Malware

What is “Win32/Xanfpezes.A”?

Malware Removal

The Win32/Xanfpezes.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Xanfpezes.A virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • A process attempted to delay the analysis task.
  • Loads a driver
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering
  • Anomalous binary characteristics

Related domains:

wt.chaoweinet.com

How to determine Win32/Xanfpezes.A?


File Info:

name: D679D84FC2B1C2155D87.mlw
path: /opt/CAPEv2/storage/binaries/cd7b1f7f4810b9d34a7b0bf7ad2babe9d9aefa047c438823ac2719d4f97b4d22
crc32: 2B9C519B
md5: d679d84fc2b1c2155d8714b5cf372c84
sha1: aafa3c49a727406a39fc92b1eaad4f8fc48e5505
sha256: cd7b1f7f4810b9d34a7b0bf7ad2babe9d9aefa047c438823ac2719d4f97b4d22
sha512: 77ad8bf8ca8677358835a2b61385456abe05aef05f02aaa78ae8595f2e6b4a87895beb9f6f8a7a0c7b20ff0b5ab94eb2c3c2d50740c158c8a5412b6a79e41e67
ssdeep: 49152:zWXTeFAlwt0Qk/Xml46Gxjnvjnalwt0Qk/Xml46GxjnW:KXTeFAlE0QGXmlXG4lE0QGXmlXGI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16CF59D65F282E433E4A62F308E1BC2D47739B9406D75959F32F46F4E3A75A837621382
sha3_384: ced08862ac68d84b46ce057c98f8a7dfa558fcb3ec975ff951c57bfc4422b387d0023599688410aaf106f3ce13ed16f2
ep_bytes: 558bec83c4e45333c08945e48945ec89
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Win32/Xanfpezes.A also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.38117981
FireEyeGeneric.mg.d679d84fc2b1c215
McAfeeGenericRXAC-RY!D679D84FC2B1
CylanceUnsafe
ZillyaTrojan.Xanfpezes.Win32.8
K7AntiVirusTrojan ( 001496011 )
K7GWTrojan ( 001496011 )
Cybereasonmalicious.9a7274
CyrenW32/DelfInject.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Xanfpezes.A
APEXMalicious
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderTrojan.GenericKD.38117981
NANO-AntivirusTrojan.Win32.Xanfpezes.egspn
AvastWin32:TrojanX-gen [Trj]
TencentMalware.Win32.Gencirc.10cde794
Ad-AwareTrojan.GenericKD.38117981
SophosTroj/Ghetifuh-A
DrWebTrojan.NtRootKit.11872
VIPRETrojan.Win32.Generic.pak!cobra
McAfee-GW-EditionBehavesLike.Win32.Dropper.wh
EmsisoftTrojan.GenericKD.38117981 (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKD.38117981
JiangminTrojan/Generic.bunu
AviraTR/Dropper.Gen
MAXmalware (ai score=87)
Antiy-AVLTrojan/Generic.ASMalwS.183F20E
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Unwanted/Win32.Agent.R345758
Acronissuspicious
VBA32BScope.Trojan.AntiAV
MalwarebytesTrojan.Agent
RisingTrojan.Generic@ML.94 (RDML:22BCmQ/oH/0D6iI8xGtc5g)
YandexRootkit.Agent!YxY55SSjpOc
IkarusTrojan.Win32.Hider
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Xanfpezes.ACMT!tr
BitDefenderThetaGen:NN.ZelphiF.34294.ARZ@aSWQ7Ubb
AVGWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Win32/Xanfpezes.A?

Win32/Xanfpezes.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment