Threat Database Trojans Trojan.MSIL.Downloader.Agent.AFNC

Trojan.MSIL.Downloader.Agent.AFNC

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.MSIL.Downloader.Agent.AFNC
Signature status: Root Not Trusted

Known Samples

MD5: fc2a5ecae9164dd637c71863dbefb1cd
SHA1: 4636923a7e8f07c0ba7601f5a550c9ad04d827f1
SHA256: 02A4B91D12ABA9886E5DB4EF0B67D9491B06625B94A14A0BE2994FF204BA65A1
File Size: 48.97 KB, 48968 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
Company Name Amazon.com
File Description LENOVO INC
File Version 1.0.0.0
Internal Name LENOVO INC.exe
Legal Copyright Copyright © Amazon.com 2026
Original Filename LENOVO INC.exe
Product Name LENOVO INC
Product Version 1.0.0.0

Digital Signatures

Signer Root Status
Shi Hu Certum Trusted Network CA Root Not Trusted

File Traits

  • .NET
  • x86

Block Information

Total Blocks: 81
Potentially Malicious Blocks: 1
Whitelisted Blocks: 53
Unknown Blocks: 27

Visual Map

? 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 ? 0 0 0 0 0 0 ? 0 ? 0 ? 0 ? 0 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 x 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\appdata\local\microsoft\lenovoupdate\update\lenovo_20260607_606f6667@2026 Synchronize,Write Attributes

Windows API Usage

Category API
User Data Access
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • NtQuerySystemInformation
Other Suspicious
  • AdjustTokenPrivileges
Network Info Queried
  • GetNetworkParams

Trending

Most Viewed

Loading...