Threat Database Trojans Trojan.MSIL.Agent.ACM

Trojan.MSIL.Agent.ACM

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 24,445
Threat Level: 80 % (High)
Infected Computers: 2
First Seen: September 3, 2024
Last Seen: August 26, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.MSIL.Agent.ACM
Signature status: No Signature

Known Samples

MD5: db3eafe3b7890a2ff315be1ffeaba30f
SHA1: 536205262fbb6cacfa39d9b0bfd66df4d885f4c1
SHA256: E6F3B534F969ADD4A98A70EB67B53CD4917B5E2BA256467A7C6D1DA3AE817C6C
File Size: 64.51 KB, 64512 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
File Description WindowsFormsApp
File Version 1.0.0.0
Internal Name WindowsFormsApp.exe
Legal Copyright Copyright © 2022
Original Filename WindowsFormsApp.exe
Product Name WindowsFormsApp
Product Version 1.0.0.0

File Traits

  • .NET
  • x86

Block Information

Total Blocks: 18
Potentially Malicious Blocks: 1
Whitelisted Blocks: 17
Unknown Blocks: 0

Visual Map

0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Agent.ACM

Files Modified

File Attributes
c:\users\user\appdata\local\windowsformsapp\536205262fbb6cacfa39d9b0b_url_gtvextlrsgzjjuthgfd1sqm5r1t2ktkl\1.0.0.0\5maiqjj3.newcfg Generic Write,Read Attributes
c:\users\user\appdata\local\windowsformsapp\536205262fbb6cacfa39d9b0b_url_gtvextlrsgzjjuthgfd1sqm5r1t2ktkl\1.0.0.0\5maiqjj3.newcfg Synchronize,Write Attributes
c:\users\user\appdata\local\windowsformsapp\536205262fbb6cacfa39d9b0b_url_gtvextlrsgzjjuthgfd1sqm5r1t2ktkl\1.0.0.0\5maiqjj3.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\windowsformsapp\536205262fbb6cacfa39d9b0b_url_gtvextlrsgzjjuthgfd1sqm5r1t2ktkl\1.0.0.0\dtsgdecw.newcfg Generic Write,Read Attributes
c:\users\user\appdata\local\windowsformsapp\536205262fbb6cacfa39d9b0b_url_gtvextlrsgzjjuthgfd1sqm5r1t2ktkl\1.0.0.0\dtsgdecw.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\windowsformsapp\536205262fbb6cacfa39d9b0b_url_gtvextlrsgzjjuthgfd1sqm5r1t2ktkl\1.0.0.0\user.config Generic Write,Read Attributes
c:\users\user\appdata\local\windowsformsapp\536205262fbb6cacfa39d9b0b_url_gtvextlrsgzjjuthgfd1sqm5r1t2ktkl\1.0.0.0\user.config Synchronize,Write Data

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey

Windows API Usage

Category API
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
Process Shell Execute
  • ShellExecuteEx

Shell Command Execution

(NULL) c:\users\user\downloads\FreeFlashPlayer.exe