Trojan

Dropped:Trojan.Agent.FOIJ malicious file

Malware Removal

The Dropped:Trojan.Agent.FOIJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dropped:Trojan.Agent.FOIJ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • At least one process apparently crashed during execution
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Starts servers listening on 127.0.0.1:0
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Checks for the presence of known windows from debuggers and forensic tools
  • Checks for the presence of known windows from debuggers and forensic tools
  • Created a process from a suspicious location
  • Collects and encrypts information about the computer likely to send to C2 server
  • Network activity contains more than one unique useragent.
  • A script process created a new process
  • Creates a hidden or system file
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Appears to use command line obfuscation
  • Deletes executed files from disk
  • Attempts to disable Windows Defender
  • Attempts to modify Windows Defender using PowerShell
  • Attempts to execute suspicious powershell command arguments
  • Uses suspicious command line tools or Windows utilities

How to determine Dropped:Trojan.Agent.FOIJ?


File Info:

name: BEEAE0294566A823CC4B.mlw
path: /opt/CAPEv2/storage/binaries/7af33e5528ab8a8f45ee7b8c4dd24b4014feaa6e1d310458fdc53f95ea9f8a04
crc32: 8D9CCB2C
md5: beeae0294566a823cc4b40d6a006b374
sha1: 2b3fd709aa60c1b436c4a2b4c90bf4bd93fee2de
sha256: 7af33e5528ab8a8f45ee7b8c4dd24b4014feaa6e1d310458fdc53f95ea9f8a04
sha512: fa24cb18729dd33deb1cf3324e64e47be5dca54f074ca096b8de81149ed6a2554df3286001fb920941af0dca942ed49162a2a02bef8031ae50715eddea4b95d3
ssdeep: 98304:xC3f/VR9BFRmo5DdNX00Lx33rOwvdfZBazR4Nypgv7nzNv:xOxxXtPx37OwvdfZkROypgvlv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BF1633107CF180F9C24143B0A9ADBBBA68F6C79A5E31189B33A4960A577F125D23D3B5
sha3_384: e8a62dc4cdc2f91b5722df8ccc85c3a82a49c510161f852ecb29be357763f442a3d94099fb6b5c5e4a40759017f73430
ep_bytes: 558bec6aff6898c24100680691410064
timestamp: 2019-02-21 16:00:00

Version Info:

CompanyName: Igor Pavlov
FileDescription: 7z Setup SFX
FileVersion: 19.00
InternalName: 7zS.sfx
LegalCopyright: Copyright (c) 1999-2018 Igor Pavlov
OriginalFilename: 7zS.sfx.exe
ProductName: 7-Zip
ProductVersion: 19.00
Translation: 0x0409 0x04b0

Dropped:Trojan.Agent.FOIJ also known as:

BkavW32.AIDetect.malware2
LionicTrojan.MSIL.Mokes.m!c
Elasticmalicious (high confidence)
MicroWorld-eScanDropped:Trojan.Agent.FOIJ
FireEyeDropped:Trojan.Agent.FOIJ
CAT-QuickHealPUA.GenericRI.S23914449
ALYacSpyware.Infostealer.RedLine
CylanceUnsafe
VIPREDropped:Trojan.Agent.FOIJ
SangforTrojan.Win32.Agent.ADMG
K7AntiVirusTrojan-Downloader ( 00588d291 )
AlibabaTrojanDownloader:Win32/Fabookie.1c39ce3e
K7GWTrojan-Downloader ( 00588d291 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Zusy.JB.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
Paloaltogeneric.ml
ClamAVWin.Dropper.Pswtool-9857535-0
KasperskyTrojan-Downloader.Win32.Agent.xxzyfy
BitDefenderDropped:Trojan.Agent.FOIJ
NANO-AntivirusTrojan.Win32.jelcax.jmrekk
AvastWin32:DropperX-gen [Drp]
TencentWin32.Trojan.Multiple.Plaw
Ad-AwareDropped:Trojan.Agent.FOIJ
SophosMal/Generic-S
ComodoMalware@#1ah8tv4y99ulh
DrWebTrojan.Siggen15.30735
TrendMicroBackdoor.Win32.MOKES.USASHK921
McAfee-GW-EditionGenericRXRL-RI!432C488C6AB4
EmsisoftDropped:Trojan.Agent.FOIJ (B)
SentinelOneStatic AI – Suspicious PE
GDataDropped:Trojan.Agent.FOIJ
JiangminTrojan.Zapchast.rz
AviraHEUR/AGEN.1213193
MAXmalware (ai score=82)
Antiy-AVLTrojan/Generic.ASMalwS.2D
KingsoftWin32.Troj.Undef.(kcloud)
ZoneAlarmHEUR:Trojan-Downloader.MSIL.ShortLoader.gen
MicrosoftTrojan:Win32/Azorult.RF!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4803571
Acronissuspicious
McAfeeArtemis!BEEAE0294566
VBA32BScope.TrojanRansom.FileCryptor
MalwarebytesTrojan.Downloader
TrendMicro-HouseCallBackdoor.Win32.MOKES.USASHK921
RisingTrojan.Starter!1.DDB6 (CLASSIC:Ri3CbxMtLzSurGcpNdboMA)
YandexTrojan.Chapak!upHE4H+uK6w
IkarusTrojan-Downloader.Win32.Agent
MaxSecureTrojan.Malware.73643692.susgen
FortinetW32/Agent.FXP!tr.dldr
BitDefenderThetaGen:NN.ZexaF.34806.zu0@ayo9qehO
AVGWin32:DropperX-gen [Drp]
Cybereasonmalicious.94566a
PandaTrj/CI.A

How to remove Dropped:Trojan.Agent.FOIJ?

Dropped:Trojan.Agent.FOIJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment