Threat Database Trojans Trojan.Filecoder.EO

Trojan.Filecoder.EO

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 4
First Seen: February 7, 2025
Last Seen: April 7, 2026
OS(es) Affected: Windows

The detection of Trojan.Filecoder.EO on your system indicates a potential security threat that requires immediate attention. This type of threat is known to cause significant damage to your files and compromise your system's security. It is essential to understand the nature of this threat and take prompt action to remove it and prevent future infections.

What Is Trojan.Filecoder.EO?

Trojan.Filecoder.EO is a type of Trojan horse malware that can infect your system and cause harm to your files and data. The name "Trojan" refers to the fact that this type of malware disguises itself as a legitimate program or file, allowing it to bypass your system's security defenses. The ".Filecoder" part of the name suggests that this malware may be capable of encrypting or modifying files on your system, while the ".EO" suffix may indicate a specific variant or subtype of the malware.

How Trojan.Filecoder.EO Operates

Trojan.Filecoder.EO, like other types of malware, operates by exploiting vulnerabilities in your system's security or by tricking you into installing it. Once installed, it can start causing damage to your files and data. This type of malware can spread through various means, including infected email attachments, compromised websites, or infected software downloads. It can also be spread through infected USB drives or other external devices.

Once Trojan.Filecoder.EO infects your system, it can start encrypting or modifying files, making them inaccessible to you. It may also create backdoors or open ports, allowing hackers to access your system remotely and steal sensitive information. In some cases, this type of malware can also install additional malware or viruses on your system, leading to further damage and compromise.

Symptoms of Infection

The symptoms of a Trojan.Filecoder.EO infection can vary, but common signs include unusual system behavior, slow performance, and unexpected errors or crashes. You may also notice that your files are encrypted or modified, or that you are unable to access certain files or programs. In some cases, you may receive ransom demands or messages from hackers, demanding payment in exchange for the decryption key or other sensitive information.

  • Unusual system behavior or crashes
  • Slow system performance
  • Encrypted or modified files
  • Unexpected errors or messages
  • Ransom demands or messages from hackers

How to Remove Trojan.Filecoder.EO

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow you to download and install removal tools.
  2. Download and install a reputable anti-malware tool, such as SpyHunter, and run a full scan to detect and remove the malware.
  3. Uninstall any suspicious programs or applications that may be related to the malware.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and run another full scan to ensure that the malware has been completely removed.

Conclusion

In conclusion, the detection of Trojan.Filecoder.EO on your system is a serious security threat that requires immediate attention. By understanding the nature of this threat and taking prompt action to remove it, you can prevent further damage and compromise to your system and data. Remember to always be cautious when downloading software or opening email attachments, and to keep your system and security software up to date to prevent future infections.

Analysis Report

General information

Family Name: Trojan.Filecoder.EO
Signature status: No Signature

Known Samples

MD5: f3d23d1379aaf6e3e1f9d0184fd83398
SHA1: 6e65a3217989c266dc5da645b10df3964bdf081f
SHA256: CE13BF13BA591B1EFB3CF3B62FA2B7965ABB15207E23E71A40A6926382038ACC
File Size: 3.31 MB, 3313592 bytes
MD5: 71e96cce64f727cd8ad9fc98f1b11a92
SHA1: 421d09ee693176f8a2b2b82eb7c8ea217431377c
SHA256: 337B282ADEDC43C2D6CD95753559DEC08F552804DEA722E3F0B96BD68C162581
File Size: 1.61 MB, 1608192 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Google LLC
Company Short Name Google
File Description Google Installer (x86)
File Version 144.0.7547.0
Internal Name Google Installer (x86)
Last Change 43ff84ab4732e1864649c417ca17b1c2149d1179-refs/branch-heads/7547@{#1}
Legal Copyright Copyright 2025 Google LLC. All rights reserved.
Official Build 1
Original Filename UpdaterSetup.exe
Product Name Google Installer (x86)
Product Short Name GoogleUpdater
Product Version 144.0.7547.0

Digital Signatures

Signer Root Status
Google LLC DigiCert Trusted Root G4 Hash Mismatch

File Traits

  • CryptUnprotectData
  • GetConsoleWindow
  • HighEntropy
  • Installer Version
  • No CryptProtectData
  • No Version Info
  • packed
  • x64

Block Information

Total Blocks: 14,185
Potentially Malicious Blocks: 47
Whitelisted Blocks: 13,825
Unknown Blocks: 313

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 ? ? 0 x x 0 0 0 0 0 0 0 0 0 ? 0 ? 0 ? ? 0 x x 0 0 0 ? 0 ? 0 ? ? 0 0 0 0 ? 0 0 0 0 0 0 0 ? x ? ? ? 0 ? ? ? 0 ? ? ? 0 0 0 0 ? ? 0 ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? 0 ? 0 ? 0 0 ? ? ? 0 0 0 0 ? ? 0 0 0 ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? ? ? ? 0 0 0 0 0 ? ? 0 0 0 ? ? ? ? ? ? ? ? ? 0 ? 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? 0 ? 0 0 ? ? 0 ? ? ? ? ? ? ? 0 ? 0 ? ? ? 0 ? ? ? ? ? ? ? 0 ? 0 ? ? ? 0 ? ? ? ? ? ? ? 0 ? 0 ? ? ? 0 ? ? ? ? ? ? ? 0 ? 0 ? ? ? 0 ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? 0 0 0 0 ? 0 ? ? ? 0 0 ? ? ? x 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? 0 ? ? 0 ? 0 ? ? ? ? 0 ? ? ? ? 0 0 ? 0 ? 0 0 ? 0 0 ? ? 0 0 0 0 0 0 ? 0 ? ? 0 0 0 ? ? 0 0 0 0 0 0 0 0 ? ? 0 ? 0 ? ? 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 x ? ? 0 ? ? 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? 0 ? ? ? 0 ? 0 ? ? 0 ? 0 0 0 0 0 0 0 ? ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 x 0 ? x 0 0 0 0 0 0 0 0 0 0 x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.HGDK
  • Agent.YT
  • Agent.YTI
  • Agent.YTJ
  • Downloader.Agent.GM
Show More
  • Filecoder.ABWE
  • Filecoder.BFA
  • Filecoder.FBH
  • Keylogger.DN
  • PSW.Agent.FGG
  • PSW.Agent.WG

Files Modified

File Attributes
c:\users\user\appdata\local\temp\dc5704e0.bin Generic Write,Read Attributes

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtProtectVirtualMemory
Show More
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Process Terminate
  • TerminateProcess
Network Winsock2
  • WSASend
  • WSASocket
  • WSAStartup
Network Winsock
  • closesocket
  • connect
  • freeaddrinfo
  • getaddrinfo

Trending

Most Viewed

Loading...