Threat Database Trojans Trojan.Filecoder.NE

Trojan.Filecoder.NE

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 23,184
Threat Level: 80 % (High)
Infected Computers: 2
First Seen: January 11, 2023
Last Seen: June 3, 2026
OS(es) Affected: Windows

The detection of Trojan.Filecoder.NE on your system indicates a potential security threat that requires immediate attention. This Trojan-type threat can cause significant damage to your files and compromise your personal data. It is essential to understand the nature of this threat and take prompt action to remove it from your system.

What Is Trojan.Filecoder.NE?

Trojan.Filecoder.NE is a type of malware that can infect your system and cause harm to your files and data. The name "Trojan" refers to the fact that this malware can disguise itself as a legitimate program or file, making it difficult to detect. The ".Filecoder" part of the name suggests that this malware may be capable of encrypting or modifying files on your system. It is crucial to note that the exact capabilities and intentions of Trojan.Filecoder.NE may vary, and it is essential to take a comprehensive approach to remove it from your system.

How Trojan.Filecoder.NE Operates

Trojan.Filecoder.NE can operate in various ways, but its primary goal is to infect your system and cause harm. It may spread through malicious downloads, infected email attachments, or exploited vulnerabilities in your system. Once inside, it can start modifying files, stealing sensitive information, or even taking control of your system. The malware may also communicate with its creators, allowing them to remotely control your system or steal your data. It is essential to be cautious when opening email attachments or downloading files from the internet, as these can be common entry points for malware like Trojan.Filecoder.NE.

Symptoms of Infection

The symptoms of a Trojan.Filecoder.NE infection can vary, but common signs include slow system performance, unexpected crashes, or strange behavior from your programs. You may also notice that your files are missing or have been modified without your knowledge. In some cases, you may receive ransom demands or messages from the malware creators, asking you to pay a fee to restore access to your files. It is essential to be aware of these symptoms and take immediate action if you suspect that your system is infected.

  • Slow system performance or crashes
  • Missing or modified files
  • Strange behavior from programs or system components
  • Ransom demands or messages from unknown sources

How to Remove Trojan.Filecoder.NE

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for a clean removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malicious components.
  3. Uninstall any suspicious programs or applications that may be related to the malware.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform another full scan with your anti-malware tool to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.Filecoder.NE from your system requires a comprehensive approach that involves understanding the nature of the threat, identifying the symptoms of infection, and taking prompt action to remove the malware. By following the steps outlined above, you can help protect your system and data from the harmful effects of this Trojan-type threat. Remember to always be cautious when interacting with the internet, and keep your anti-malware tools and operating system up to date to prevent future infections.

Analysis Report

General information

Family Name: Trojan.Filecoder.NE
Signature status: No Signature

Known Samples

MD5: f72d3cc203294e55ba75b711cf4c1afc
SHA1: 91f8d9132cce1f6a2357affe7c2ea6173e525cc6
SHA256: 911AA8285F6AA4F6E94B088E8622C54A4A06FFE8234B912D4336B9E165CA125E
File Size: 56.83 KB, 56832 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name Microsoft Corporation
File Description Host Process for Windows Services
File Version 6.1.7601.23403 (win7sp1_ldr.160325-0600
Internal Name svchost.exe
Legal Copyright Microsoft Corporation. All rights reserved.
Original Filename svchost.exe
Product Name Microsoft Windows Operating System
Product Version 6.1.7601.23403

File Traits

  • x86

Block Information

Total Blocks: 67
Potentially Malicious Blocks: 45
Whitelisted Blocks: 20
Unknown Blocks: 2

Visual Map

x x x 0 0 x 0 x 0 0 0 x x x x x x x 0 0 x x x x x 0 x x x x x x x 0 x 0 x x x x x 0 x x ? x x x ? x x x x 0 x x x x x x 2 1 2 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.VD
  • Filecoder.NE

Files Modified

File Attributes
c:\$winreagent\how to restore your files.html Generic Write,Read Attributes
c:\$winreagent\how to restore your files.html Synchronize,Write Attributes
c:\$winreagent\how to restore your files.html.c313b713 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\$winreagent\how to restore your files.html.c313b713 Synchronize,Write Data
c:\$winreagent\scratch\how to restore your files.html Generic Write,Read Attributes
c:\$winreagent\scratch\how to restore your files.html Synchronize,Write Attributes
c:\$winreagent\scratch\how to restore your files.html.c313b713 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\$winreagent\scratch\how to restore your files.html.c313b713 Synchronize,Write Data
c:\bootnxt Synchronize,Write Attributes
c:\bootnxt.531fe580 Generic Read,Write Data,Write Attributes,Write extended,Append data
Show More
c:\bootnxt.531fe580 Synchronize,Write Data
c:\documents and settings\how to restore your files.html Generic Write,Read Attributes
c:\how to restore your files.html Generic Write,Read Attributes
c:\inetpub\how to restore your files.html Generic Write,Read Attributes
c:\inetpub\how to restore your files.html Synchronize,Write Attributes
c:\inetpub\how to restore your files.html.c313b713 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\inetpub\how to restore your files.html.c313b713 Synchronize,Write Data
c:\pagefile.sys Synchronize,Write Attributes
c:\perflogs\how to restore your files.html Generic Write,Read Attributes
c:\perflogs\how to restore your files.html Synchronize,Write Attributes
c:\perflogs\how to restore your files.html.c313b713 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\perflogs\how to restore your files.html.c313b713 Synchronize,Write Data
c:\recovery\how to restore your files.html Generic Write,Read Attributes
c:\recovery\how to restore your files.html Synchronize,Write Attributes
c:\recovery\how to restore your files.html.c313b713 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\recovery\how to restore your files.html.c313b713 Synchronize,Write Data
c:\sandbox_local\how to restore your files.html Generic Write,Read Attributes
c:\sandbox_local\how to restore your files.html Synchronize,Write Attributes
c:\sandbox_local\how to restore your files.html.c313b713 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\sandbox_local\how to restore your files.html.c313b713 Synchronize,Write Data
c:\sandbox_stage\how to restore your files.html Generic Write,Read Attributes
c:\sandbox_stage\how to restore your files.html Synchronize,Write Attributes
c:\sandbox_stage\how to restore your files.html.c313b713 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\sandbox_stage\how to restore your files.html.c313b713 Synchronize,Write Data
c:\sandbox_stage\logs\how to restore your files.html Generic Write,Read Attributes
c:\sandbox_stage\logs\how to restore your files.html Synchronize,Write Attributes
c:\sandbox_stage\logs\how to restore your files.html.c313b713 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\sandbox_stage\logs\how to restore your files.html.c313b713 Synchronize,Write Data
c:\sandbox_stage\mnt\how to restore your files.html Generic Write,Read Attributes
c:\sandbox_stage\mnt\how to restore your files.html Synchronize,Write Attributes
c:\sandbox_stage\mnt\how to restore your files.html.c313b713 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\sandbox_stage\mnt\how to restore your files.html.c313b713 Synchronize,Write Data
c:\sandbox_stage\mnt\nas\amas_test_data\how to restore your files.html Generic Write,Read Attributes
c:\sandbox_stage\mnt\nas\amas_test_data\malware\how to restore your files.html Generic Write,Read Attributes
c:\sandbox_stage\mnt\nas\how to restore your files.html Generic Write,Read Attributes
c:\sandbox_stage\mnt\nas\how to restore your files.html Synchronize,Write Attributes
c:\sandbox_stage\mnt\nas\how to restore your files.html.c313b713 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\sandbox_stage\mnt\nas\how to restore your files.html.c313b713 Synchronize,Write Data
c:\swapfile.sys Synchronize,Write Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe I�@�m�� RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe �H�m�� RegNtPreCreateKey

Windows API Usage

Category API
Encryption Used
  • CryptAcquireContext
Service Control
  • OpenSCManager
  • OpenService
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • ShellExecute
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
Show More
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation

Shell Command Execution

open cmd.exe /c vssadmin.exe delete shadows /all /quiet

Trending

Most Viewed

Loading...