Trojan

Trojan.Keylogger.S25879104 (file analysis)

Malware Removal

The Trojan.Keylogger.S25879104 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Keylogger.S25879104 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Checks adapter addresses which can be used to detect virtual network interfaces
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • CAPE detected the Kutaki malware family
  • Anomalous binary characteristics

How to determine Trojan.Keylogger.S25879104?


File Info:

name: 9156AD371784D9D3639D.mlw
path: /opt/CAPEv2/storage/binaries/24c617f6c994a7a2f8520020365669fbd3cf5535f893118cefc39401394c2e15
crc32: 74B95F2C
md5: 9156ad371784d9d3639d617e52216f35
sha1: d83523bbbf918da1408faf0fb815456acb862b85
sha256: 24c617f6c994a7a2f8520020365669fbd3cf5535f893118cefc39401394c2e15
sha512: fe99810ee3d2c9c970ce30a3a619ab2890fc8024f77e57f9f6e0420d70da18ebd132f61db9623f9ca9815ed4488c955be7893cdd211dfebecf8413a45597a146
ssdeep: 24576:yB9gUkWYldr5HE+wS7aPK3v9oE3IfFAnQDgfmP/UDMS08Ckn31:2fkWk5cS7a+9XYaQsfmP/SA8Nl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10265D0139D044B43E41C97F47E131DB81BA67A0CAB82BBFB5412EEDB3E246215C5E52E
sha3_384: 1c75584e3da1f32347579d4aa459b049c5469fdd2bec9a7d2c7a891af5a2c27b3bb2f49497cfb5707e7e896ffb098af8
ep_bytes: 6864174000e8eeffffff000000000000
timestamp: 2022-07-17 10:52:39

Version Info:

Translation: 0x0409 0x04b0
CompanyName: KIDware
ProductName: Fun Visual Basic Projects
FileVersion: 1.00.0005
ProductVersion: 1.00.0005
InternalName: 1
OriginalFilename: 1.exe

Trojan.Keylogger.S25879104 also known as:

BkavW32.AIDetect.malware2
FireEyeGeneric.mg.9156ad371784d9d3
CAT-QuickHealTrojan.Keylogger.S25879104
CylanceUnsafe
Cybereasonmalicious.bbf918
BitDefenderThetaGen:NN.ZevbaF.34786.Cn0@amxbHQgi
CyrenW32/Keylogger.BD.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Spy.KeyLogger.ODN
KasperskyHEUR:Trojan-Spy.Win32.KeyLogger.gen
AvastWin32:Kutaki-A [Spy]
SophosML/PE-A
IkarusTrojan-Spy.Agent
JiangminTrojan.Generic.adrmt
AviraHEUR/AGEN.1239053
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataWin32.Trojan.PSE.BR8PEB
CynetMalicious (score: 100)
MalwarebytesMalware.AI.4196899708
APEXMalicious
RisingStealer.Kutaki!1.D278 (CLASSIC)
SentinelOneStatic AI – Malicious PE
FortinetW32/KeyLogger.ODN!tr
AVGWin32:Kutaki-A [Spy]
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Trojan.Keylogger.S25879104?

Trojan.Keylogger.S25879104 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment