criteria.
Infected Computers: The number of confirmed and suspected cases of a particular threat detected on infected computers as reported by SpyHunter.
See also Threat Assessment Criteria.
| Threat Level: | 80 % (High) |
| Infected Computers: | 0 |
| First Seen: | April 12, 2023 |
| OS(es) Affected: | Windows |
The detection of Trojan.Agent.OR on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the security and integrity of your computer, and it's essential to understand its nature and take steps to remove it.
Table of Contents
What Is Trojan.Agent.OR?
Trojan.Agent.OR is a type of Trojan horse malware, which is a broad category of malicious software that disguises itself as legitimate or harmless. The ".OR" suffix may indicate a specific variant or designation, but it's crucial to focus on the overall characteristics of Trojan horse malware. These threats are typically designed to gain unauthorized access to a system, steal sensitive information, or disrupt normal operations. Trojan horses can be delivered through various means, including infected software downloads, phishing emails, or exploited vulnerabilities.
How Trojan.Agent.OR Operates
Once installed, Trojan.Agent.OR can operate in various ways, depending on its intended purpose. It may attempt to communicate with its command and control servers to receive instructions or transmit stolen data. The malware might also try to disable security software, create backdoors for future access, or install additional malicious components. Trojan horses often rely on social engineering tactics or exploit system weaknesses to achieve their goals, making them a significant concern for computer users.
Symptoms of Infection
Identifying a Trojan.Agent.OR infection can be challenging, as it may not always exhibit obvious symptoms. However, some common signs of infection include unusual system behavior, such as slow performance, frequent crashes, or unexplained changes to system settings. You may also notice unfamiliar programs or icons on your desktop, or receive unexpected pop-ups or alerts. In some cases, the malware may attempt to intercept or manipulate your online activities, such as redirecting you to fake websites or stealing login credentials.
- Unexplained changes to system settings or configuration
- Slow system performance or frequent crashes
- Unfamiliar programs or icons on your desktop
- Unexpected pop-ups or alerts
- Unusual network activity or connectivity issues
How to Remove Trojan.Agent.OR
- Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for internet access.
- Download and install a reputable anti-malware tool, such as SpyHunter, and perform a full system scan to detect and remove the Trojan.Agent.OR infection.
- Uninstall any suspicious programs or applications that may be related to the malware.
- Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any potential malware components.
- Reboot your system and perform another full scan with your anti-malware tool to ensure that the infection has been completely removed.
Conclusion
Removing Trojan.Agent.OR from your system requires a combination of technical expertise and caution. By following the steps outlined above and using reputable security tools, you can help ensure the complete removal of the malware and prevent future infections. It's essential to remain vigilant and proactive in maintaining your system's security, including keeping your operating system and software up-to-date, using strong antivirus protection, and being cautious when interacting with unknown or untrusted sources.
Analysis Report
General information
| Family Name: | Trojan.Agent.OR |
|---|---|
| Signature status: | No Signature |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
56746cb8a2d87c353d4244621170746a
SHA1:
d484571c24e606ace1421d40a584e66d9607bbdf
SHA256:
8D5958720D650BC6D0E3533770D37EF91D53C66163E5149DC251ECFE57D4873C
File Size:
36.86 KB, 36864 bytes
|
|
MD5:
59d7b6c66aff4b4827b9d241b64e1dce
SHA1:
70f53c1291d1d1a739e5e8f8d5c3a9bec2737e9a
SHA256:
AC98AEC25355BD40D22CC5930C5189E9A98C8E1D013DCE07A9AD81411EC15B2E
File Size:
20.99 KB, 20992 bytes
|
|
MD5:
20986973f143190e4798c4e316a9676b
SHA1:
653d0764c6dbc66ac917bf092fdef15f0e78e175
SHA256:
BF33235079EDDFC3A0205912C08A1F7410434BFE613806B42887266DF0FB4736
File Size:
243.12 KB, 243115 bytes
|
|
MD5:
530f9fa7658fcb9f6de4d151d3b091ce
SHA1:
92795ea6e11420d2e5328e05f179d99ca0af3dfb
SHA256:
24F8163860D117F53CE79ECFDF44851C5820123157B8EE51E0C5EC5FC630FA38
File Size:
80.38 KB, 80384 bytes
|
|
MD5:
aa550a71c8fa801255df2cf9f66635a4
SHA1:
309cd5f3dbed5d67181c1a99a266824a3b947059
SHA256:
C9ED4CC70D75DDAD5273A7401745F24981066003ABBA11442B65932E76DFF898
File Size:
318.83 KB, 318834 bytes
|
Show More
|
MD5:
3a21f4d7039d68cc149729f6624734ca
SHA1:
bf9046a31ef17fdff07dead531a7388d997eb589
SHA256:
49CD491EB4CC200AA0B145964758FF8539E7A321497912E6FFF6B540F689CCE2
File Size:
20.99 KB, 20992 bytes
|
|
MD5:
9757ef3c67f2a8b303bf7e855531b091
SHA1:
88570193c5f3a0470e4eeb76b20488cd038ef973
SHA256:
3B34E21D338149E8B58B444B618F81AEA9B2C60CD862D3D7809A674DEE192A4F
File Size:
28.16 KB, 28160 bytes
|
|
MD5:
cd539547dc8acf5ae303ef200eddabbd
SHA1:
0772d814f568838827dbbaba691fbf8610d0adfc
SHA256:
4A3D1D7155EB9EB9E4E035369A565159019FF41AB8B51C720A800C6A72A20B05
File Size:
132.41 KB, 132415 bytes
|
|
MD5:
07151e00c06de3d90f9cf74554282002
SHA1:
0dd7edfad7157c555f7c063386e4fc898abf0752
SHA256:
3F050D87669ADBADC0B44F85742445A26BA731DE6C94BF9394B70456995C1C4E
File Size:
17.41 KB, 17408 bytes
|
|
MD5:
2bd41c7a940bd0720ae468028f9e3329
SHA1:
0b13850e46008f45fb27afa0a9ee597127cd39cf
SHA256:
65893AD2C2E138CBDC7FFDBE024199EC4F8069B7117C258F151D5FFA52297325
File Size:
1.42 MB, 1415295 bytes
|
|
MD5:
fbd67ee05049919b925bd3f90a5e77be
SHA1:
46ff83bf7784f737132ab93171c954a5aff7a530
SHA256:
410B08F7AD9867117BC3BAE968BC07ACE8BDCF469D9A042C19E67E655863D0CB
File Size:
20.48 KB, 20480 bytes
|
|
MD5:
8a158f7d8f897978766c1fb886bef0a3
SHA1:
e40447abc7753cd3f0f75dcf7de632c8214d17c1
SHA256:
37CF10A30D3AF5086F5B89AE41BD10191D233FF498AF0AE297F07B8C530E596E
File Size:
19.97 KB, 19968 bytes
|
|
MD5:
e63592420b6237962662fdb109c049c0
SHA1:
97a43feebcbb99141f5d7c47806153c90e4400da
SHA256:
84E31A0179921774DBD3901418F62990D9E65F3888417672E0647B35AB1FFB49
File Size:
53.76 KB, 53760 bytes
|
|
MD5:
6bf610924fb4bf0efb336c5ea831e0a8
SHA1:
420a111fe6b9996c761bc468f392ce1f23e09618
SHA256:
887839ECCB2D79D1B5F02E7EB094192264F340DCCC69163E694C6D90533F019C
File Size:
55.51 KB, 55508 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have debug information
- File doesn't have exports table
- File doesn't have relocations information
- File doesn't have resources
- File doesn't have security information
- File has been packed
- File is 32-bit executable
- File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
- File is either console or GUI application
Show More
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is Native application (NOT .NET application)
- File is not packed
- IMAGE_FILE_DLL is not set inside PE header (Executable)
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
File Icons
File Icons
This section displays icon resources found within family samples. Malware often replicates icons commonly associated with legitimate software to mislead users into believing the malware is safe.Windows PE Version Information
Windows PE Version Information
This section displays values and attributes that have been set in the Windows file version information data structure for samples within this family. To mislead users, malware actors often add fake version information mimicking legitimate software.| Name | Value |
|---|---|
| Comments |
|
| Company Name |
|
| File Description |
|
| File Version |
|
| Internal Name |
|
| Legal Copyright |
|
| Legal Trademarks | Tutti i diritti sono riservati, (TM) DVL & Inc. |
| Lingua | Italiano (Standard) |
| Original Filename |
|
| Product Name |
|
| Product Version |
|
File Traits
- 2+ executable sections
- big overlay
- HighEntropy
- No Version Info
- packed
- x86
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 211 |
|---|---|
| Potentially Malicious Blocks: | 146 |
| Whitelisted Blocks: | 21 |
| Unknown Blocks: | 44 |
Visual Map
? - Unknown Block
x - Potentially Malicious Block
Similar Families
Similar Families
This section lists other families that share similarities with this family, based on EnigmaSoft’s analysis. Many malware families are created from the same malware toolkits and use the same packing and encryption techniques but uniquely extend functionality. Similar families may also share source code, attributes, icons, subcomponents, compromised and/or invalid digital signatures, and network characteristics. Researchers leverage these similarities to rapidly and effectively triage file samples and extend malware detection rules.- Agent.OR
Files Modified
Files Modified
This section lists files that were created, modified, moved and/or deleted by samples in this family. File system activity can provide valuable insight into how malware functions on the operating system.| File | Attributes |
|---|---|
| \device\namedpipe\gmdasllogger | Generic Write,Read Attributes |
| c:\users\user\downloads\risulta.trc | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\downloads\risultati.txt | Generic Write,Read Attributes |
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API usage analysis is a valuable tool that can help identify malicious activity, such as keylogging, security privilege escalation, data encryption, data exfiltration, interference with antivirus software, and network request manipulation.| Category | API |
|---|---|
| Anti Debug |
|
| User Data Access |
|
| Other Suspicious |
|