Trojan.Downloader.Firseria
Threat Scorecard
EnigmaSoft Threat Scorecard
EnigmaSoft Threat Scorecards are assessment reports for different malware threats which have been collected and analyzed by our research team. EnigmaSoft Threat Scorecards evaluate and rank threats using several metrics including real-world and potential risk factors, trends, frequency, prevalence, and persistence. EnigmaSoft Threat Scorecards are updated regularly based on our research data and metrics and are useful for a wide range of computer users, from end users seeking solutions to remove malware from their systems to security experts analyzing threats.
EnigmaSoft Threat Scorecards display a variety of useful information, including:
Popularity Rank: The ranking of a particular threat in EnigmaSoft’s Threat Database.
Severity Level: The determined severity level of an object, represented numerically, based on our risk modeling process and research, as explained in our Threat Assessment Criteria.
Infected Computers: The number of confirmed and suspected cases of a particular threat detected on infected computers as reported by SpyHunter.
See also Threat Assessment Criteria.
| Popularity Rank: | 10,428 |
| Threat Level: | 80 % (High) |
| Infected Computers: | 728 |
| First Seen: | August 22, 2018 |
| Last Seen: | September 29, 2026 |
| OS(es) Affected: | Windows |
The detection of Trojan.Downloader.Firseria on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to download and install additional malicious software on your computer, which can lead to a range of problems, including data theft, system crashes, and unauthorized access to your personal information.
Table of Contents
What Is Trojan.Downloader.Firseria?
Trojan.Downloader.Firseria is a type of Trojan horse malware that is designed to download and install additional malicious software on your computer. The name "Trojan" refers to the fact that this type of malware disguises itself as a legitimate program or file, allowing it to bypass your system's security defenses. The "Downloader" part of the name indicates that this malware is capable of downloading and installing additional malicious software, which can include viruses, spyware, adware, and other types of malware.
How Trojan.Downloader.Firseria Operates
Trojan.Downloader.Firseria typically operates by exploiting vulnerabilities in your system's security or by tricking you into downloading and installing it. Once installed, it can download and install additional malicious software, which can include keyloggers, ransomware, and other types of malware. This malware can also communicate with its creators, allowing them to remotely control your system and steal your personal information. Trojan.Downloader.Firseria can be difficult to detect, as it can disguise itself as a legitimate program or file, and it may not exhibit any obvious symptoms of infection.
Symptoms of Infection
While Trojan.Downloader.Firseria may not exhibit any obvious symptoms of infection, there are some signs that may indicate that your system is infected. These can include slow system performance, unexpected pop-ups or ads, unfamiliar programs or files on your system, and unexplained changes to your system's settings or configuration. If you suspect that your system is infected with Trojan.Downloader.Firseria, it is essential to take immediate action to remove the malware and prevent further damage.
How to Remove Trojan.Downloader.Firseria
- Restart your system in Safe Mode with Networking to prevent the malware from loading and to allow you to download and install removal tools.
- Download and install a reputable anti-malware tool, such as SpyHunter, and perform a full scan of your system to detect and remove the malware.
- Uninstall any suspicious programs or applications that may be related to the malware.
- Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
- Reboot your system and perform another scan with your anti-malware tool to ensure that the malware has been completely removed.
Conclusion
The removal of Trojan.Downloader.Firseria requires careful attention to detail and a thorough understanding of the malware's behavior and characteristics. By following the steps outlined above, you can help to ensure that your system is completely free of the malware and that your personal information is protected. It is also essential to take steps to prevent future infections, including keeping your operating system and software up to date, using strong antivirus software, and avoiding suspicious downloads and email attachments. By taking these precautions, you can help to protect your system and your personal information from the threats posed by Trojan.Downloader.Firseria and other types of malware.
Analysis Report
General information
| Family Name: | Trojan.Downloader.Firseria |
|---|---|
| Signature status: | Self Signed |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
74419fcafd5b0cf8b66b4040a824442b
SHA1:
045a0700ba81030a479fd6f041d5eb1a388cdc3d
SHA256:
A676B802990386764F43AA6FC32034458CA499B765E5B08F19A314759BBE52AF
File Size:
526.43 KB, 526432 bytes
|
|
MD5:
b2e4e7069c57a165c3c609d5ea9a4cef
SHA1:
ff02bfbada66239b68e2cd2e66020238f7551964
SHA256:
765C8BF1009D1F39A2EB1147082F5BA58603F96F7860D3C33BEE5DC6542F967D
File Size:
178.02 KB, 178024 bytes
|
|
MD5:
f06bb0ccfac60369651ea821d8a19bfe
SHA1:
34bea79397f8adac74aea195804224ca3c3bddfb
SHA256:
ADB6FEA52A6EE9BBF10EEDBF175C689979A58980919A0438B5F67F94C880E1C6
File Size:
660.06 KB, 660064 bytes
|
|
MD5:
f9b609aaa3c0e1ba7c4db25de7914221
SHA1:
520dd913a1303042df3b5878e92ba676c2819946
SHA256:
B40AE1F02F077A8B9F029B78BAF2B9C5C72C3F3C6AD9C20860F4C8295FC3D44D
File Size:
195.43 KB, 195432 bytes
|
|
MD5:
1e0349488247d7864200f1e25c037c2d
SHA1:
e212aa6a39c4bf358e69a4974b24fd7e8ecb6c64
SHA256:
8600C5EF0113803F1959F153F42354F9FD8BE48B1723462073E32185EF94A8B1
File Size:
642.67 KB, 642672 bytes
|
Show More
|
MD5:
cea45b45257b16374bbb54f7c5edf361
SHA1:
edc160b879b2697c30a6aac5ea59572d98f6e352
SHA256:
036C4C465E026E9C0B177AAFBEA38D7A3FA6C9A495CB584E2FAEFFCD10190F28
File Size:
428.52 KB, 428518 bytes
|
|
MD5:
8fda14ad9ff6379fef7dcba2eda4ca32
SHA1:
3b616c272e027ef0a5201ca9d808c5900d996495
SHA256:
8FDDFDFC89F79131CBB8F3E2CC96C4FD3608ED9B26BE7353DC0A42418A8B3FE3
File Size:
205.86 KB, 205856 bytes
|
|
MD5:
b1d8b85091b603900e909a5c85c1fcf4
SHA1:
f0a00228445a90abc0ba567845c5bdf6aeda8720
SHA256:
8F1BBFCB8589491265BE6C93FEBB504017A6EE96B96222EEA4DE7D4FAE1F118F
File Size:
529.48 KB, 529480 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have debug information
- File doesn't have exports table
- File doesn't have relocations information
- File doesn't have security information
- File has been packed
- File is 32-bit executable
- File is either console or GUI application
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is Native application (NOT .NET application)
Show More
- File is not packed
- IMAGE_FILE_DLL is not set inside PE header (Executable)
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
File Icons
File Icons
This section displays icon resources found within family samples. Malware often replicates icons commonly associated with legitimate software to mislead users into believing the malware is safe.Windows PE Version Information
Windows PE Version Information
This section displays values and attributes that have been set in the Windows file version information data structure for samples within this family. To mislead users, malware actors often add fake version information mimicking legitimate software.| Name | Value |
|---|---|
| Company Name | Rapiddown |
| File Description | DownloaddMger |
| File Version |
|
| Internal Name | install |
| Legal Copyright | copyright·©·2013 |
| Original Filename | ¡nstal·exe |
| Product Version | 3.0.26 |
Digital Signatures
Digital Signatures
This section lists digital signatures that are attached to samples within this family. When analyzing and verifying digital signatures, it is important to confirm that the signature’s root authority is a well-known and trustworthy entity and that the status of the signature is good. Malware is often signed with non-trustworthy “Self Signed” digital signatures (which can be easily created by a malware author with no verification). Malware may also be signed by legitimate signatures that have an invalid status, and by signatures from questionable root authorities with fake or misleading “Signer” names.| Signer | Root | Status |
|---|---|---|
| RAPIDDOWN | DigiCert Assured ID Root CA | Root Not Trusted |
| Imbernes Premium s.l. | GlobalSign CodeSigning CA - G2 | Self Signed |
| Moresta Holdings Limited | UTN-USERFirst-Object | Root Not Trusted |
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 530 |
|---|---|
| Potentially Malicious Blocks: | 79 |
| Whitelisted Blocks: | 450 |
| Unknown Blocks: | 1 |
Visual Map
? - Unknown Block
x - Potentially Malicious Block
Files Modified
Files Modified
This section lists files that were created, modified, moved and/or deleted by samples in this family. File system activity can provide valuable insight into how malware functions on the operating system.| File | Attributes |
|---|---|
| c:\users\user\appdata\local\temp\bitool.xxx | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\n1890\s1890.exe | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\n3747\ins3747.exe | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\n3836\ins3836.exe | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\n768\s768.exe | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsc2fd2.tmp\banner.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsc2fd2.tmp\inetc.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsc2fd2.tmp\math.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsc2fd2.tmp\md5dll.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsc2fd2.tmp\modern-wizard.bmp | Generic Write,Read Attributes |
Show More
| c:\users\user\appdata\local\temp\nsc2fd2.tmp\nsdialogs.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsc2fd2.tmp\system.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\3b179347615b32fe859ceabbe50c3ee6_1482135258fbe767ae04e6b2cbe1f88d | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\7d266d9e1e69fa1eefb9699b009b34c8_0a9bfdd75b598c2110cbf610c078e6e6 | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\8a9510437cb4eeb09f4b3ac2bc980e19 | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\8dfdf057024880d7a081afbf6d26b92f | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\9a19adad9d098e039450abbedd5616eb_90988534438596fe5d238c3ba6208526 | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\a89dfcc31c360ba5cbd616749b1b1c5d | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\c8e7ec0c85688f4738f3be49b104ba67 | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\3b179347615b32fe859ceabbe50c3ee6_1482135258fbe767ae04e6b2cbe1f88d | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\7d266d9e1e69fa1eefb9699b009b34c8_0a9bfdd75b598c2110cbf610c078e6e6 | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\8a9510437cb4eeb09f4b3ac2bc980e19 | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\8dfdf057024880d7a081afbf6d26b92f | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\9a19adad9d098e039450abbedd5616eb_90988534438596fe5d238c3ba6208526 | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\a89dfcc31c360ba5cbd616749b1b1c5d | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\c8e7ec0c85688f4738f3be49b104ba67 | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\windows\assembly | Synchronize,Write Attributes |
Registry Modifications
Registry Modifications
This section lists registry keys and values that were created, modified and/or deleted by samples in this family. Windows Registry activity can provide valuable insight into malware functionality. Additionally, malware often creates registry values to allow itself to automatically start and indefinitely persist after an initial infection has compromised the system.| Key::Value | Data | API Name |
|---|---|---|
| HKLM\system\controlset001\control\session manager::pendingfilerenameoperations | \??\C:\Windows\SystemTemp\a9dd6c3f-d641-4292-855a-e9c09c1b694b.tmp \??\C:\Windows\SystemTemp\85968c61-a19d-4e7b-a80f-d2a1fc3c08 | RegNtPreCreateKey |
| HKLM\system\controlset001\control\session manager::pendingfilerenameoperations | \??\C:\Windows\SystemTemp\a9dd6c3f-d641-4292-855a-e9c09c1b694b.tmp \??\C:\Windows\SystemTemp\85968c61-a19d-4e7b-a80f-d2a1fc3c08 | RegNtPreCreateKey |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect | RegNtPreCreateKey |
Show More
| HKLM\software\microsoft\systemcertificates\authroot\certificates\4eb6d578499b1ccf5f581ead56be3d9b6744a5e5::blob | ់㹧ৢ䗾鍗ᳺ ứ霞輫穆轙⊩㢅즔S c 愰ℰଆ虠ňŅᜇ〆〒ؐ⬊ĆĄ㞂ļ́ダ؟怉䢆蘁泽ĂሰူਆثЁ舁㰷āȃ쀀ᬰԆ腧Č〃〒ؐ⬊ĆĄ㞂ļ́翀 Ā ⨀ ب⬈Ćԅ̇⬈Ćԅ̇⬈Ćԅ̇⬈Ćԅ̇ँ Ā ⨀ ب⬈Ćԅ̇⬈Ćԅ | RegNtPreCreateKey |
| HKLM\software\microsoft\systemcertificates\authroot\certificates\4eb6d578499b1ccf5f581ead56be3d9b6744a5e5::blob | \ ص�6�hbu�B�Ҫ�7 N��xI��_X�V�=�gD��h ~ �/-�� ����\L�A��T�a V e r i S i g n �e�����0 �C9��313b �ϫ~C��k&*����e������d��� * 0( | RegNtPreCreateKey |
| HKLM\software\microsoft\systemcertificates\root\certificates\be36a4562fb2ee05dbb3d32323adf445084ed656::blob | \ Ѐ 볝蚽㾜ࠛ컯퇄춈ᔻ ᰘ兘槹镹⍋ . Thawte Timestamping CA ਰࠆثԁ܅ࠃ 㚾嚤눯돛⏓괣䗴丈囖 晿煺硩騠ᑑ莝⃚ ꗨ뺘芄ﺎ炮ᔑ㔁뉶 ʥ | RegNtPreCreateKey |
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API usage analysis is a valuable tool that can help identify malicious activity, such as keylogging, security privilege escalation, data encryption, data exfiltration, interference with antivirus software, and network request manipulation.| Category | API |
|---|---|
| Anti Debug |
|
| User Data Access |
|
| Process Manipulation Evasion |
|
| Process Shell Execute |
|
| Syscall Use |
Show More
2 additional items are not displayed above. |
| Encryption Used |
|
| Network Wininet |
|
| Network Info Queried |
|
Shell Command Execution
Shell Command Execution
This section lists Windows shell commands that are run by the samples in this family. Windows Shell commands are often leveraged by malware for nefarious purposes and can be used to elevate security privileges, download and launch other malware, exploit vulnerabilities, collect and exfiltrate data, and hide malicious activity.
s1890.exe 30cb3dae7b4f397e0a5a9108uL6KamSNxbsl/Wecags7y73LNZQPW+uSWU5Sxg0COmpLiC8ruo5Ai5eK+m4joydHyxhFdkZhMfDq/FUByLH/A94eOVBWUT8vyjWSp2hv3Unjvp01lNZhove/rME9gL7OjVdIknuE0ZY4ya5zarIcTR6J /v "c:\users\user\downloads\045a0700ba81030a479fd6f041d5eb1a388cdc3d_0000526432"
|
open C:\Users\Kbbzzxwt\AppData\Local\Temp\\n3836\ins3836.exe ins.exe /e5610583 /u50d1d9d5-cf90-407c-820a-35e05bc06f2f
|
open C:\Users\Qtctuuqa\AppData\Local\Temp\\n3747\ins3747.exe ins.exe /e12091047 /u50af3520-6b08-4b9d-a6b2-07165bc06f2f
|
s768.exe baee47db5d4108c126c7ec9abOZXq/fkBtNkpsvrsQ9LCwLpZDg/janIfhJ88E7eARsCNA4tC+CgNR9aL/aDUE9cPng4z/wrX1ESP/cEk4J9xatBk/8PpMqNqdIhgJkkOdVGRL6CPsov01/ye7yzdLh0cZ2WxEk4fu3WeqOvG/CovSdB /v "c:\users\user\downloads\f0a00228445a90abc0ba567845c5bdf6aeda8720_0000529480"
|