Trojan

About “Dropped:Trojan.Agent.FTMN (B)” infection

Malware Removal

The Dropped:Trojan.Agent.FTMN (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dropped:Trojan.Agent.FTMN (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Checks for the presence of known windows from debuggers and forensic tools
  • Created a process from a suspicious location
  • Steals private information from local Internet browsers
  • Collects and encrypts information about the computer likely to send to C2 server
  • Network activity contains more than one unique useragent.
  • Stack pivoting was detected when using a critical API
  • Creates a hidden or system file
  • CAPE detected the DLInjector03 malware family
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • CAPE detected injection into a browser process, likely for Man-In-Browser (MITB) infostealing
  • Attempts to disable Windows Defender
  • Attempts to modify Windows Defender using PowerShell
  • Harvests cookies for information gathering
  • Attempts to execute suspicious powershell command arguments
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities

How to determine Dropped:Trojan.Agent.FTMN (B)?


File Info:

name: 20D6E9FBD3CBF1A6E841.mlw
path: /opt/CAPEv2/storage/binaries/ff7e2160fa0f7546ce4777008bfab70e4a8fb4ff5d99d8ec97be7f035947faae
crc32: A47C9825
md5: 20d6e9fbd3cbf1a6e841097f6bdb2523
sha1: 706fa2f8112ea145c29de56fddb5c58107c9f8ca
sha256: ff7e2160fa0f7546ce4777008bfab70e4a8fb4ff5d99d8ec97be7f035947faae
sha512: 5065c469e98f66b3cdb20a96654db1b5e6fa843f1ad7837e319e6cf955f4df3203e1299d463a99e748f4a7fee13a7dae7ef236c33e51f387274a74de991feab8
ssdeep: 196608:JAWs/KATCExRZN73DUNj5p+5HFS08h56aH+KsW4glk5vSU:JBsKEx3NDEL4tGHeKsWbk56U
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1659633A46DBCD0C6E635B4B9BB2C3896C45B8C4A76EC0BF85F52EC96682314547D3332
sha3_384: 6ac4bebe06f9988b4c76436ecfa03ad9677632c6baa929a615d117076851005c2fe94200b80ecb4332479d59474fe157
ep_bytes: 81ecd40200005356576a205f33db6801
timestamp: 2020-08-01 02:44:18

Version Info:

0: [No Data]

Dropped:Trojan.Agent.FTMN (B) also known as:

tehtrisGeneric.Malware
MicroWorld-eScanDropped:Trojan.Agent.FTMN
CAT-QuickHealTrojan.Meretam
BitDefenderDropped:Trojan.Agent.FTMN
Cybereasonmalicious.bd3cbf
CyrenW32/MSIL_Kryptik.GUN.gen!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32multiple detections
APEXMalicious
ClamAVWin.Dropper.Pswtool-9857487-0
KasperskyTrojan.Win32.Agentb.ktpi
NANO-AntivirusTrojan.Win32.Zapchast.jkxuvd
AvastWin32:Malware-gen
RisingDropper.Agent/NSIS!1.D805 (CLASSIC:cmRtazoFHABn4jjLTdE)
SophosTroj/Krypt-FV
ComodoMalware@#3ueak0jaft5c7
F-SecureHeuristic.HEUR/AGEN.1210138
DrWebTrojan.Siggen17.45837
TrendMicroTROJ_GEN.R031C0PBS22
McAfee-GW-EditionBehavesLike.Win32.Generic.rc
FireEyeGeneric.mg.20d6e9fbd3cbf1a6
EmsisoftDropped:Trojan.Agent.FTMN (B)
IkarusTrojan.Agent
GDataDropped:Trojan.Agent.FTMN
AviraHEUR/AGEN.1210138
MAXmalware (ai score=88)
Antiy-AVLTrojan/Generic.ASMalwS.3535610
KingsoftWin32.Troj.Generic_a.a.(kcloud)
ArcabitTrojan.Agent.FTMN
ZoneAlarmHEUR:Trojan.Win32.Zapchast.gen
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
Acronissuspicious
BitDefenderThetaGen:NN.ZexaCO.34606.b8Wba4NBA3m
ALYacDropped:Trojan.Agent.FTMN
VBA32CIL.StupidPInvoker-1.Heur
MalwarebytesTrojan.Crypt
TrendMicro-HouseCallTROJ_GEN.R031C0PBS22
FortinetMalicious_Behavior.SB
AVGWin32:Malware-gen
CrowdStrikewin/grayware_confidence_60% (D)

How to remove Dropped:Trojan.Agent.FTMN (B)?

Dropped:Trojan.Agent.FTMN (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment