Trojan

Trojan:Win32/Seheq!rfn (file analysis)

Malware Removal

The Trojan:Win32/Seheq!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Seheq!rfn virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Binary file triggered YARA rule
  • Binary compilation timestomping detected

How to determine Trojan:Win32/Seheq!rfn?


File Info:

name: 2FF97DE7A16519B74113.mlw
path: /opt/CAPEv2/storage/binaries/fe07dca68f288a4f6d7cbd34d79bb70bc309635876298d4fde33c25277e30bd2
crc32: 67EAC854
md5: 2ff97de7a16519b74113ea9137c6ba0c
sha1: 5def5e492435cfd423e51515925d17285b77cdbc
sha256: fe07dca68f288a4f6d7cbd34d79bb70bc309635876298d4fde33c25277e30bd2
sha512: bf51ab31b293e788c2caa14cc4e9b1c0a0caa40f7c2680698387ca4d8ba5c01278bc56ec43e3940ddc144519d59f3f6a3d24c5f87381404aa3f99ed389f17c36
ssdeep: 24576:XDOJwgb7bpJsYbPQ4LiGlKMA4DQpYkZWAT8mB+lEq2O5f5qmT:X4j9KYbPQ4uGfd06kZWi8my5f5z
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FE25124692B7CA50DDAB09311DD51F217B331C6748808BAD9BF4B0EC4E77FB6A242267
sha3_384: 21a5bd2a3091f70c6f811ce9dfcd8b577532f49cd0e983a28e944b6510fd55240f2f8f7001cbebc990a5a20c2cfd00e2
ep_bytes: ff250020400000000000000000000000
timestamp: 2068-02-11 13:35:16

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: F5UPDATER
FileVersion: 1.0.0.0
InternalName: F5UPDATER.exe
LegalCopyright: F5 Copyright © 2023
LegalTrademarks:
OriginalFilename: F5UPDATER.exe
ProductName: F5UPDATER
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Trojan:Win32/Seheq!rfn also known as:

LionicTrojan.Win32.KillFiles.j!c
MicroWorld-eScanTrojan.GenericKD.70887971
FireEyeTrojan.GenericKD.70887971
SkyhighMSIL/KillFiles!2FF97DE7A165
McAfeeMSIL/KillFiles!2FF97DE7A165
MalwarebytesMalware.AI.2328865823
VIPRETrojan.GenericKD.70887971
K7AntiVirusRiskware ( 00584baa1 )
K7GWRiskware ( 00584baa1 )
Cybereasonmalicious.7a1651
SymantecTrojan Horse
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/KillFiles.DL
APEXMalicious
TrendMicro-HouseCallTrojan.Win32.KILLDISK.YXDLUZ
KasperskyHEUR:Trojan-Ransom.MSIL.Agent.gen
BitDefenderTrojan.GenericKD.70887971
NANO-AntivirusTrojan.Win32.Ransom.khnnrk
AvastWin32:BackdoorX-gen [Trj]
EmsisoftMalCert-S.RI (A)
F-SecureTrojan.TR/KillFiles.exevp
ZillyaTrojan.KillFiles.Win32.38166
TrendMicroTrojan.Win32.KILLDISK.YXDLUZ
SophosMal/Generic-S
IkarusTrojan.MSIL.KillFiles
GoogleDetected
AviraTR/KillFiles.exevp
VaristW32/ABRisk.UVEU-7938
KingsoftMSIL.Trojan-Ransom.Agent.gen
MicrosoftTrojan:Win32/Seheq!rfn
ArcabitTrojan.Generic.D439AA23
ViRobotTrojan.Win.S.Dropper.1007440
ZoneAlarmHEUR:Backdoor.MSIL.Agent.gen
GDataTrojan.GenericKD.70887971
AhnLab-V3Trojan/Win.Generic.C5565101
ALYacTrojan.MSIL.KillFiles
MAXmalware (ai score=89)
Cylanceunsafe
PandaTrj/Chgt.AD
RisingRansom.Agent!8.6B7 (CLOUD)
MaxSecureTrojan.Malware.11035479.susgen
FortinetMSIL/KillFiles.DL!tr
AVGWin32:BackdoorX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Seheq!rfn?

Trojan:Win32/Seheq!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment