Trojan

TrojanDownloader:Win32/Zeagle!A malicious file

Malware Removal

The TrojanDownloader:Win32/Zeagle!A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Zeagle!A virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Performs some HTTP requests
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Detects SunBelt Sandbox through the presence of a library
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Attempts to identify installed analysis tools by a known file location
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • The sample wrote data to the system hosts file.
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
dynupdate.no-ip.com
www.piadasnaweb.com
www.procurase.net
www.cifrando.com

How to determine TrojanDownloader:Win32/Zeagle!A?


File Info:

crc32: E38C1C91
md5: f9dd4cfe820709476fcc6ef28ee686cd
name: F9DD4CFE820709476FCC6EF28EE686CD.mlw
sha1: 091423aba6ec11618c616db6a97117b4f7bd4a05
sha256: aa15d7aba2e621b87606d4420bda37c47e307f940140991aad03254093f8bfe7
sha512: edd164f715940acf572e69726fec4c5d82dcac48487f7bfc9145bfe0f370f55b519aaadf4c0e6c12ef698eb62d5b2d0c8e2a1c18efd10798b5b3764fe11d1c97
ssdeep: 49152:ECRgufR5azsijucK9bo4LKRPpFM+88ePrTA:Em7fR5qsG+84mRPpF16rc
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

TrojanDownloader:Win32/Zeagle!A also known as:

MicroWorld-eScanGen:Variant.Symmi.1468
FireEyeGeneric.mg.f9dd4cfe82070947
McAfeeGenDownloader.bg
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusSpyware ( 0055e3db1 )
BitDefenderGen:Variant.Symmi.1468
K7GWSpyware ( 0055e3db1 )
Cybereasonmalicious.e82070
SymantecML.Attribute.HighConfidence
TotalDefenseWin32/Dropper.ZABM
APEXMalicious
AvastWin32:Zeagle-B [Trj]
KasperskyTrojan-Dropper.Win32.Dapato.avkt
AlibabaTrojanDownloader:Win32/Dapato.984e77b9
NANO-AntivirusTrojan.Win32.Dapato.nymlc
AegisLabTrojan.Win32.Dapato.b!c
Ad-AwareGen:Variant.Symmi.1468
EmsisoftGen:Variant.Symmi.1468 (B)
ComodoMalware@#29pc43mp1mrkb
F-SecureHeuristic.HEUR/AGEN.1129031
DrWebTrojan.DownLoader3.20436
ZillyaDropper.Dapato.Win32.7607
TrendMicroTSPY_BANKER.JWE
McAfee-GW-EditionGenDownloader.bg
SophosMal/Generic-R + Troj/Dapato-J
GDataGen:Variant.Symmi.1468
JiangminTrojanDropper.Dapato.zyf
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1129031
Antiy-AVLTrojan[Dropper]/Win32.Dapato
KingsoftWin32.Troj.Generic.a.(kcloud)
ArcabitTrojan.Symmi.D5BC
ZoneAlarmTrojan-Dropper.Win32.Dapato.avkt
MicrosoftTrojanDownloader:Win32/Zeagle.gen!A
CynetMalicious (score: 85)
BitDefenderThetaGen:NN.ZelphiF.34804.WIW@aSXWG5pG
ALYacGen:Variant.Symmi.1468
MAXmalware (ai score=98)
VBA32TrojanDropper.Dapato
MalwarebytesGeneric.Malware/Suspicious
PandaGeneric Malware
ESET-NOD32Win32/Spy.Banker.XQU
TrendMicro-HouseCallTSPY_BANKER.JWE
RisingRansom.Blocker!8.12A (TFE:4:mPvQ85epnmU)
YandexTrojan.DR.Dapato!k81f8DYMKrw
IkarusTrojan-Dropper.Win32.Dapato
FortinetW32/Dapato.AVKT!tr
AVGWin32:Zeagle-B [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Dropper.170

How to remove TrojanDownloader:Win32/Zeagle!A?

TrojanDownloader:Win32/Zeagle!A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment