Trojan

Trojan.Agent.ESMN (B) (file analysis)

Malware Removal

The Trojan.Agent.ESMN (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.ESMN (B) virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (4 unique times)
  • A process attempted to delay the analysis task.
  • Performs some HTTP requests
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to interact with an Alternate Data Stream (ADS)

Related domains:

iplogger.org
apps.identrust.com

How to determine Trojan.Agent.ESMN (B)?


File Info:

crc32: EC6B402E
md5: 2d96a06a5f3ee723f940ff0f4274a345
name: ATTN_08016_06112020.vbs
sha1: 475b9288dc2953ce6b9a2990350ab8ffea2ea103
sha256: a37287e8f80537b52b7bb63b76c4b33b210d6a75e9e2ab40844b8c47e7df700b
sha512: acc07b6db97a85a60c3d0018ddcedb4d9928167fc772f9c4c1d537bd9ad6896146715a1dc7106feb26204bd698afe90305c366bfc1fec8ec25a82ad5c027a177
ssdeep: 12288:IhsNDhaHDNhSPEClIgHWSksZstJVUteLhK/GX4Vbqgmwpr3HvNoMIbcrFc6PuTmp:N+N0PEQVeLc/GX4VbRvx3vVIbWvIHOhj
type: ASCII text, with very long lines, with CRLF line terminators

Version Info:

0: [No Data]

Trojan.Agent.ESMN (B) also known as:

ALYacTrojan.Agent.ESMN
BitDefenderTrojan.Agent.ESMN
MicroWorld-eScanTrojan.Agent.ESMN
Ad-AwareTrojan.Agent.ESMN
EmsisoftTrojan.Agent.ESMN (B)
FireEyeTrojan.Agent.ESMN
FortinetVBS/Agent.TLR!tr
ArcabitTrojan.Agent.ESMN
ZoneAlarmUDS:DangerousObject.Multi.Generic
MAXmalware (ai score=83)
IkarusTrojan.Agent
GDataTrojan.Agent.ESMN
Qihoo-360Generic/Trojan.a19

How to remove Trojan.Agent.ESMN (B)?

Trojan.Agent.ESMN (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment