Trojan

Trojan-Downloader.Win32.Agent.xxzuin malicious file

Malware Removal

The Trojan-Downloader.Win32.Agent.xxzuin is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Agent.xxzuin virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Scheduled file move on reboot detected
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Attempts to remove evidence of file being downloaded from the Internet
  • Deletes its original binary from disk
  • Collects and encrypts information about the computer likely to send to C2 server
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify Windows Defender using PowerShell

Related domains:

wpad.local-net

How to determine Trojan-Downloader.Win32.Agent.xxzuin?


File Info:

name: 66EB53B404B7E18D5EB6.mlw
path: /opt/CAPEv2/storage/binaries/ba154c21d0f1585de8f6389fc1bffad5c6b30edf9492e460002536f1c32e0f68
crc32: E7EE41B3
md5: 66eb53b404b7e18d5eb642eb3dcf82e3
sha1: 65436f5de6d39df0cfd48f258493a2d2a3162923
sha256: ba154c21d0f1585de8f6389fc1bffad5c6b30edf9492e460002536f1c32e0f68
sha512: 6e6ea5411df557a69b8ac28684d546428aef27426527438c97fde8d5d626ff9f65b2f508dad36e0f4fb212b7f87fe0b54eb56c1058ae04454bab3b3e2e4960eb
ssdeep: 49152:ACwvzxjqCsgDPGVQy/XzfZ6XT78Ch9C0JeZPLAcD84/:c1qCDDuVX/XzfZ6XEChzJeW0
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T1048533E6B3536BABF2A4D6FC3963148177B1F076814A894DB301CB43C2A75C90A71F66
sha3_384: 65b10acae82f964b111bd02ff624b2b66cfb40e6a422036aead9d19d9f2c31dd6c746fedebf2f76934f53c1ed3957ed4
ep_bytes: 53565755488d353a4ee4ff488dbedb9f
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan-Downloader.Win32.Agent.xxzuin also known as:

LionicTrojan.Win32.Generic.4!c
DrWebTrojan.MulDrop19.4395
MicroWorld-eScanTrojan.GenericKDZ.79917
FireEyeTrojan.GenericKDZ.79917
ALYacTrojan.GenericKDZ.79917
MalwarebytesTrojan.Dropper
K7AntiVirusTrojan ( 005897a81 )
AlibabaTrojanDownloader:Win32/Redcap.97f79e68
K7GWTrojan ( 005897a81 )
Cybereasonmalicious.de6d39
ESET-NOD32a variant of WinGo/Agent.CT
TrendMicro-HouseCallTROJ_GEN.R002H09KN21
Paloaltogeneric.ml
KasperskyTrojan-Downloader.Win32.Agent.xxzuin
BitDefenderTrojan.GenericKDZ.79917
AvastFileRepMalware
TencentWin32.Trojan.Generic.Wrhb
Ad-AwareTrojan.GenericKDZ.79917
EmsisoftTrojan.GenericKDZ.79917 (B)
McAfee-GW-EditionBehavesLike.Win64.Trickbot.tc
SophosGeneric ML PUA (PUA)
IkarusTrojan.WinGo.Agent
GDataTrojan.GenericKDZ.79917
AviraTR/Redcap.hmnmd
Antiy-AVLTrojan/Generic.ASBOL.C5E3
GridinsoftRansom.Win64.Sabsik.sa
ArcabitTrojan.Generic.D1382D
ViRobotTrojan.Win32.Z.Agent.1817088.B
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R451137
MAXmalware (ai score=83)
APEXMalicious
SentinelOneStatic AI – Suspicious PE
FortinetW32/Agent.CT!tr
AVGFileRepMalware
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Trojan-Downloader.Win32.Agent.xxzuin?

Trojan-Downloader.Win32.Agent.xxzuin removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment