Trojan

Trojan.Win32.Agent.xahrpp (file analysis)

Malware Removal

The Trojan.Win32.Agent.xahrpp is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Agent.xahrpp virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Anomalous binary characteristics

How to determine Trojan.Win32.Agent.xahrpp?


File Info:

name: FB948A6EEC5B41E75DD7.mlw
path: /opt/CAPEv2/storage/binaries/622aa131abd98bdcc5dad1703488cc65c22cba62f2d3a1385aa8cd8ba1106058
crc32: 88CA4C05
md5: fb948a6eec5b41e75dd736fd51cf64e5
sha1: 58ee3cddc28652c009546eb457b3819f45b3d95b
sha256: 622aa131abd98bdcc5dad1703488cc65c22cba62f2d3a1385aa8cd8ba1106058
sha512: 26fbe1ac70720bd5cf8580cee68dcbd9cf2e04a8249488a7f62c1db5d63cfb7c8e422ac47ac32c540f1eeb9af4ece5353326fe7a354d2aeaa9292a173acf708d
ssdeep: 393216:cVjSEWiswe+h+DqGT/+cTQ30VUgB3ZyMnlFr7uVyNbxouVl:Yhfh+u2GcftB3ZyMnPOVyNVoGl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A0E63306E127C433C99105B58502DBF25D327C75A7B4E8EFAFC8797698242E2EA3534B
sha3_384: daf58b60a45b2d97d87fa97f650912a87949da03e27a3591a819e23060a6c6f99e6209d3ec0e392869154b2434c400f4
ep_bytes: e8a61d0000e989feffff8bff565733f6
timestamp: 2015-02-09 21:57:00

Version Info:

Comments: Created with Setup Factory
FileDescription: Setup Application
FileVersion: 9.5.0.0
InternalName: suf_launch
LegalCopyright: Setup Engine Copyright © 2004-2015 Indigo Rose Corporation
LegalTrademarks: Setup Factory is a trademark of Indigo Rose Corporation.
OriginalFilename: suf_launch.exe
ProductName: Setup Factory Runtime
ProductVersion: 9.5.0.0
Translation: 0x0409 0x04e4

Trojan.Win32.Agent.xahrpp also known as:

LionicTrojan.Win32.Agent.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.36951093
FireEyeTrojan.GenericKD.36951093
McAfeeArtemis!FB948A6EEC5B
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDownloader:Win32/Generic.92f8c0a0
K7GWTrojan-Downloader ( 005779501 )
K7AntiVirusTrojan-Downloader ( 005779501 )
ESET-NOD32Win32/TrojanDownloader.Agent.FNS
APEXMalicious
KasperskyTrojan.Win32.Agent.xahrpp
BitDefenderTrojan.GenericKD.36951093
AvastWin32:Trojan-gen
Ad-AwareTrojan.GenericKD.36951093
SophosMal/Generic-S
DrWebTrojan.PWS.Stealer.31026
VIPRETrojan.GenericKD.36951093
McAfee-GW-EditionBehavesLike.Win32.Dropper.vc
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.GenericKD.36951093 (B)
IkarusTrojan-Downloader.LUA.Agent
GDataTrojan.GenericKD.36951093
AviraTR/Dldr.Agent.intbg
MAXmalware (ai score=86)
ArcabitTrojan.Generic.D233D435
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
ALYacTrojan.GenericKD.36951093
RisingDownloader.Agent!8.B23 (CLOUD)
MaxSecureTrojan.Malware.118175769.susgen
FortinetW32/Agent.FNS!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.dc2865

How to remove Trojan.Win32.Agent.xahrpp?

Trojan.Win32.Agent.xahrpp removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment