Threat Database Trojans Trojan.Agent.HAFA

Trojan.Agent.HAFA

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 5,854
Threat Level: 80 % (High)
Infected Computers: 222
First Seen: December 3, 2024
Last Seen: July 17, 2026
OS(es) Affected: Windows

The detection of Trojan.Agent.HAFA on your system indicates a potential security threat that requires immediate attention. This Trojan-type threat can compromise your computer's security and put your personal data at risk. It is essential to understand the nature of this threat and take prompt action to remove it from your system.

What Is Trojan.Agent.HAFA?

Trojan.Agent.HAFA is a type of malware that can infiltrate your system without your knowledge or consent. Trojans are malicious programs that can disguise themselves as legitimate software, making them difficult to detect. They can be used to steal sensitive information, install additional malware, or provide unauthorized access to your system. The name "Trojan.Agent.HAFA" suggests that it is a Trojan-type threat, but its specific characteristics and behavior may vary.

How Trojan.Agent.HAFA Operates

Trojan.Agent.HAFA can operate in various ways, depending on its intended purpose. It may be designed to collect sensitive information, such as login credentials, credit card numbers, or personal data. It can also be used to install additional malware, such as ransomware, spyware, or adware, which can further compromise your system's security. In some cases, Trojans can create backdoors, allowing hackers to access your system remotely and perform malicious activities.

Symptoms of Infection

The symptoms of a Trojan.Agent.HAFA infection can vary, but common indicators include slow system performance, unexpected pop-ups or ads, and unusual network activity. You may also notice that your system is crashing or freezing frequently, or that your antivirus software is detecting suspicious activity. In some cases, you may not notice any symptoms at all, which is why regular system scans and monitoring are essential for detecting and removing malware.

  • Slow system performance or crashes
  • Unexpected pop-ups or ads
  • Unusual network activity
  • Frequent system freezes or errors
  • Antivirus software detecting suspicious activity

How to Remove Trojan.Agent.HAFA

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for a more effective removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full system scan and detect any malware or suspicious activity.
  3. Uninstall any suspicious programs or software that may be related to the Trojan.Agent.HAFA infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform another full scan to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.Agent.HAFA from your system requires a combination of technical expertise and caution. It is essential to follow the steps outlined above and to use reputable anti-malware tools to ensure that the malware is completely removed. Regular system scans, monitoring, and maintenance can help prevent future infections and protect your personal data. By taking prompt action and staying vigilant, you can help keep your system secure and prevent the spread of malware.

Analysis Report

General information

Family Name: Trojan.Agent.HAFA
Packers: UPX!
Signature status: No Signature

Known Samples

MD5: 263eab091b5a9849df8b8ee6fc36df16
SHA1: b69bbca4373e6ab3f0992908b237d37e240d0e8e
SHA256: 799094C72FC027A87179CB8532FE49D55045D5EF5D8904CA02D7204A2866BEF4
File Size: 1.65 MB, 1647600 bytes
MD5: a148af4674690325d100c1a006388b71
SHA1: b4b5d3581c99c1203bc6f5ecd55f9da29f3d9362
SHA256: B541AFD7842D2B267B4DF90DE69C1A4E15EFE50F6F2F302ADE3EC7DE85126E1C
File Size: 653.82 KB, 653824 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File has been packed
  • File has exports table
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
Show More
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Digital Signatures

Signer Root Status
Extravi Extravi Self Signed

File Traits

  • dll
  • fptable
  • No Version Info
  • packed
  • x64

Block Information

Total Blocks: 6,274
Potentially Malicious Blocks: 299
Whitelisted Blocks: 4,336
Unknown Blocks: 1,639

Visual Map

0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 ? 0 ? ? ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 ? ? ? ? 0 0 ? ? ? 0 0 0 0 0 ? ? ? ? ? 0 0 0 ? ? 0 ? 0 x ? 0 ? ? ? ? 0 0 0 ? 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 x 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 ? 0 0 ? 0 0 0 ? ? ? 0 ? 0 ? 0 0 0 0 0 0 0 ? 0 ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 ? 1 0 0 0 0 0 0 ? ? 0 ? 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 ? ? 0 ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 1 ? ? 0 ? 0 0 x 0 x 0 ? 0 ? ? 0 ? ? ? 0 ? ? x 0 0 0 ? 0 0 0 ? ? ? ? ? 1 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 ? 0 ? 0 0 0 0 0 ? 0 0 ? ? ? ? 0 ? 0 0 ? ? ? 0 0 0 ? 0 ? ? 0 0 0 ? 0 x 0 0 0 ? ? 0 ? ? 0 ? 0 ? 0 ? 0 ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? x ? ? 0 0 0 0 0 0 ? ? ? ? ? ? ? 0 ? 0 ? ? ? 0 0 0 0 ? ? ? ? ? ? ? ? ? 0 0 0 ? ? 0 ? ? ? ? ? 0 ? ? ? 0 0 ? ? ? 0 ? ? 0 0 0 0 ? ? ? ? ? ? ? 0 0 0 ? 0 ? 0 0 0 0 0 ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? x ? ? ? 0 ? ? 0 x ? ? ? ? 0 ? ? x ? ? ? ? 0 ? ? ? 0 0 0 ? ? ? ? 0 0 ? 0 0 1 0 ? ? 0 ? ? 0 ? ? ? ? 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 1 0 ? 1 0 0 1 0 0 1 0 0 0 0 0 0 0 1 0 0 0 1 0 0 0 1 0 0 1 0 0 0 0 0 1 0 0 0 0 0 1 0 0 1 0 0 1 0 0 1 0 0 0 1 0 0 0 1 0 0 0 0 1 0 0 1 0 0 0 0 0 1 0 0 1 0 0 x x 0 0 0 0 x x x ? 0 ? 0 ? 0 ? x x x ? ? ? 0 0 0 0 0 0 0 0 x x 0 0 0 0 ? 0 ? ? ? ? 0 ? 0 ? x x ? ? x ? ? ? ? ? ? ? x x ? ? ? ? ? 0 0 ? ? ? ? 0 ? ? 0 ? ? x ? x ? 0 ? 0 ? ? 0 0 ? ? ? 0 0 0 0 0 0 0 0 ? 0 0 ? ? ? ? 0 0 0 ? 0 ? ? 0 ? ? ? 0 ? ? 0 ? ? 0 ? ? ? ? 0 0 ? 0 0 ? 1 x x x 0 0 ? ? ? x x ? ? 0 0 0 0 0 0 ? 0 ? ? 0 ? x x x x 0 0 0 x x x 0 0 ? ? x ? 0 0 0 0 ? ? 0 0 ? 0 0 0 0 0 0 0 ? ? ? ? 0 0 0 0 0 ? ? 0 x ? ? x ? ? ? ? x ? 0 ? 0 0 0 ? ? ? ? ? ? ? ? 0 0 0 ? 0 ? ? 0 0 0 0 ? ? x ? ? 0 0 0 ? 0 ? 0 0 ? x 0 ? x ? 0 ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 ? x ? ? ? x ? ? ? 0 ? ? ? x x ? ? 0 x ? ? 0 ? 1 0 ? ? 0 ? x 0 x x x x ? ? 0 0 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? 0 ? ? ? ? ? x ? ? ? ? ? ? 0 ? ? 0 ? 0 ? 0 ? ? ? ? ? 0 ? ? ? 0 0 0 ? 0 0 0 0 0 ? 0 0 ? 0 0 ? ? ? ? ? 0 ? ? 0 ? x 0 0 0 ? ? ? ? ? 0 0 ? ? x 0 0 ? ? 0 ? ? 0 0 0 x 0 0 0 0 0 0 ? 0 0 ? 0 0 ? 0 ? 0 ? ? ? 1 ? ? ? ? ? ? ? ? 0 0 0 ? x x x x 0 0 0 x x 0 0 0 ? 0 ? 1 0 ? 0 ? 0 ? ? 0 0 ? 0 0 ? 0 ? 0 ? ? 0 x x 0 0 x x 0 0 x x 0 x x 0 ? ? ? 0 ? ? ? 0 0 0 0 0 0 x 0 0 ? ? 0 ? ? 0 x ? x ? ? 0 x x x 0 0 x x 0 0 0 0 ? ? ? ? ? x ? x ? 0 x x x ? ? ? x 0 ? 0 0 0 x 0 0 ? 0 0 0 0 0 0 0 x x 0 ? 0 ? 0 ? x ? x ? x x x x x x ? ? ? 0 x ? ? 0 ? ? ? 0 0 ? x x x x 0 0 ? 0 0 0 ? 0 ? 0 ? 0 ? 0 ? ? ? 0 ? ? 0 ? ? ? ? 0 ? ? ? x ? ? ? x 0 ? ? x ? ? ? 0 x ? 0 0 ? x 0 x ? 0 ? ? 0 ? x 0 ? ? ? ? ? ? 0 ? ? ? x 0 x ? ? ? ? 0 ? 0 ? 0 ? 0 0 ? ? 0 0 ? 0 ? 0 0 0 x ? ? ? 0 ? 0 ? ? ? 0 0 0 x ? ? x 0 ? ? 0 ? ? x 0 x ? 0 ? ? ? 0 x x x 0 0 ? 0 0 ? ? x 0 x 0 ? 0 ? ? ? x 0 x 0 0 x 0 ? 0 ? 0 ? 0 ? 0 ? ? 0 0 ? ? x ? 0 1 ? ? x ? 1 0 x ? ? ? 0 0 x ? ? ? 0 0 ? ? 0 ? 0 ? ? ? 0 0 0 ? ? ? 0 x 0 0 ? ? ? ? x 0 x ? 0 ? 0 ? ? x x x 0 0 ? ? ? 0 ? 0 0 0 0 ? 0 ? ? 0 ? ? 0 0 ? ? 0 ? 0 ? ? ? 0 0 ? ? 0 ? ? 0 ? 0 ? x x x ? 0 ? 0 ? ? x 0 0 0 x 0 x x 0 0 ? 0 ? 0 ? ? ? ? 0 ? ? 0 ? ? ? x ? ? 0 ? x x x x ? ? ? 0 0 0 ? ? 0 0 x x 0 0 0 x x x x x ? ? ? 0 ? ? ? ? ? ? ? ? ? ? 0 ? 0 0 x 0 ? ? 0 ? x 0 ? ? 0 x ? 0 0 0 0 ? 0 0 ? 1 ? ? 0 ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? 0 0 x x 0 0 ? 0 0 ? ? ? 0 ? 0 ? 1 0 0 ? 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 ? 0 0 0 ? ? 0 ? ? x x x 0 0 x x x 0 x 0 x 0 x x 0 0 x x x x 0 ? ? x ? ? ? 0 ? ? 0 ? x 0 ? x x 0 x ? ? ? ? x ? 0 0 ? x ? 0 x 0 0 0 x x 0 0 0 0 0 0 0 x 0 ? 0 0 ? ? x 0 0 0 x x 0 x 0 0 0 0 0 0 x 0 x x 0 x x 0 ? 0 ? 0 0 ? x ? x x ? 0 0 ? 0 x ? 0 0 0 0 0 0 0 ? 0 0 ? 0 0 ? x 0 0 0 ? x x 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? ? ? 0 ? 0 0 ? 0 0 0 ? ? ? ? ? ? ? 0 0 ? ? ? 0 ? 0 ? ? 0 0 ? ? 0 0 0 ? ? 0 x 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? ? 0 0 0 0 0 ? ? ? ? 0 ? ? ? 0 ? ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 0 0 ? 0 ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 ? ? ? ? ? 0 0 x 0 0 0 0 0 0 0 0 0 ? 0 ? ?
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\program files\bloxshade\install.txt Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\explorer::slowcontextmenuentries `$�!�:i��+00��� Gs]XM���"�2��FXD�':D��exA-��LG=�A��J� �C� RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\content::cacheprefix RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\cookies::cacheprefix Cookie: RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\history::cacheprefix Visited: RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 Jhe\x �� �6 xy ��������%��Bx�<���R#@�#��$¨%f�'�(�)E*9*�"0P%1HO5,]9�@V�@��B��H��J��K�iN$U_*VN�\tec�wd��g��lR n�ArnJr�Bu�~v�!x�dy�y�^|ۘ~D���P����jI�����7��a��3 RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 Khe\x �� �6 xy ��������%��Bx�<���R#@�#��$¨%f�'�(�)E*9*�"0P%1HO5,]9�@V�@��B��H��J��K�iN$U_*VN�\tec�wd��g��lR n�ArnJr�Bu�~v�!x�dy�y�^|ۘ~D���P����jI�����7��a��3 RegNtPreCreateKey
HKCU\software\microsoft\edge\blbeacon::failed_count RegNtPreCreateKey
HKCU\software\microsoft\edge\blbeacon::state  RegNtPreCreateKey
HKCU\software\microsoft\edge\thirdparty::statuscodes (NULL) RegNtPreCreateKey
HKCU\software\microsoft\edge\thirdparty::statuscodes  RegNtPreCreateKey
Show More
HKCU\software\microsoft\edge\elfbeacon::version 142.0.3595.90 RegNtPreCreateKey
HKCU\software\microsoft\edge\blbeacon::failed_count  RegNtPreCreateKey
HKCU\software\microsoft\edge\blbeacon::state  RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAccessCheckByType
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcAcceptConnectPort
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreatePort
  • ntdll.dll!NtAlpcCreatePortSection
  • ntdll.dll!NtAlpcCreateSectionView
Show More
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcQueryInformationMessage
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtAlpcSetInformation
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateUserProcess
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDeleteValueKey
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtImpersonateAnonymousToken
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtPowerInformation
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryEvent
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationObject
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSetTimerEx
  • ntdll.dll!NtSetValueKey
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection

10 additional items are not displayed above.

Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
Process Shell Execute
  • CreateProcess
  • ShellExecute

Shell Command Execution

open https://www.roblox.com/download/client
"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --edge-skip-compat-layer-relaunch --single-argument https://www.roblox.com/download/client

Trending

Most Viewed

Loading...