Win32/Agent.XLN [Threat Name] go to Threat

Win32/Agent.XLN [Threat Variant Name]

Category trojan
Size 69632 B
Detection created Sep 09, 2015
Detection database version 12227
Short description

The trojan has a simple payload. The trojan is probably a part of other malware.

Installation

The trojan does not create any copies of itself.

Information stealing

The trojan collects the following information:

  • MAC address

The trojan attempts to send gathered information to a remote machine.

Other information

The trojan acquires data and commands from a remote computer or the Internet.


The trojan contains a list of (2) URLs. The HTTP protocol is used in the communication.


It can execute the following operations:

  • download files from a remote computer and/or the Internet
  • send requested files
  • send gathered information

The trojan may create the following files:

  • %temp%\­_233ad24.zip
  • %temp%\­_223we224.zip

The trojan may create the following folders:

  • %appdata%\­DevSet\­CK%variable%

A string with variable content is used instead of %variable% .


The trojan may delete the following files:

  • %temp%\­_233ad24.zip

Please enable Javascript to ensure correct displaying of this content and refresh this page.