Trojan

What is “Trojan.Toga.26592”?

Malware Removal

The Trojan.Toga.26592 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Toga.26592 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Starts servers listening on 0.0.0.0:6634
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings

How to determine Trojan.Toga.26592?


File Info:

name: C6D8BCAA8C8618A1148F.mlw
path: /opt/CAPEv2/storage/binaries/178fc6c7aca98a8832c6ffcbb2039fbd3fd0a29ae6a98b66e2be4d5e7a31c9a1
crc32: F0308EB8
md5: c6d8bcaa8c8618a1148f733e1df00da9
sha1: 412e0e0f24b9df6c244b29b5b4dc281abcb1ae38
sha256: 178fc6c7aca98a8832c6ffcbb2039fbd3fd0a29ae6a98b66e2be4d5e7a31c9a1
sha512: ba95c11f97453a27eb7e98c1c6edf6fbaeefc27e2112db3fea6d7167954ee78284525ea62e4c7ab1e00dd228b64dea1c9c02d033f84fbb49f458e5685c18f6d5
ssdeep: 12288:Cb5syS5Z5Z5sy/yS5Z5Z5Z5B+G5Z5Z5BM5Z5Z5Z5Z5Z5Z5Z5Z5syS5Z5Z5Z5Z5s6:QeaSgmaaaaaa2a7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18F45024AF5ECAB61E9273CF6E2CD6540857712990F042522F69733A2612ED33D1FD28E
sha3_384: 6ad8b5cc56a645ddc7d9ece25524b749372c1fce570c021feb40d60c3b3d1c2e258e04667673ea082b493d661c664376
ep_bytes: 60be007057018dbe00a0e8fe5783cdff
timestamp: 2008-04-02 18:32:48

Version Info:

0: [No Data]

Trojan.Toga.26592 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Crypt.AS
FireEyeGeneric.mg.c6d8bcaa8c8618a1
CAT-QuickHealTrojan.Toga.26592
McAfeeObfuscated-FPR!hb
CylanceUnsafe
ZillyaWorm.Socks.Win32.544
SangforSuspicious.Win32.Save.a
K7AntiVirusEmailWorm ( 0003ef7f1 )
K7GWEmailWorm ( 0003ef7f1 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Crypt.AS
VirITTrojan.Win32.Generic.WQH
CyrenW32/Socks.A.gen!Eldorado
SymantecTrojan.Dropper
ESET-NOD32a variant of Win32/Socks.NAJ
APEXMalicious
ClamAVWin.Worm.Socks-7102088-0
KasperskyTrojan-Ransom.Win32.Blocker.jaty
BitDefenderTrojan.Crypt.AS
NANO-AntivirusTrojan.Win32.Socks.crakqx
AvastWin32:Injecter-AT [Trj]
TencentMalware.Win32.Gencirc.10cfe5a7
Ad-AwareTrojan.Crypt.AS
EmsisoftTrojan.Crypt.AS (B)
DrWebTrojan.KillFiles.13123
VIPREP2P-Worm.Win32.Socks.g (fs)
TrendMicroTROJ_SPNR.30CU14
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
SophosML/PE-A + Troj/Scrub-Gen
IkarusWorm.Win32.Socks
JiangminTrojan.Blocker.igh
AviraTR/Drop.Agent.snv
Antiy-AVLTrojan/Win32.AGeneric
MicrosoftTrojan:Script/Phonzy.C!ml
ZoneAlarmTrojan-Ransom.Win32.Blocker.jaty
GDataTrojan.Crypt.AS
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Socks.R76979
Acronissuspicious
BitDefenderThetaAI:Packer.57E0A16A1B
ALYacTrojan.Crypt.AS
MAXmalware (ai score=88)
VBA32BScope.Worm.Socks.afv
MalwarebytesMalware.AI.3417656905
TrendMicro-HouseCallTROJ_SPNR.30CU14
RisingRansom.Blocker!8.12A (RDMK:cmRtazpHJwoAhVIEwXKS6GWwgpEh)
YandexWorm.Socks!kTEylFde0kc
SentinelOneStatic AI – Malicious PE
FortinetW32/Generic.AC.209E!tr
AVGWin32:Injecter-AT [Trj]
Cybereasonmalicious.a8c861

How to remove Trojan.Toga.26592?

Trojan.Toga.26592 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment