Backdoor

About “Backdoor.Agent.WNAGen” infection

Malware Removal

The Backdoor.Agent.WNAGen is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Agent.WNAGen virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Starts servers listening on 127.0.0.1:0
  • Reads data out of its own binary image
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Arabic (Oman)
  • The binary likely contains encrypted or compressed data.
  • Looks up the external IP address
  • Executed a process and injected code into it, probably while unpacking
  • Exhibits behavior characteristics of HawkEye keylogger.
  • Steals private information from local Internet browsers
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

Related domains:

whatismyipaddress.com

How to determine Backdoor.Agent.WNAGen?


File Info:

crc32: 151C5869
md5: 5b778420b2b9800939481c390c01baf7
name: 5B778420B2B9800939481C390C01BAF7.mlw
sha1: 37a884469446e40d80e307c16f9ae4dec2359b82
sha256: ddca87e26162a0338131ea43bfaf069b9758852f2fcafbee42878d73312dace4
sha512: 6098ceda3229035cd79d05536e84187edd4ec8326ee8c28fdfa06ddec156b5e79fe3feae4a0070b05679eed15cdf1ecc5529b2d78c9cf12bfe4da0ee86b08f12
ssdeep: 12288:7dUM+tQfsoEt0Q30jLEApg/tVVDX2tFgq9V1WjrL:hgtJ30jLDG5DXU+q9ujr
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 Vraccc 2014
Assembly Version: 2.0.0.0
InternalName: Vraccc.exe
FileVersion: 2.0.0.0
CompanyName: Vraccc
LegalTrademarks: Vraccc
Comments: Vraccc
ProductName: Vraccc
ProductVersion: 2.0.0.0
FileDescription: Vraccc
OriginalFilename: Vraccc.exe

Backdoor.Agent.WNAGen also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.MSIL.Dropper.Z
FireEyeGeneric.mg.5b778420b2b98009
Qihoo-360Win32/Trojan.Dropper.97f
McAfeePWSZbot-FADS!5B778420B2B9
CylanceUnsafe
ZillyaTrojan.Inject.Win32.91148
SangforMalware
K7AntiVirusTrojan ( 700000121 )
BitDefenderTrojan.MSIL.Dropper.Z
K7GWTrojan ( 700000121 )
CyrenW32/S-c9fa8947!Eldorado
SymantecInfostealer.Limitail
TotalDefenseWin32/Tnega.cdBDJE
APEXMalicious
AvastMSIL:GenMalicious-APF [Trj]
KasperskyTrojan.MSIL.Inject.afnh
NANO-AntivirusTrojan.Win32.Zbot.dkmowl
Ad-AwareTrojan.MSIL.Dropper.Z
EmsisoftTrojan.MSIL.Dropper.Z (B)
ComodoTrojWare.MSIL.Zapchast.FR@5t9ww2
F-SecureHeuristic.HEUR/AGEN.1117402
DrWebTool.PassView.849
VIPRETrojan-Dropper.Win32.Nyu.z (v)
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
SophosMal/Generic-R + Troj/MSIL-AQN
IkarusTrojan-Spy.Agent
JiangminTrojanSpy.Zbot.egja
AviraHEUR/AGEN.1117402
MAXmalware (ai score=82)
Antiy-AVLTrojan[Dropper]/Win32.Sysn
MicrosoftTrojan:Win32/Malagent!gmb
ArcabitTrojan.MSIL.Dropper.Z
ZoneAlarmTrojan.MSIL.Inject.afnh
GDataTrojan.MSIL.Dropper.Z
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Limitail.R117429
BitDefenderThetaGen:NN.ZemsilF.34804.Am0@a4NoKVpG
ALYacTrojan.MSIL.Dropper.Z
VBA32TScope.Trojan.MSIL
MalwarebytesBackdoor.Agent.WNAGen
PandaTrj/Chgt.F
ESET-NOD32a variant of MSIL/Injector.FCQ
TencentMsil.Trojan.Inject.Sxop
YandexTrojan.Inject!+j38c8v7sTM
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetMSIL/Injector.FCQ!tr
AVGMSIL:GenMalicious-APF [Trj]
Cybereasonmalicious.0b2b98
Paloaltogeneric.ml

How to remove Backdoor.Agent.WNAGen?

Backdoor.Agent.WNAGen removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment