Threat Database Trojans Trojan.MSIL.Downloader.Agent.HAKA

Trojan.MSIL.Downloader.Agent.HAKA

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 22,812
Threat Level: 80 % (High)
Infected Computers: 25
First Seen: August 13, 2022
Last Seen: June 3, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Downloader.Agent.HAKA on your system indicates a potential security threat that requires immediate attention. This malware is categorized as a Trojan, which is a type of malicious software designed to gain unauthorized access to a computer system. Trojans can be used to spy on users, steal sensitive information, or disrupt system operations. It is essential to understand the nature of this threat and take prompt action to remove it and prevent further damage.

What Is Trojan.MSIL.Downloader.Agent.HAKA?

Trojan.MSIL.Downloader.Agent.HAKA is a type of malware that falls under the broader category of Trojans. The name suggests it may be involved in downloading additional malicious components, which could lead to a variety of harmful activities on the infected system. Understanding the specifics of how this malware operates is crucial for effective removal and prevention of future infections.

How Trojan.MSIL.Downloader.Agent.HAKA Operates

Malware like Trojan.MSIL.Downloader.Agent.HAKA typically operates by exploiting vulnerabilities in software or tricking users into executing the malicious code. Once inside a system, it can perform a range of malicious activities, including but not limited to, downloading and installing additional malware, stealing personal data, or hijacking system resources for malicious purposes. The exact operation can vary, but the end goal is usually to compromise the security and integrity of the infected system for the benefit of the attackers.

Symptoms of Infection

Symptoms of a Trojan.MSIL.Downloader.Agent.HAKA infection can vary widely, depending on the specific goals of the malware and the extent of the infection. Common signs include unexpected changes to system settings, appearance of unwanted programs or toolbars, slow system performance, frequent crashes, or unusual network activity. In some cases, the infection may not exhibit overt symptoms, making it difficult for users to detect without the aid of security software.

How to Remove Trojan.MSIL.Downloader.Agent.HAKA

  1. Enter Safe Mode with Networking to prevent the malware from loading and to give you a cleaner environment to work in.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all traces of the malware.
  3. Uninstall any suspicious programs that you do not recognize or that were installed around the time the malware was detected.
  4. Reset your web browsers (Chrome, Firefox, Edge, etc.) to their default settings to remove any malicious extensions or settings changes made by the malware.
  5. Reboot your system and perform another full scan to ensure that all malware components have been removed and that your system is clean.

Conclusion

Removing Trojan.MSIL.Downloader.Agent.HAKA requires careful and thorough action to ensure that all components of the malware are eliminated from your system. By following the steps outlined above and maintaining good security practices, such as keeping your operating system and software up to date, using strong antivirus software, and being cautious when clicking on links or downloading attachments, you can significantly reduce the risk of future infections. Remember, vigilance and proactive security measures are key to protecting your digital assets and personal information in today's cyber landscape.

Analysis Report

General information

Family Name: Trojan.MSIL.Downloader.Agent.HAKA
Signature status: Hash Mismatch

Known Samples

MD5: dc76e2b53b49ade6436d1445fee04432
SHA1: ca202536956997780ff2d38531fa2cd112101d1e
SHA256: A0CB0F536E8AD10F2C77B50F1736531563284EF54B9B5760ECF3CFF9A5AE88AC
File Size: 2.56 MB, 2557496 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File is .NET application
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 10.0.19041.1202
Comments Task Manager
Company Name Microsoft Corporation
File Description Task Manager
File Version 10.0.19041.1202
Internal Name Kdlkuahr.exe
Legal Copyright © Microsoft Corporation. All rights reserved.
Original Filename Kdlkuahr.exe
Product Name Microsoft® Windows® Operating System
Product Version 10.0.19041.1202

Digital Signatures

Signer Root Status
MICRO-STAR INTERNATIONAL CO., LTD. GlobalSign Hash Mismatch

File Traits

  • .NET
  • HighEntropy
  • x64

Block Information

Total Blocks: 4
Potentially Malicious Blocks: 4
Whitelisted Blocks: 0
Unknown Blocks: 0

Visual Map

x x x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelTimer2
  • ntdll.dll!NtCancelWaitCompletionPacket
Show More
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCompareSigningLevels
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtGetCachedSigningLevel
  • ntdll.dll!NtGetContextThread
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtSuspendThread
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtUnsubscribeWnfStateChange
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • ntdll.dll!NtYieldExecution

1 additional items are not displayed above.

User Data Access
  • GetComputerName
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserName
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Other Suspicious
  • AdjustTokenPrivileges
Anti Debug
  • IsDebuggerPresent
Process Manipulation Evasion
  • ReadProcessMemory

Related Posts

Trending

Most Viewed

Loading...