Threat Database Trojans Trojan.MSIL.Agent.NOB

Trojan.MSIL.Agent.NOB

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 26,865
Threat Level: 80 % (High)
Infected Computers: 1
First Seen: June 6, 2026
Last Seen: August 26, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.MSIL.Agent.NOB
Signature status: No Signature

Known Samples

MD5: 912f2c5acae8599fc7e46a34a9640fbd
SHA1: c67df4d42a114548268a375b7dbb1cc3714d1caf
SHA256: 45CF29EA4DFD41064E41CAAA03B393C2F13C19DC578EFA3DDB2DF33505C59680
File Size: 46.59 KB, 46592 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 1.8.2.0
Company Name Microsoft
File Description Microsoft Teams
File Version 1.9.5.0
Internal Name xeno rat client.exe
Legal Copyright Copyright © 2023
Legal Trademarks Microsoft
Original Filename MsoftTeams.exe
Product Name Microsoft Teams
Product Version 1.8.2.0

File Traits

  • .NET
  • ntdll
  • Run
  • x86

Block Information

Total Blocks: 114
Potentially Malicious Blocks: 48
Whitelisted Blocks: 66
Unknown Blocks: 0

Visual Map

x x 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 x x 0 x x x 0 0 0 0 0 0 0 0 x x x x x x x x 0 0 x 0 0 0 x x x x x 0 0 x x x 0 0 x x x x x x 0 x x 0 x 0 x 0 x x x x 0 0 0 0 0 0 0 x x x 0 x 0 0 0 x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\appdata\roaming\xenomanager\c67df4d42a114548268a375b7dbb1cc3714d1caf_0000046592 Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144

Windows API Usage

Category API
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation