Crack

HackTool:Win32/NSudo.A (file analysis)

Malware Removal

The HackTool:Win32/NSudo.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What HackTool:Win32/NSudo.A virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Appears to use command line obfuscation
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine HackTool:Win32/NSudo.A?


File Info:

name: EF24FDD075EE19D0BE45.mlw
path: /opt/CAPEv2/storage/binaries/b81048611402515ed6b0f482ab3635ebae86151be52e62c85d141af1d13008a8
crc32: C73272A4
md5: ef24fdd075ee19d0be45af5010e342e2
sha1: 8af7e4a538aadaa12e50264dbb9bb4c70c9bd018
sha256: b81048611402515ed6b0f482ab3635ebae86151be52e62c85d141af1d13008a8
sha512: 40157b49c93da5cebe81a498232b13681fd5386df380d4ed283f05247bc88fd890333a1cce65a3f2b679983bb346dd02a6b05aeb4868ca4e7fb8685a7a127dc2
ssdeep: 24576:sYIZj6UhqNuTpOawS7Fuu7pgRPpPZqIcSwnfXNDyDvU8T62vuSkd9yI6gwdLa:s96mqNuTpPZ7Fukpg9pPMIBwV2DRTMMa
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15475338E7781B104FB646970ED1717F28488FEA8B457A05706E43C5C7E7AE2CE4922F5
sha3_384: 9d88413469300bc5be4e4f7b8d91a35c06aebe597e25a1a8f96f15253080b942110e4d35303e4ad36ee167f2e4fa7754
ep_bytes: 60be00c041008dbe0050feff57eb0b90
timestamp: 2016-04-02 22:14:34

Version Info:

CompanyName: TSD-SOFT
LegalCopyright: (c) TSD-SOFT
LegalTrademarks: (c) TSD-SOFT
FileVersion: 1.3.1.0
ProductName: Windows Defender Tuner
ProductVersion: 1.3.1.0
InternalName: Windows Defender Tuner
FileDescription: Windows Defender Tuner
Created: 7z SFX Constructor v4.6.0.0 (http://usbtor.ru/viewtopic.php?t=798)
Builder: computersoft@abv.bg 08:42:38 26/03/2022
Translation: 0x0000 0x04b0

HackTool:Win32/NSudo.A also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
AVGWin32:Malware-gen
MicroWorld-eScanTrojan.GenericFCA.Agent.101253
FireEyeTrojan.GenericFCA.Agent.101253
McAfeeArtemis!EF24FDD075EE
MalwarebytesFloxif.Virus.FileInfector.DDS
ZillyaTool.Agent.Win32.16829
SangforHacktool.Win32.Nsudo.Ve15
K7AntiVirusTrojan ( 0051918e1 )
K7GWTrojan ( 0051918e1 )
CrowdStrikewin/grayware_confidence_70% (D)
VirITTrojan.Win32.Genus.LXF
CyrenW32/Trojan.DDEH-5647
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
CynetMalicious (score: 99)
BitDefenderTrojan.GenericFCA.Agent.101253
AvastWin32:Malware-gen
SophosNSUDO (PUA)
F-SecureHeuristic.HEUR/AGEN.1303929
VIPRETrojan.GenericFCA.Agent.101253
McAfee-GW-EditionRDN/Generic.grp
EmsisoftTrojan.GenericFCA.Agent.101253 (B)
GDataTrojan.GenericFCA.Agent.101253
AviraHEUR/AGEN.1303929
Antiy-AVLTrojan/Win32.Bluteal
XcitiumMalCrypt.Indus!@1qrzi1
ArcabitTrojan.GenericFCA.Agent.D18B85
MicrosoftHackTool:Win32/NSudo.A
GoogleDetected
ALYacTrojan.GenericFCA.Agent.101253
MAXmalware (ai score=82)
VBA32BScope.Trojan.SelfDel
Cylanceunsafe
FortinetW32/PossibleThreat
DeepInstinctMALICIOUS

How to remove HackTool:Win32/NSudo.A?

HackTool:Win32/NSudo.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment