Trojan

Trojan.AgentRI.S22827838 (file analysis)

Malware Removal

The Trojan.AgentRI.S22827838 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.AgentRI.S22827838 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Kazak
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Anomalous binary characteristics

How to determine Trojan.AgentRI.S22827838?


File Info:

name: 8740E3409B8FD2F6542B.mlw
path: /opt/CAPEv2/storage/binaries/a14a96554d527e64804f04ac2715abaca66a1af73c36e3b2da75d975b833026f
crc32: F9ACAE7C
md5: 8740e3409b8fd2f6542bdfdb2a9d3555
sha1: c1bd20daa211d8d0dde555c042812374ef6a89da
sha256: a14a96554d527e64804f04ac2715abaca66a1af73c36e3b2da75d975b833026f
sha512: eb2dfd33d90b1ac63bf1e759a02826087237ae29c3f4d7f75c21124bda539f271397ae935a26ecf155ce9efbd1a2c3d742eae6a9bec5836e8ad1929485abb01e
ssdeep: 6144:1+v74h5AdjXilSnhlsKH17V7SdLPH8d/Nz:8705ApSlOsKH17ZSxEp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10B548C30AAA1C035F9F211F849BA83BDA5393AB16B3440CF53E51AF956386E5EC30757
sha3_384: 6fc6b8d55ffe155af49bcf91100d522ddf7599791908af98ae72f5e8a24022f0369c70fff11230ee91458be061d9dddd
ep_bytes: 8bff558bece8a6980000e8110000005d
timestamp: 2020-04-02 04:54:02

Version Info:

Translation: 0x120a 0x052e

Trojan.AgentRI.S22827838 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.77336
FireEyeGeneric.mg.8740e3409b8fd2f6
CAT-QuickHealTrojan.AgentRI.S22827838
McAfeePacked-GDT!8740E3409B8F
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00588c321 )
BitDefenderTrojan.GenericKDZ.77336
K7GWTrojan ( 00588c321 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.34182.rqX@amTFA2gG
CyrenW32/Kryptik.EYC.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HMFH
APEXMalicious
ClamAVWin.Dropper.Brook-9888361-0
KasperskyHEUR:Trojan.Win32.Agent.gen
RisingTrojan.Kryptik!1.D9C0 (RDMK:cmRtazrJHZBAI9oCPZqQRdFEUcvj)
EmsisoftTrojan.Crypt (A)
DrWebTrojan.DownLoader41.29278
McAfee-GW-EditionBehavesLike.Win32.PUPXAA.dh
SophosML/PE-A + Mal/EncPk-AQE
IkarusTrojan.Win32.Crypt
AviraHEUR/AGEN.1144907
MAXmalware (ai score=81)
Antiy-AVLTrojan/Generic.ASMalwS.347B8DD
MicrosoftRansom:Win32/StopCrypt.MGK!MTB
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
GDataTrojan.GenericKDZ.77336
CynetMalicious (score: 100)
AhnLab-V3CoinMiner/Win.Glupteba.R438825
VBA32Malware-Cryptor.Azorult.gen
ALYacTrojan.GenericKDZ.77336
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
YandexTrojan.Agent!ecSxoAIr4Zk
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.HMGB!tr
AVGWin32:BotX-gen [Trj]
Cybereasonmalicious.aa211d
AvastWin32:BotX-gen [Trj]

How to remove Trojan.AgentRI.S22827838?

Trojan.AgentRI.S22827838 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment