Threat Database Trojans Trojan.MSIL.Downloader.Agent.ANFI

Trojan.MSIL.Downloader.Agent.ANFI

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 25
First Seen: November 21, 2023
Last Seen: December 2, 2025
OS(es) Affected: Windows

The detection of Trojan.MSIL.Downloader.Agent.ANFI on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the security of your computer, allowing unauthorized access and potentially leading to further malicious activities. It is essential to understand the nature of this threat and take prompt action to remove it and prevent future infections.

What Is Trojan.MSIL.Downloader.Agent.ANFI?

Trojan.MSIL.Downloader.Agent.ANFI is a type of Trojan horse malware that can be used to download and install additional malicious software on your computer. The name suggests that it is written in MSIL (Microsoft Intermediate Language), which is a platform-agnostic intermediate representation of the .NET Framework. This allows the malware to run on any system that supports the .NET Framework, making it a versatile and potentially widespread threat.

How Trojan.MSIL.Downloader.Agent.ANFI Operates

Once installed on your system, Trojan.MSIL.Downloader.Agent.ANFI can operate in various ways, depending on its intended purpose. It may download and install additional malware, such as keyloggers, ransomware, or spyware, to steal sensitive information or disrupt your system's operation. It can also create backdoors, allowing remote access to your computer, or modify system settings to disable security features and evade detection. The malware may also communicate with its command and control servers to receive updates or transmit stolen data.

Symptoms of Infection

The symptoms of a Trojan.MSIL.Downloader.Agent.ANFI infection can vary, but common indicators include slow system performance, unexpected pop-ups or advertisements, and unfamiliar programs or icons on your desktop. You may also notice unusual network activity, such as increased data usage or unfamiliar connections. In some cases, the malware may not exhibit any noticeable symptoms, making it difficult to detect without the aid of security software.

How to Remove Trojan.MSIL.Downloader.Agent.ANFI

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for easier removal.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove the malware and any associated files.
  3. Uninstall any suspicious programs or applications that may be related to the malware.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your computer and perform another full scan to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.MSIL.Downloader.Agent.ANFI from your system requires a combination of technical knowledge and the right tools. By following the steps outlined above and maintaining good security practices, such as keeping your operating system and software up to date, using strong passwords, and avoiding suspicious downloads, you can help prevent future infections and protect your computer from malicious threats. Remember to always be cautious when browsing the internet and to use reputable security software to detect and remove any potential threats before they can cause harm.

Analysis Report

General information

Family Name: Trojan.MSIL.Downloader.Agent.ANFI
Signature status: No Signature

Known Samples

MD5: 42cebc943ce6a5ecde9b2648954df9c3
SHA1: 93b5bcc3cde88938c41eeb530f7d453fa56c19a9
SHA256: C82A409FFB78F28ABD0105AEB328041D9FA6E2720F970D7865F8CC8E95E4882A
File Size: 2.93 MB, 2929152 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
File Version 1.0.0.0
Internal Name Azor.exe
Original Filename Azor.exe
Product Version 1.0.0.0

File Traits

  • .NET
  • GenKrypt
  • HighEntropy
  • x86

Block Information

Total Blocks: 1,695
Potentially Malicious Blocks: 246
Whitelisted Blocks: 711
Unknown Blocks: 738

Visual Map

x ? ? ? ? 0 0 x 0 ? 0 x 0 0 0 0 0 0 0 ? 0 ? x ? 0 0 0 x 0 ? 0 0 0 ? x ? ? ? ? x ? ? ? 0 x 0 0 0 ? ? ? 0 0 0 0 ? 0 x ? ? ? 0 0 0 ? ? ? ? ? ? ? ? 0 0 0 0 x ? 0 0 0 0 0 ? ? ? 0 0 0 ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 ? x ? ? ? x x 0 0 x ? ? x ? 0 0 ? 0 x 0 ? ? 0 x ? ? ? ? ? ? ? ? ? ? ? x 0 0 0 0 0 0 ? 0 0 ? x ? ? ? 0 x x x 0 ? ? ? ? ? ? ? 0 x 0 0 0 0 0 0 0 0 0 x 0 ? 0 x ? ? x ? ? 0 x 0 0 0 0 0 x ? ? ? ? ? ? x 0 0 0 0 0 0 0 ? 0 ? 0 x ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 x 0 0 ? x ? ? ? 0 0 0 x x 0 x 0 0 ? ? ? 0 0 ? 0 ? 0 0 0 0 0 0 0 ? ? ? ? ? ? x ? 0 0 ? 0 ? ? ? x ? 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? ? ? x 0 0 0 0 x 0 0 0 ? 0 0 0 0 0 ? x ? x ? ? 0 0 0 ? ? ? ? 0 0 ? x ? 0 ? 0 0 0 0 x 0 0 0 0 ? ? ? 0 0 ? 0 0 0 0 ? 0 0 ? ? 0 ? ? ? ? 0 0 0 0 0 ? 0 ? x 0 0 ? 0 ? 0 ? 0 ? 0 0 x 0 x ? ? 0 0 ? ? x 0 0 0 ? x 0 0 ? x 0 0 ? x ? 0 ? ? x ? 0 0 ? ? x ? 0 ? x ? x 0 0 ? ? ? ? ? ? 0 ? 0 ? ? ? 0 0 0 0 0 0 0 0 ? ? ? ? ? 0 ? ? x 0 0 0 0 ? 0 0 0 x 0 0 ? 0 ? x ? ? ? ? ? ? ? ? ? x 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? x 0 0 0 0 0 0 0 0 x 0 0 ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? x ? x 0 0 ? ? x ? ? x x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x 0 0 0 0 0 0 0 0 x x x ? ? ? x 0 x x ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 0 ? ? x x 0 0 0 x x 0 0 0 0 0 ? ? ? ? 0 0 0 0 0 x 0 ? ? x 0 ? ? ? ? 0 ? ? ? ? ? ? ? 0 x 0 0 0 0 x x x x x ? 0 ? 0 ? 0 0 0 0 ? 0 ? 0 ? ? ? ? ? 0 0 0 0 x 0 0 x ? x x 0 0 0 ? ? 0 0 0 x ? 0 0 ? 0 0 x ? x 0 0 0 x ? 0 ? 0 ? 0 ? 0 ? 0 ? ? x 0 0 0 ? ? 0 ? ? x x x 0 x ? ? x 0 0 0 x 0 0 0 ? 0 ? 0 0 x x ? x 0 0 0 0 ? ? 0 x 0 0 x ? x ? x 0 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 ? 0 0 ? 0 ? 0 0 0 ? ? ? ? 0 0 x ? ? 0 x ? ? ? 0 ? ? ? ? ? 0 0 ? x 0 0 0 0 0 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? x 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 ? x ? ? 0 0 0 0 ? 0 ? ? 0 x x x x ? x x 0 ? x ? ? ? ? ? ? ? ? ? 0 ? ? ? ? x 0 ? ? x x 0 0 0 x x 0 0 0 0 0 0 0 x ? 0 ? x 0 ? 0 ? ? ? ? 0 0 ? ? x 0 0 0 0 ? x ? ? ? ? ? x ? ? ? ? ? ? ? ? x ? ? ? ? 0 0 0 0 0 ? ? ? ? x x ? x x ? 0 ? ? ? ? ? ? ? ? ? ? 0 ? x ? x ? ? ? ? ? ? x 0 0 0 0 ? ? x x ? ? ? x x ? x ? ? x ? ? x x ? ? ? ? ? x x ? x ? x ? ? x ? ? ? ? ? 0 0 0 0 0 ? x 0 ? 0 x x ? x 0 ? x 0 x x 0 ? ? ? x ? ? 0 0 0 0 ? 0 ? 0 ? ? x 0 0 ? 0 0 0 x 0 x x 0 0 x 0 0 0 0 0 ? ? 0 0 0 0 0 ? 0 ? x 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 x 0 0 0 ? ? ? ? x 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 ? ? ? x ? ? ? ? x 0 0 0 0 0 0 0 ? 0 x 0 0 0 0 ? ? 0 x ? 0 ? 0 0 x x x ? ? ? x 0 ? x ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? 0 ? ? ? x 0 0 0 x x 0 x 0 0 0 x ? 0 ? 0 0 ? ? ? ? ? x ? ? ? ? ? x 0 0 0 x ? 0 0 0 x x 0 0 0 0 0 ? 0 x 0 ? ? 0 ? ? 0 0 ? x ? ? ? ? ? ? 0 0 ? x ? 0 ? ? x 0 0 0 ? ? ? ? x x 0 0 ? ? ? 0 0 0 0 0 0 0 ? x ? ? ? ? 0 0 0 0 0 ? ? 0 0 0 0 0 0 ? x ? x ? ? ? ? ? ? ? x x ? 0 0 0 0 ? ? x ? ? ? ? ? ? x 0 0 0 ? x ? ? 0 0 x ? 0 ? x x ? 0 ? 0 ? ? ? 0 0 0 0 ? ? 0 ? 0 0 0 ? ? x ? ? x 0 ? ? ? x ? ? ? 0 0 0 0 0 x ? 0 0 0 0 0 x 0 ? 0 0 x x 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? x x x 0 0 0 0 ? 0 ? ? 0 0 x ? ? ? ? x 0 0 0 0 x ? 0 ? ? ? ? ? ? 0 ? x ? ? 0 ? x 0 0 x ? 0 0 ? x x 0 ? ? 0 0 0 ? ? ? ? 0 0 0 ? ? 0 x ? ? x 0 ? ? ? 0 ? 0 0 0 0 0 0 0 x ? 0 ? 0 x 0 0 0 0 0 0 0 ? ? 0 ? 0 x 0 0 0 0 0 0 ? ? ? 0 ? 0 0 0 0 ? 0 ? 0 ? 0 x 0 0 0 0 0 0 0 0 0 x 0 ? ? ? 0 0 0 x x 0 x x x x ? x x x x ? ? ? 0 0 0 0 0 0 0 ? ? ? x x ? x 0 ? x ? ? ? ? 0 0 ? x 0 0 0 0 0 ? x ? ? ? ? ? ? 0 0 0 0 0 ? x ? ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
User Data Access
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • NtQuerySystemInformation
Other Suspicious
  • AdjustTokenPrivileges
Encryption Used
  • BCryptOpenAlgorithmProvider
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
  • VirtualAllocEx
Process Shell Execute
  • CreateProcess

Shell Command Execution

c:\users\user\downloads\93b5bcc3cde88938c41eeb530f7d453fa56c19a9_0002929152

Related Posts

Trending

Most Viewed

Loading...