Threat Database Trojans Trojan.Downloader.Firseria

Trojan.Downloader.Firseria

By CagedTech in Trojans
Published:
Last updated:

Threat Scorecard

Popularity Rank: 10,428
Threat Level: 80 % (High)
Infected Computers: 728
First Seen: August 22, 2018
Last Seen: September 29, 2026
OS(es) Affected: Windows

The detection of Trojan.Downloader.Firseria on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to download and install additional malicious software on your computer, which can lead to a range of problems, including data theft, system crashes, and unauthorized access to your personal information.

What Is Trojan.Downloader.Firseria?

Trojan.Downloader.Firseria is a type of Trojan horse malware that is designed to download and install additional malicious software on your computer. The name "Trojan" refers to the fact that this type of malware disguises itself as a legitimate program or file, allowing it to bypass your system's security defenses. The "Downloader" part of the name indicates that this malware is capable of downloading and installing additional malicious software, which can include viruses, spyware, adware, and other types of malware.

How Trojan.Downloader.Firseria Operates

Trojan.Downloader.Firseria typically operates by exploiting vulnerabilities in your system's security or by tricking you into downloading and installing it. Once installed, it can download and install additional malicious software, which can include keyloggers, ransomware, and other types of malware. This malware can also communicate with its creators, allowing them to remotely control your system and steal your personal information. Trojan.Downloader.Firseria can be difficult to detect, as it can disguise itself as a legitimate program or file, and it may not exhibit any obvious symptoms of infection.

Symptoms of Infection

While Trojan.Downloader.Firseria may not exhibit any obvious symptoms of infection, there are some signs that may indicate that your system is infected. These can include slow system performance, unexpected pop-ups or ads, unfamiliar programs or files on your system, and unexplained changes to your system's settings or configuration. If you suspect that your system is infected with Trojan.Downloader.Firseria, it is essential to take immediate action to remove the malware and prevent further damage.

How to Remove Trojan.Downloader.Firseria

  1. Restart your system in Safe Mode with Networking to prevent the malware from loading and to allow you to download and install removal tools.
  2. Download and install a reputable anti-malware tool, such as SpyHunter, and perform a full scan of your system to detect and remove the malware.
  3. Uninstall any suspicious programs or applications that may be related to the malware.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform another scan with your anti-malware tool to ensure that the malware has been completely removed.

Conclusion

The removal of Trojan.Downloader.Firseria requires careful attention to detail and a thorough understanding of the malware's behavior and characteristics. By following the steps outlined above, you can help to ensure that your system is completely free of the malware and that your personal information is protected. It is also essential to take steps to prevent future infections, including keeping your operating system and software up to date, using strong antivirus software, and avoiding suspicious downloads and email attachments. By taking these precautions, you can help to protect your system and your personal information from the threats posed by Trojan.Downloader.Firseria and other types of malware.

Analysis Report

General information

Family Name: Trojan.Downloader.Firseria
Signature status: Self Signed

Known Samples

MD5: 74419fcafd5b0cf8b66b4040a824442b
SHA1: 045a0700ba81030a479fd6f041d5eb1a388cdc3d
SHA256: A676B802990386764F43AA6FC32034458CA499B765E5B08F19A314759BBE52AF
File Size: 526.43 KB, 526432 bytes
MD5: b2e4e7069c57a165c3c609d5ea9a4cef
SHA1: ff02bfbada66239b68e2cd2e66020238f7551964
SHA256: 765C8BF1009D1F39A2EB1147082F5BA58603F96F7860D3C33BEE5DC6542F967D
File Size: 178.02 KB, 178024 bytes
MD5: f06bb0ccfac60369651ea821d8a19bfe
SHA1: 34bea79397f8adac74aea195804224ca3c3bddfb
SHA256: ADB6FEA52A6EE9BBF10EEDBF175C689979A58980919A0438B5F67F94C880E1C6
File Size: 660.06 KB, 660064 bytes
MD5: f9b609aaa3c0e1ba7c4db25de7914221
SHA1: 520dd913a1303042df3b5878e92ba676c2819946
SHA256: B40AE1F02F077A8B9F029B78BAF2B9C5C72C3F3C6AD9C20860F4C8295FC3D44D
File Size: 195.43 KB, 195432 bytes
MD5: 1e0349488247d7864200f1e25c037c2d
SHA1: e212aa6a39c4bf358e69a4974b24fd7e8ecb6c64
SHA256: 8600C5EF0113803F1959F153F42354F9FD8BE48B1723462073E32185EF94A8B1
File Size: 642.67 KB, 642672 bytes
Show More
MD5: cea45b45257b16374bbb54f7c5edf361
SHA1: edc160b879b2697c30a6aac5ea59572d98f6e352
SHA256: 036C4C465E026E9C0B177AAFBEA38D7A3FA6C9A495CB584E2FAEFFCD10190F28
File Size: 428.52 KB, 428518 bytes
MD5: 8fda14ad9ff6379fef7dcba2eda4ca32
SHA1: 3b616c272e027ef0a5201ca9d808c5900d996495
SHA256: 8FDDFDFC89F79131CBB8F3E2CC96C4FD3608ED9B26BE7353DC0A42418A8B3FE3
File Size: 205.86 KB, 205856 bytes
MD5: b1d8b85091b603900e909a5c85c1fcf4
SHA1: f0a00228445a90abc0ba567845c5bdf6aeda8720
SHA256: 8F1BBFCB8589491265BE6C93FEBB504017A6EE96B96222EEA4DE7D4FAE1F118F
File Size: 529.48 KB, 529480 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Rapiddown
File Description DownloaddMger
File Version
  • 1.0.0.28
  • 1.0.0.27
Internal Name install
Legal Copyright copyright·©·2013
Original Filename ¡nstal·exe
Product Version 3.0.26

Digital Signatures

Signer Root Status
RAPIDDOWN DigiCert Assured ID Root CA Root Not Trusted
Imbernes Premium s.l. GlobalSign CodeSigning CA - G2 Self Signed
Moresta Holdings Limited UTN-USERFirst-Object Root Not Trusted

Block Information

Total Blocks: 530
Potentially Malicious Blocks: 79
Whitelisted Blocks: 450
Unknown Blocks: 1

Visual Map

x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 x x 0 0 x x x 0 0 x 0 0 x x 0 x x 0 x x 0 0 x x x x x x x 0 x 0 x 0 0 x x 0 0 x x x x x x x x x 0 x x ? 0 x x x x 0 0 0 x x x x x x x x x x x x x x x x x x 0 0 0 x 0 0 0 x x 0 0 0 x x x x x x x x x 0 0 x x x x 0 0 x 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 2 3 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 1 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 1 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 2 2 1 0 0 0 0 0 0 0 0 0 0 1 0 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\appdata\local\temp\bitool.xxx Generic Write,Read Attributes
c:\users\user\appdata\local\temp\n1890\s1890.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\n3747\ins3747.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\n3836\ins3836.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\n768\s768.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsc2fd2.tmp\banner.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsc2fd2.tmp\inetc.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsc2fd2.tmp\math.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsc2fd2.tmp\md5dll.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsc2fd2.tmp\modern-wizard.bmp Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\nsc2fd2.tmp\nsdialogs.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsc2fd2.tmp\system.dll Generic Write,Read Attributes
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\3b179347615b32fe859ceabbe50c3ee6_1482135258fbe767ae04e6b2cbe1f88d Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\7d266d9e1e69fa1eefb9699b009b34c8_0a9bfdd75b598c2110cbf610c078e6e6 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\8a9510437cb4eeb09f4b3ac2bc980e19 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\8dfdf057024880d7a081afbf6d26b92f Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\9a19adad9d098e039450abbedd5616eb_90988534438596fe5d238c3ba6208526 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\a89dfcc31c360ba5cbd616749b1b1c5d Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\c8e7ec0c85688f4738f3be49b104ba67 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\3b179347615b32fe859ceabbe50c3ee6_1482135258fbe767ae04e6b2cbe1f88d Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\7d266d9e1e69fa1eefb9699b009b34c8_0a9bfdd75b598c2110cbf610c078e6e6 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\8a9510437cb4eeb09f4b3ac2bc980e19 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\8dfdf057024880d7a081afbf6d26b92f Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\9a19adad9d098e039450abbedd5616eb_90988534438596fe5d238c3ba6208526 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\a89dfcc31c360ba5cbd616749b1b1c5d Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\c8e7ec0c85688f4738f3be49b104ba67 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\assembly Synchronize,Write Attributes

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations \??\C:\Windows\SystemTemp\a9dd6c3f-d641-4292-855a-e9c09c1b694b.tmp\??\C:\Windows\SystemTemp\85968c61-a19d-4e7b-a80f-d2a1fc3c08 RegNtPreCreateKey
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations \??\C:\Windows\SystemTemp\a9dd6c3f-d641-4292-855a-e9c09c1b694b.tmp\??\C:\Windows\SystemTemp\85968c61-a19d-4e7b-a80f-d2a1fc3c08 RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
Show More
HKLM\software\microsoft\systemcertificates\authroot\certificates\4eb6d578499b1ccf5f581ead56be3d9b6744a5e5::blob ់㇤㹧ৢ䗾鍗૳ᳺứ霞輫穆轙⊩㢅즔Sc愰ℰଆ虠ňŅᜇ〆〒ؐ⬊ĆĄ㞂ļ́ダ؟怉䢆蘁泽ĂሰူਆثЁ舁㰷āȃ쀀ᬰԆ腧Č〃〒ؐ⬊ĆĄ㞂ļ́翀Ā⨀ ب⬈Ćԅ̇؂⬈Ćԅ̇؃⬈Ćԅ̇؄⬈Ćԅ̇ँĀ⨀ ب⬈Ćԅ̇؂⬈Ćԅ RegNtPreCreateKey
HKLM\software\microsoft\systemcertificates\authroot\certificates\4eb6d578499b1ccf5f581ead56be3d9b6744a5e5::blob \ص�6�hbu�B�Ҫ�7N��xI��_X�V�=�gD��h~�/-������\L�A��T�a VeriSign�e�����0 �C9��313b �ϫ~C�؀�k&*����e������d��� *0( RegNtPreCreateKey
HKLM\software\microsoft\systemcertificates\root\certificates\be36a4562fb2ee05dbb3d32323adf445084ed656::blob \Ѐ볝蚽㾜ࠛ컯퇄춈ᔻᰘ兘槹镹⍋ .Thawte Timestamping CA  ਰࠆثԁ܅ࠃ㚾嚤눯׮돛⏓괣䗴丈囖晿煺硩騠ᑑ莝⃚ꗨ뺘芄ﺎ炮ᔑ㔁뉶 ʥ RegNtPreCreateKey

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserName
  • GetUserObjectInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • ShellExecuteEx
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreateResourceReserve
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcDeleteSecurityContext
  • ntdll.dll!NtAlpcDisconnectPort
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcQueryInformationMessage
Show More
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtAlpcSetInformation
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDeleteValueKey
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtGetCompleteWnfStateSubscription
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtPowerInformation
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryEvent
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtQueueApcThread
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationObject
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetSecurityObject
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtUnsubscribeWnfStateChange
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady

2 additional items are not displayed above.

Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Network Wininet
  • HttpOpenRequest
  • HttpQueryInfo
  • HttpSendRequest
  • InternetConnect
  • InternetOpen
  • InternetOpenUrl
  • InternetQueryOption
  • InternetSetOption
Network Info Queried
  • GetAdaptersInfo

Shell Command Execution

s1890.exe 30cb3dae7b4f397e0a5a9108uL6KamSNxbsl/Wecags7y73LNZQPW+uSWU5Sxg0COmpLiC8ruo5Ai5eK+m4joydHyxhFdkZhMfDq/FUByLH/A94eOVBWUT8vyjWSp2hv3Unjvp01lNZhove/rME9gL7OjVdIknuE0ZY4ya5zarIcTR6J /v "c:\users\user\downloads\045a0700ba81030a479fd6f041d5eb1a388cdc3d_0000526432"
open C:\Users\Kbbzzxwt\AppData\Local\Temp\\n3836\ins3836.exe ins.exe /e5610583 /u50d1d9d5-cf90-407c-820a-35e05bc06f2f
open C:\Users\Qtctuuqa\AppData\Local\Temp\\n3747\ins3747.exe ins.exe /e12091047 /u50af3520-6b08-4b9d-a6b2-07165bc06f2f
s768.exe baee47db5d4108c126c7ec9abOZXq/fkBtNkpsvrsQ9LCwLpZDg/janIfhJ88E7eARsCNA4tC+CgNR9aL/aDUE9cPng4z/wrX1ESP/cEk4J9xatBk/8PpMqNqdIhgJkkOdVGRL6CPsov01/ye7yzdLh0cZ2WxEk4fu3WeqOvG/CovSdB /v "c:\users\user\downloads\f0a00228445a90abc0ba567845c5bdf6aeda8720_0000529480"