Threat Database Trojans Trojan.Spy.Agent.MG

Trojan.Spy.Agent.MG

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 13,654
Threat Level: 80 % (High)
Infected Computers: 5
First Seen: July 21, 2026
Last Seen: September 3, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Spy.Agent.MG
Signature status: No Signature

Known Samples

MD5: d1e2f5de90c8c7f93c6ca9df9d484234
SHA1: 0c1dce19ac6a33946d6f400c8836d4953d1ad071
SHA256: 7FAB256991967E8D0DC102AE13ED258E27A783CEA661503DA3B7CC0C4F81D208
File Size: 9.63 MB, 9629184 bytes
MD5: 5ca474bfde0aa5b2819c531c2d982e21
SHA1: 14bc80490a8767c13fa13e53202ec6d239d3c655
SHA256: B64BB8349DF04AEFAAB0F200CBCF3100F69E866535AF4E9C23DCFF0DF20E6086
File Size: 9.26 MB, 9257984 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name NetGuard
File Description NetGuard
File Version 1.0.9
Product Name NetGuard
Product Version 1.0.9

File Traits

  • HighEntropy
  • No Version Info
  • ntdll
  • x64

Block Information

Total Blocks: 25,299
Potentially Malicious Blocks: 314
Whitelisted Blocks: 20,505
Unknown Blocks: 4,480

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 x 0 0 0 0 ? 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 x 0 x 0 x 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x ? 0 0 ? ? ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? ? ? ? ? 0 0 0 ? 0 x ? ? ? ? ? x ? ? ? 0 x ? 0 ? ? ? x 0 ? 0 x x 0 0 0 ? ? ? ? ? ? 0 ? 0 0 ? 0 ? 0 0 0 ? 0 ? 0 ? 0 ? 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 x 0 x 0 ? 0 ? ? ? 0 0 0 0 0 0 0 0 x ? 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 ? x 0 0 0 0 0 0 ? ? 0 ? ? 0 0 0 0 ? 0 ? 0 ? 0 0 ? 0 ? 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 ? ? 0 0 ? 0 0 0 ? 0 0 0 ? 0 0 0 ? 0 0 ? 0 0 ? 0 ? x ? x x x 0 x ? x 0 0 0 ? 0 0 0 ? 0 ? ? 0 ? 0 0 0 0 0 0 0 0 0 ? x x 0 0 ? ? ? x ? 0 0 ? 0 0 ? ? x x ? 0 0 0 0 0 ? 0 ? 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 ? ? 0 0 0 0 0 0 0 0 ? ? ? ? ? 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? 0 ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 ? 0 0 ? ? 0 0 0 ? 0 0 0 ? ? x ? x 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 ? 0 ? ? 0 0 ? ? 0 ? ? ? 0 0 0 0 0 0 0 ? ? 0 ? 0 0 ? 0 0 0 0 0 0 0 0 ? 0 0 ? 0 ? ? 0 0 ? 0 ? ? ? ? 0 0 ? ? 0 0 ? ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? ? 0 ? 0 0 0 ? ? ? ? ? 0 0 0 0 ? 0 ? 0 ? ? 0 0 0 ? 0 ? 0 ? ? 0 0 ? 0 ? ? ? ? ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? 0 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? 0 0 0 0 ? 0 0 0 0 ? 0 ? ? ? ? ? ? ? 0 0 ? ? 0 ? 0 ? ? ? ? ? ? ? ? 0 ? 0 0 ? ? ? ? ? ? ? ? ? 0 0 ? 0 0 0 ? 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? ? 0 ? ? ? ? 0 ? ? 0 0 ? ? 0 0 ? ? ? ? 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 ? ? 0 ? 0 0 ? ? 0 ? 0 ? 0 ? 0 0 0 0 0 x 0 ? 0 0 ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 ? 0 0 0 ? ? 0 ? ? ? 0 ? 0 0 0 0 ? ? ? ? ? ? ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 x ? ? ? ? ? 0 ? 0 0 0 ? ? 0 ? 0 ? ? ? ? ? 0 ? 0 0 0 0 ? ? 0 ? ? 0 0 0 0 ? ? 0 ? ? ? 0 0 0 ? ? ? ? ? ? ? ? 0 ? ? 0 0 0 ? 0 ? ? ? 0 0 ? 0 0 0 ? ? 0 ? 0 0 0 0 ? 0 ? 0 0 0 0 ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? 0 0 ? 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? 0 ? ? 0 ? ? ? ? ? 0 ? 0 ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? 0 ? 0 0 ? ? ? ? ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? 0 ? 0 ? 0 0 0 0 ? ? ? ? 0 x ? 0 ? ? ? ? ? ? ? 0 0 0 0 ? ? ? ? ? ? 0 0 0 ? ? 0 ? 0 ? ? ? ? ? 0 ? 0 0 0 ? ? ? 0 0 0 0 ? 0 x 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? x 0 ? ? 0 ? 0 0 0 0 0 ? 0 0 ? 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? ? 0 0 0 ? 0 0 0 ? 0 0 ? ? ? 0 ? ? ? ? 0 ? ? ? 0 ? 0 ? ? 0 ? ? 0 ? ? ? ? ? ? ? ? 0 ? 0 ? ? 0 ? ? ? ? ? 0 ? ? ? ? ? 0 ? 0 ? ? ? 0 ? 0 ? 0 ? 0 ? 0 0 ? ? ? 0 0 ? 0 0 ? 0 ? 0 0 0 ? ? ? 0 ? 0 0 ? ? ? ? ? ? ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 ? ? ? ? ? ? x ? ? 0 0 0 0 0 ? 0 ? 0 ? 0 0 ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 ? 0 0 ? 0 ? 0 ? 0 0 ? ? 0 ? ? ? x 0 ? ? ? 0 0 ? ? 0 0 0 x 0 0 0 0 ? 0 ? ? ? ? x 0 0 ? ? 0 ? ? 0 0 ? 0 0 ? ? ? 0 ? ? 0 ? ? 0 0 ? ? ? ? 0 0 ? ? ? ? ? 0 ? 0 0 0 0 0 0 ? 0 0 0 ? 0 0 0 ? ? ? ? 0 0 0 0 ? ? ? ? 0 0 ? ? ? ? 0 ? 0 ? ? ? ? ? 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 ? ? ? ? 0 ? ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? 0 ? 0 ? ? 0 ? ? ? ? ? 0 ? ? ? 0 0 ? ? 0 0 0 0 0 ? ? ? 0 0 0 ? ? ? ? ? ? ? ? 0 0 ? 0 0 ? ? ? 0 ? ? 0 0 0 0 0 0 0 ? ? ? ? 0 0 ? 0 ? 0 0 ? 0 0 ? ? 0 0 ? 0 ? 0 0 ? ? ? ? 0 ? ? ? ? ? ? x ? x ? ? ? ? 0 ? 0 0 ? ? ? ? ? 0 ? ? ? 0 ? 0 0 ? ? 0 ? ? ? 0 ? ? ? 0 ? ? ? ? ? ? 0 0 ? ? 0 ? 0 ? 0 0 0 0 0 ? ? ? 0 x 0 ? ? ? ? ? ? ? ? 0 0 ? ? 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.XFS

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheckByType
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcAcceptConnectPort
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreatePort
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcDeleteSecurityContext
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
Show More
  • ntdll.dll!NtAlpcSetInformation
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCompareSigningLevels
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtGetCachedSigningLevel
  • ntdll.dll!NtImpersonateAnonymousToken
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRemoveIoCompletionEx
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationObject
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetIoCompletion
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSetTimerEx
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTerminateProcess
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Other Suspicious
  • AdjustTokenPrivileges
Network Winsock2
  • WSAStartup

Shell Command Execution

C:\WINDOWS\system32\taskkill.exe "taskkill" /F /IM iTunes.exe
C:\WINDOWS\system32\taskkill.exe "taskkill" /F /IM iTunesHelper.exe
C:\WINDOWS\system32\taskkill.exe "taskkill" /F /IM 3uTools.exe
C:\WINDOWS\system32\taskkill.exe "taskkill" /F /IM iTools.exe
C:\WINDOWS\system32\taskkill.exe "taskkill" /F /IM AnyTrans.exe
Show More
C:\WINDOWS\system32\taskkill.exe "taskkill" /F /IM iMazing.exe
C:\WINDOWS\system32\taskkill.exe "taskkill" /F /IM iDeviceBackup2.exe