Trojan

TrojanDownloader:Win32/Cutwail (file analysis)

Malware Removal

The TrojanDownloader:Win32/Cutwail is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Cutwail virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (19 unique times)
  • Network activity contains generic phishing indicators indicative of a website clone.
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Attempts to modify proxy settings
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
smtp.live.com
tutuji-saitama.com
thedonaldsongroup.com
bigjohnsbeefjerky.com
capitalcitytuxedo.com
merceorti.com
manuyantralaya.com
wsipowerontheweb.com
sortedorganizing.com
mandi-man.com
vanguardpkg.com
woodlandhillwinery.com
goodvaluecenter.com
agence-des-druides.com
slcago.org
floridadoubled.com
enzoyrodrigo.com.br
s2s.fr
shs-sales.co.uk
gjk.com.pl
adultlivechat.us
fraser-high.school.nz
gablemarine.com
rewardhits.com
tavdi.com
fleshercorp.com
audience-web.net
nazcapictures.com
mojacar-vacaciones.com
racknstackwarehouse.com.au
www.hugedomains.com
e-shuukyaku.com
link-list-uk.com
topex.ro
arckepesajandek.hu
al-mawared.com
hartmultimedia.com
wlf.louisiana.gov
djkentaro.com
www.buyukshop.com
www.tutuji-saitama.com
eleterno.com
automa.it
upsilon89.com
www.wlf.louisiana.gov
kafrit.com
chocolatecovers.com
youjoomla.com
theartofhair.com
stormwildlifeart.com
djkentaro.jp
vitalur.by
kamaruka.vic.edu.au
sgprinting.ca
vbwgz.com
hoyuu.com
www.sgprintinginc.com
structives.org
tss.org
muxearileiju.kz
kebvadcug.kz
padwuqanke.kz
kebfufrur.kz
xeseosograc.kz
iaiglobal.or.id
spiti.org
tvndra.net
photoclubs.com
digpro.se
www.spiti.org
www.photoclubs.com
digpro.com
ans-service.com
kaufthal.com
servico-ind.com
leadershipforum.us
robertmcintyre.com.au
timeturkey.com
bigtopmultimedia.com
murnufbos.kz
bumitgovadf.kz
qufqosgit.kz
bimgursek.kz
jeogeajixf.kz
bigtopmultimedia.net
ocsp.digicert.com
a.tomx.xyz
paulrenna.com
istanbultarim.com.tr
frederickallergy.com
heliomare.nl
www.heliomare.nl
www.istanbultarim.com.tr
x.ss2.us
celebikalip.com.tr
fruitspot.co.za
apps.identrust.com
asterisk.com.sg
trinity-works.com
orion-networks.net
mastechn.com
vuvimforebx.kz
rijofimdalz.kz
doqsogkoqm.kz
sekhogjuci.kz
qixzeiqan.kz
freepatentauction.com
www.patentauction.com
ginalimo.com
skaner.com.pl
ompgp.co.jp
myfilecenter.com
www.ompgp.co.jp
www.lucion.com
www.filecenterdms.com
muzulelufvos.kz
jogpiseada.kz
xadpadpecp.kz
cogvoqduje.kz
hoqcahocur.kz
sun-ele.co.jp
ocsp.usertrust.com
isp-h.com
crl4.digicert.com
crl3.digicert.com
fastarchofamerica.com
unslp.edu.bo
tollefsondesign.com
penavision.co.in
avisay.com
gofekwadveo.kz
huxedeowuzra.kz
cabooseonline.com
cozizeocapi.kz
sosnoqvim.kz
pebpilanq.kz
dbcomponents.com
shakeyspizza.ph
www.shakeyspizza.ph
bocr.cz
atr-technologies.com
4pipp.com
wimlumimea.kz
kitmirall.kz
xibufwadpebc.kz
deanudimho.kz
rursekpij.kz
violadagamba.com
berkshirebusiness.org
malagacorp.com
crl.usertrust.com
ocsp.sectigo.com
pixemia.com
geixawosi.kz
xalpofech.kz
zadriqitz.kz
gofixfixruz.kz
duqdoqcitd.kz
stepnet.de
www.stepnet.de
rea-soft.ru
ligannixdud.kz
heamaljeoru.kz
goqesosseks.kz
dukaqifecqul.kz
jogfekzadn.kz
doctsf.com
www.doctsf.com
coe.pku.edu.cn
dukekitloga.kz
junecxecogw.kz
huzsanjeij.kz
meaxiroheoz.kz
moqicitcuqur.kz
midwestga.com
dithd.com
wildrosemarketing.com
mikuveivuzci.kz
cujuzosanxi.kz
qukalbadzov.kz
zivuzqugobad.kz
kuzwunoqpe.kz
meridies.org
iktus.fr
toutenmeuse.com
status.rapidssl.com
cdp.rapidssl.com
www.iktus.fr
www.toutenmeuse.com
nuritech.com
risaxeawecvi.kz
mirogjaqogse.kz
huzfaguvoq.kz
wimcoswebp.kz
bixbeigowu.kz
csmbc.org
impex.com.pl
mail57.us2.mcsv.net
fujino-lab.com
rurmebwal.kz
wunaladvimmo.kz
duqcidimgi.kz
kakefadnofi.kz
dujeicuzakoq.kz
rueggeberg.com
www.pferd.com
isrg.trustid.ocsp.identrust.com
www.traderush.com
justconnect.co.za
gcs-cpa.com
www.gcs-cpa.com
paintball.be
buzzkillmedia.com
telenavis.com
plus.ba
xeveipolipoh.kz
curbeipoqo.kz
lobuheowike.kz
pecwijanli.kz
citlixkeka.kz
eurasia.it
austriansurfing.at
graintrain.coop
ibcd.com.br
www.austriansurfing.at
kvadratoff.ru
cath4choice.org
easyformations.net
www.ltd-companies.co.uk
childscope.com
empordalia.com
www.empordalia.com
wkhk.net
gipebfufzei.kz
vibeawojitko.kz
puzmurwoq.kz
deamalvuva.kz
siguwopimno.kz
optiver.com.au
korta-sa.com
neurotoxininstitute.com
beechwoodmetalworks.com
naijagurus.com
meubles-jacquelin.com
safetyconnection.ca
ricated.com
lockerlookz.com
ocsp.int-x3.letsencrypt.org
shipeliteexpress.com
minatech.net
www.beechwoodmetalworks.com
zoveikezixeq.kz
puqekbufvufg.kz
palqoskej.kz
qanoheanoqj.kz
jojanqixbeo.kz
www.meubles-jacquelin.com
ajdo.net
bethisraelcenter.org
teasing-video.com
unitedearthgroup.com
selldoor.pl
krafthaus.com
survey-smiles.com
schiedel.it
sigmametalsinc.com
miltinio-teatras.lt
ww1.survey-smiles.com
www.schiedel.com
ziuabarbatului.ro
ocsp.godaddy.com
nd-evenementiel.com
nataliecurtiss.com
ruzgurfigu.kz
seozusogsek.kz
vimgohitw.kz
boqxoqman.kz
nixkiqarej.kz
choice-select.com
perc.ca
e-storming.com
www.e-storming.com
thesergery.com
biurimex.pl
brijindia.com
mastergrp-spb.ru
avant-ime.com
hinnenwiese.de
ripadboswebr.kz
fixalbiqali.kz
heoxalzan.kz
badsosveoc.kz
bufnumobuv.kz
mattiussiecologia.com
jeangatz.com
www.mattiussiecologia.com
ryumachi-jp.com
bimvikurg.kz
qanqegurzo.kz
rurwuzkoq.kz
zeocekoglan.kz
fecvixeal.kz
audio-direkt.net
authentica-travel.com
sarpy.com
crl.godaddy.com
x-cellcommunications.de
lognetic.com
geothermusa.com
sztartufi.com
chscreative.com
www.chs.agency
xing-group.com
qiqacogjogse.kz
jitnosgalj.kz
malvifolan.kz
kuzbidaduq.kz
malwimqaba.kz
westhillsstl.org
urayasu.net
kagu-hokuren.com
trenpalau.com
lexjuridica.com
www.kagu-hokuren.com
cedagufaxoqm.kz
vadfosmeav.kz
qufecbeiwuz.kz
murjirebh.kz
heijeijocurj.kz
ocsp.comodoca.com
crl.comodoca.com
padstow.com
acmepacificrepairs.com
taykon.com
curpebgobu.kz
kedapadxufri.kz
wimhanixja.kz
heijogvosjei.kz
himlufhuzk.kz
macgregor.co.kr
jahulufjogb.kz
pebcikuzj.kz
sekqufwecp.kz
jitcapegea.kz
zopebnecmea.kz
actfactory.net
stecom.nl
www.itgsolutions.nl
zeronet.co.jp
valuessl.net
jimiwuwolog.kz
nejumojeawoq.kz
bowuznimnix.kz
geobeojitw.kz
sankoglage.kz
xuanxiao.com
xoqsurkit.kz
pimxaludar.kz
zisihitzeiq.kz
sikafirenab.kz
piqixbixpop.kz
cgc-england.com
fabianonline.de
fofecqekwos.kz
sogpusixqe.kz
xifinuhugurr.kz
xakeboqmeaj.kz
qepekavibimw.kz
aethora.com
courtney.ca
lixvubiriv.kz
noqcogdoq.kz
zosqoslan.kz
covohoghuzf.kz
wuzbavuwi.kz
norakuroya.com
cosmoripe.kz
zoxupuzleaji.kz
jaxaheidajuj.kz
cinaqexealei.kz
duqladxoqp.kz
toddpipe.com
babeaseafecv.kz
meaqekmunoj.kz
xamuzkognaq.kz
rebvowuqog.kz
nafurebxexa.kz
cksglobal.net
kenoqjeivim.kz
gobirogcanco.kz
dimvimfixp.kz
gipecogpadm.kz
kuzgeanimk.kz
www.cksglobal.net
nori-k.com
pbna.com
arquiteturadigital.com
zeokuhicane.kz
hakikuzhuzd.kz
lovibufxoqh.kz
xenohitredan.kz
garalqufnage.kz
screaminpeach.com
geodecisions.com
pcpeds.com
www.cgc-school.com
christybarry.com
geowofowoq.kz
bazoheasape.kz
qekkahoqp.kz
lankitnozo.kz
quheinaxizi.kz
ctr4process.org
searanadfufo.kz
deolivuzf.kz
dalvuruzc.kz
wuzwimhan.kz
wuznufrod.kz
curitnekkeq.kz
nimbimgov.kz
badlowuvil.kz
seojorenosk.kz
xoqjudoqx.kz
mebnuflige.kz
jigallefine.kz
wupoqwimpuz.kz
fuligomosek.kz
ciwebfadlohu.kz
tessera.co.jp
zospuhoqh.kz
huqosnosnuf.kz
qitseacuca.kz
duvuzxadfopo.kz
muduqufxogal.kz
eyggroup.com
boqweckog.kz
povajikoqzos.kz
beoxiragudeo.kz
vufrequrqe.kz
jitwucogze.kz
sspackaginggroup.com
guberman.com.br
malzufceks.kz
xevufruzxami.kz
canpojeik.kz
qabosheojuv.kz
woqbojomeb.kz
urantiaproject.com
redconeretreat.com
konishi-hp.com
sixhivuzn.kz
wecqepijog.kz
koqoswimbuma.kz
kucokebfano.kz
heowalbav.kz
churchsupplies.net
shbrazil.com
www.shbrazil.com
wagigeoleimi.kz
poxuzmifave.kz
safuxazokit.kz
jangakogn.kz
duranmixaxu.kz
sopecxuzdoqw.kz
fekgacupec.kz
gagozoswoqwi.kz
coswadlok.kz
bearefufs.kz
golfpark-moossee.ch
theautospas.com
www.theautospas.com
pebruznec.kz
xeawoqhavu.kz
bamurcogadi.kz
mogqimicu.kz
wadleinoqk.kz
o.ss2.us
zolixpoqboqj.kz
brookfarm.com.au
gojaroduwuwe.kz
fixzankoqn.kz
manqekogd.kz
fimuznarogj.kz
bapasitaramsevatrust.org
tenpole.com
jaqihumogpec.kz
fimkopecd.kz
galqeknoqi.kz
vosmuzcixq.kz
hahokalgeago.kz
momonophoto.com
www.momonophoto.com
bredainternet.nl
coopsupermarkt.nl
espace-hotelier.com
jukalcurheo.kz
www.espace-hotelier.com
pebpimfaq.kz
waditlimujaz.kz
widitvinoqb.kz
cihisifosqur.kz
coop.nl
boundbydesign.com
www.coop.nl
e-kagami.com
vimviditw.kz
heimuzlufmit.kz
ditjuqeso.kz
zakicuvafad.kz
leijitxima.kz
www.e-kagami.com
hogvawufu.kz
zosvuzkev.kz
vizeikiforu.kz
lunawadkebqa.kz
xefimralral.kz
s.ss2.us
crl.rootg2.amazontrust.com
ocsp.rootg2.amazontrust.com
crl.sca1b.amazontrust.com
ocsp.sca1b.amazontrust.com
crl.rootca1.amazontrust.com
ocsp.rootca1.amazontrust.com
quxuzmeagof.kz
coslealea.kz
galdaqixni.kz
binufadzossa.kz
cixlowuku.kz
totalearthcare.com.au
isle-karnataka.org
starmedia.ca
acicinvestor.ca
wapuzwadheic.kz
zolixrebheog.kz
xenekwimvop.kz
qitvimleix.kz
kurwoloke.kz
niray.com.cn
cbsprinting.com.au
easygen.com
zobimufobuf.kz
zadpolezi.kz
bixdeozuko.kz
jijisazeoje.kz
cosladcos.kz
sarahdavid.com
gamblingonlinemagazine.com
etcycles.com
areafor.com
deavuzfekd.kz
xufxokanug.kz
guhojixdeir.kz
hoqfimdozu.kz
beanufcix.kz
rodeoshow.com.au
sdlp.ie
churchclothes.com

How to determine TrojanDownloader:Win32/Cutwail?


File Info:

crc32: 3A358800
md5: 82037b6e1b37ab6a3f8e3fc369637e7c
name: n251_216.exe
sha1: 1a53a0a4230daf637f7120fba3d6656be0587552
sha256: 2cde0429620577eb19a1a4f281894be611c9500883afccadad599dc33ce2b322
sha512: 3e5695900b23b564279bf74ad98ab8ad4e5b66319b380b1620587c5dc12be7d09c89d4c2a0aa12d6dce9c3c0972f01cb45362d818f705578031566eac42f3f25
ssdeep: 1536:JQUkwhoqsGekKMHyISnxNHV/KqycA+pF:HkSsX2gx1Yqyup
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

TrojanDownloader:Win32/Cutwail also known as:

BkavW32.PrazalA.Trojan
MicroWorld-eScanGen:Variant.Fugrafa.39407
FireEyeGeneric.mg.82037b6e1b37ab6a
CAT-QuickHealTrojanPWS.Kegotip.WR4
McAfeePWSZbot-FOK!82037B6E1B37
ALYacGen:Variant.Fugrafa.39407
CylanceUnsafe
VIPRETrojan.Win32.Kryptik.cdc (v)
SangforMalware
K7AntiVirusTrojan ( 0055dd191 )
BitDefenderGen:Variant.Fugrafa.39407
K7GWTrojan ( 0055dd191 )
Cybereasonmalicious.e1b37a
Invinceaheuristic
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Cutwail-CO [Trj]
ClamAVWin.Trojan.Zbot-1347
GDataGen:Variant.Fugrafa.39407
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Cutwail.daixox
AegisLabVirus.Win32.Virut.lcCA
RisingMalware.Heuristic!ET#93% (RDMK:cmRtazpH7vFHhXnQuEh1gWr1pwkk)
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Fugrafa.39407 (B)
ComodoMalware@#3zf5ywfbgol4
DrWebTrojan.Packed.26836
TrendMicroTROJ_CUTWAIL.YAT
McAfee-GW-EditionPWSZbot-FOK!82037B6E1B37
Trapminemalicious.high.ml.score
SophosTroj/Wonton-DE
IkarusBackdoor.Win32.Androm
CyrenW32/Trojan.QHUY-4831
JiangminTrojan/Cutwail.fj
WebrootTrojan.Dropper.Gen
eGambitUnsafe.AI_Score_96%
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Cutwail
ArcabitTrojan.Fugrafa.D99EF
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojanDownloader:Win32/Cutwail
AhnLab-V3Spyware/Win32.Zbot.R108019
Acronissuspicious
TACHYONTrojan/W32.Cutwail.90624
Ad-AwareGen:Variant.Fugrafa.39407
MalwarebytesTrojan.Agent.ED
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Kryptik.CEBY
TrendMicro-HouseCallTROJ_CUTWAIL.YAT
TencentWin32.Trojan.Generic.Dwit
YandexTrojan.Kryptik!BoDmHsgi4DA
SentinelOneDFI – Suspicious PE
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Zbot.XXU!tr
BitDefenderThetaGen:NN.ZexaF.34108.fqW@aeRl4Qpi
AVGWin32:Cutwail-CO [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_70% (D)
Qihoo-360HEUR/Malware.QVM10.Gen

How to remove TrojanDownloader:Win32/Cutwail?

TrojanDownloader:Win32/Cutwail removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment