Trojan

About “TrojanDownloader:Win32/Dofoil.R” infection

Malware Removal

The TrojanDownloader:Win32/Dofoil.R is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Dofoil.R virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • A named pipe was used for inter-process communication
  • Starts servers listening on 127.0.0.1:0
  • Expresses interest in specific running processes
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Enumerates services, possibly for anti-virtualization
  • Crashed cuckoomon during analysis. Report this error to the Github repo.
  • A process attempted to delay the analysis task by a long amount of time.
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Steals private information from local Internet browsers
  • A system process is generating network traffic likely as a result of process injection
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Attempts to modify or disable Security Center warnings
  • Anomalous binary characteristics

Related domains:

monsterbobz.net
florasister.com
crl3.digicert.com
ocsp.digicert.com

How to determine TrojanDownloader:Win32/Dofoil.R?


File Info:

crc32: CFBF5F09
md5: 54b086ccc3dfd60fbc255f1137e4f6d4
name: 54B086CCC3DFD60FBC255F1137E4F6D4.mlw
sha1: 44f335d5287fee5426d1c0ad62a3458c6fe94193
sha256: dda8c473879b6b4f09611989c26670fd0b1a35783ca8c8aec1155dd8608a00cb
sha512: 399fd38ad22ec547debb0a58ce534af563cd38ec3293404c9bbe276c960eb561b6fb7bdc74b2c196c534f7fa5eba3d1eef17c20ba59b0b2d16c8bfd79abcda84
ssdeep: 12288:TfLvl8cioA9CLJjpBZIlepegwLgtXAP3SsEb/:Tf7DBAaJjpcKtu3Q7
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: xae TradeMark 2001-2011 C.U.B.E
InternalName: a
FileVersion: 2.11
CompanyName: Softwareentwicklung Yuschuk
LegalTrademarks: C.U.B.E Corp xa9 http:\www.CUBECORP.TV
Comments: This Program Check Booking And Preservation
ProductName: Booking Check
ProductVersion: 2.11
FileDescription: Booking Checking V2
OriginalFilename: a.exe

TrojanDownloader:Win32/Dofoil.R also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Zygug.5
FireEyeGeneric.mg.54b086ccc3dfd60f
McAfeeArtemis!54B086CCC3DF
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Multi.Generic.4!c
SangforMalware
BitDefenderGen:Heur.Zygug.5
Cybereasonmalicious.cc3dfd
BitDefenderThetaGen:NN.ZevbaF.34804.Jm1@aelZIQcO
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.ACPT
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Zurgop-7586567-0
KasperskyTrojan-Downloader.Win32.Dofoil.bvwc
NANO-AntivirusTrojan.Win32.TrjGen.cbfobn
Ad-AwareGen:Heur.Zygug.5
SophosML/PE-A
ComodoTrojWare.Win32.Injector.ADKK@4vyrc7
F-SecureTrojan.TR/Dropper.VB.Gen
DrWebTrojan.PWS.SpySweep.389
ZillyaTrojan.Genome.Win32.222629
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.hc
EmsisoftGen:Heur.Zygug.5 (B)
IkarusTrojan.Win32.Injector
AviraTR/Dropper.VB.Gen
MAXmalware (ai score=85)
Antiy-AVLTrojan/Win32.Unknown
KingsoftWin32.Troj.Genome.(kcloud)
MicrosoftTrojanDownloader:Win32/Dofoil.R
ArcabitTrojan.Zygug.5
AhnLab-V3Spyware/Win32.Zbot.R53905
ZoneAlarmTrojan-Downloader.Win32.Dofoil.bvwc
GDataGen:Heur.Zygug.5
CynetMalicious (score: 100)
VBA32TScope.Trojan.VB
MalwarebytesMalware.AI.94428479
PandaTrj/CI.A
TencentWin32.Trojan.Genome.Swku
YandexTrojan.GenAsa!jQV7+jH/uYM
SentinelOneStatic AI – Malicious PE
eGambitGeneric.Malware
FortinetW32/Injector.ACPT!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (D)
Qihoo-360HEUR/Malware.QVM03.Gen

How to remove TrojanDownloader:Win32/Dofoil.R?

TrojanDownloader:Win32/Dofoil.R removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment