威胁数据库 特洛伊木马 特洛伊木马代理DNA

特洛伊木马代理DNA

Trojan.Agent.DNA是一个检测名称,用于识别木马恶意软件家族中的一种成员。被归类为“Agent”的威胁通常具有一些共同的恶意特征,但在具体有效载荷或用途上可能有所不同。与大多数木马一样,Trojan.Agent.DNA 的设计目的是在伪装成合法或无害程序的同时渗透计算机,使用户难以识别危险,直到损害已经发生。

Trojan.Agent.DNA 的作用

虽然每个样本的具体行为可能有所不同,但此类检测类别中的威胁通常会在受感染系统的后台静默运行。一般来说,此类木马程序可用于执行以下一项或多项操作,这也是此类恶意软件的典型特征:

  • 在受感染的设备上下载并安装其他恶意文件或程序
  • 收集敏感信息,例如登录凭证、浏览习惯或系统数据
  • 修改系统设置或安全配置以削弱计算机的防御能力
  • 建立与远程服务器的连接,使攻击者能够发出命令或窃取数据。
  • 创建后门访问权限,该访问权限可能被利用进行进一步攻击。

由于木马程序不像病毒或蠕虫那样能够自我复制,Trojan.Agent.DNA 依靠欺骗用户或利用安全漏洞来获得系统立足点。

它通常是如何进入电脑的

这类木马程序通常通过欺骗手段而非直接攻击进行传播。典型的感染途径包括恶意电子邮件附件、虚假软件更新、破解或盗版软件、来自不可信网站的捆绑下载以及嵌入在钓鱼邮件中的链接。用户可能在不知不觉中安装了木马程序,误以为自己正在下载合法的程序、文档或媒体文件。

用户面临的风险

Trojan.Agent.DNA 感染可能使用户面临一系列严重风险。这些风险包括个人或财务信息被盗、设备遭到未经授权的访问、系统性能下降,以及可能安装其他恶意软件,例如勒索软件、间谍软件或广告软件。在某些情况下,受感染的系统可能被攻击者利用,成为其控制的更大规模受感染计算机网络的一部分。

感染迹象

由于木马程序旨在隐蔽运行,因此感染迹象并不总是显而易见。但是,用户可能会注意到一些异常症状,例如系统运行速度变慢、意外崩溃、后台运行着陌生的程序或进程、未经许可更改浏览器或系统设置、网络活动异常增多,或者安全工具被意外禁用。

如何做好防护

为了降低遭遇 Trojan.Agent.DNA 等威胁的风险,用户应避免从未经核实的来源下载软件,不要打开未知或可疑电子邮件中的附件或链接,并及时更新操作系统和应用程序,安装最新的安全补丁。定期进行系统扫描、备份重要数据以及谨慎安装免费或捆绑软件也有助于预防感染。了解用于传播木马的常见社会工程攻击手段是避免成为此类威胁受害者的最有效方法之一。

分析报告

一般信息

姓: Trojan.Agent.DNA
签名状态: Hash Mismatch

已知样本

MD5: 9cc15853a120e8b984bef3aba27600cc
SHA1: 2b1a5e1a5cd268525fb37da5dbd2e88c03a41a75
SHA256: 830BC700AB043B4801BAE79E7C4B076EA7AE9C0C6298D63F9AD06B3BD6007C75
文件大小: 132.80 KB,132800字节

Windows 可移植可执行文件属性

  • File doesn't have "Rich" header
  • File doesn't have resources
  • File has exports table
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

数字签名

签名者 根 地位
LY Corporation GlobalSign Code Signing Root R45 Hash Mismatch
LY Corporation GlobalSign Code Signing Root R45 Hash Mismatch

文件特征

  • dll
  • x64

区块信息

总区块数: 402
潜在恶意块: 11
白名单区块: 391
未知区块: 0

可视化地图

x x x x x x x 0 x x x 0 0 0 0 0 x 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 2 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1
0 - 可能的保险箱
? - 未知区块
x - 潜在恶意拦截

相似家庭

  • Trojan.Agent.Gen.FDJ
  • Trojan.Downloader.Gen.APZ
  • Trojan.Downloader.Gen.AQO
  • Trojan.Downloader.Gen.ARB
  • Trojan.Kryptik.Gen.JWZ
显示更多
  • Trojan.ShellcodeRunner.Gen.YR

Windows API 使用情况

类别 API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
显示更多
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtQueryWnfStateNameInformation
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetSystemInformation
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtUpdateWnfStateData
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN