Pour le fonctionnement correct du site, vous devez activer JavaScript dans votre navigateur.
Trojan.Siggen33.11277
Added to the Dr.Web virus database:
2026-08-05
Virus description added:
2026-08-07
Technical Information
Triggers a user-defined sigma rule:
aba15bdd-657f-422a-bab3-ac2d2a0d6f1c
d5866ddf-ce8f-4aea-b28e-d96485a20d3d
20f0ee37-5942-4e45-b7d5-c5b5db9df5cd
92626ddd-662c-49e3-ac59-f6535f12d189
7a02e22e-b885-4404-b38b-1ddc7e65258a
89ca78fd-b37c-4310-b3d3-81a023f83936
5e993621-67d4-488a-b9ae-b420d08b96cb
f17211f1-1f24-4d0c-829f-31e28dc93cdd
e4a6b256-3e47-40fc-89d2-7a477edd6915
e507feb7-5f73-4ef6-a970-91bb6f6d744f
f2c64357-b1d2-41b7-849f-34d2682c0fad
8a8379b8-780b-4dbf-b1e9-31c8d112fefb
970823b7-273b-460a-8afc-3a6811998529
01d2e2a1-5f09-44f7-9fc1-24faa7479b6d
96036718-71cc-4027-a538-d1587e0006a7
36210e0d-5b19-485d-a087-c096088885f0
87e3c4e8-a6a8-4ad9-bb4f-46e7ff99a180
f4bbd493-b796-416e-bbf2-121235348529
ec82e2a5-81ea-4211-a1f8-37a0286df2c2
edf3485d-dac4-4d50-90e4-b0e5813f7e60
d223b46b-5621-4037-88fe-fda32eead684
a29c1813-ab1f-4dde-b489-330b952e91ae
ccb5742c-c248-4982-8c5c-5571b9275ad3
502b42de-4306-40b4-9596-6f590c81f073
297ae038-edc2-4b2e-bb3e-7c5fc94dd5c7
To ensure autorun and distribution
Modifies the following registry keys
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'PhantomX4F9' = '"%ALLUSERSPROFILE%\Microsoft\Updater\heal.cmd"'
[HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'PhantomX4F9' = '"%ALLUSERSPROFILE%\Microsoft\Updater\heal.cmd"'
[HKLM\Software\Microsoft\Windows\CurrentVersion\Run] 'PhantomX4F9' = '"%ALLUSERSPROFILE%\Microsoft\Updater\heal.cmd"'
Creates or modifies the following files
<SYSTEM32>\tasks\phantomx4f9_b
<SYSTEM32>\tasks\phantomx4f9_l
<SYSTEM32>\tasks\phantomx4f9_h
<SYSTEM32>\tasks\phantomx4f9_w
Sets the following service settings
[HKLM\SYSTEM\CurrentControlSet\Services\PhantomX4F9Svc] 'Start' = '00000002'
[HKLM\SYSTEM\CurrentControlSet\Services\PhantomX4F9Svc] 'ImagePath' = '"%APPDATA%\Microsoft\Network\svchost.exe"'
Creates the following services
'PhantomX4F9Svc' C:�sers�ser\AppData\Roaming\Microsoft�etwork\svchost.exe
'PhantomX4F9Svc' %APPDATA%\Microsoft\Network\svchost.exe
'PhantomX4F9Svc' <SYSTEM32>\config\systemprofile\AppData\Roaming\Microsoft�etwork\svchost.exe
Malicious functions
Terminates or attempts to terminate
the following system processes:
<SYSTEM32>\windowspowershell\v1.0\powershell.exe
Modifies file system
Creates the following files
%APPDATA%\microsoft\network\svchost.exe
%WINDIR%\temp\runtime.dat:payload
%WINDIR%\temp\__psscriptpolicytest_vkbakym3.3g5.ps1
%WINDIR%\temp\__psscriptpolicytest_0nzrwfcf.rg1.psm1
<SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\powershell\startupprofiledata-noninteractive
Sets the 'hidden' attribute to the following files
%APPDATA%\microsoft\network\svchost.exe
Deletes following files that it created itself
%WINDIR%\temp\__psscriptpolicytest_vkbakym3.3g5.ps1
%WINDIR%\temp\__psscriptpolicytest_0nzrwfcf.rg1.psm1
Network activity
Connects to
'ap#.#pify.org':443
'di##ord.com':443
TCP
Other
'ap#.#pify.org':443
'di##ord.com':443
UDP
DNS ASK ap#.#pify.org
DNS ASK di##ord.com
Miscellaneous
Searches for the following windows
ClassName: '' WindowName: ''
Creates and executes the following
'%APPDATA%\microsoft\network\svchost.exe'
Executes the following
'<SYSTEM32>\schtasks.exe' /create /f /tn PhantomX4F9_L /tr "%ALLUSERSPROFILE%\Microsoft\Updater\heal.cmd" /sc onlogon
'<SYSTEM32>\schtasks.exe' /create /f /tn PhantomX4F9_H /tr "%ALLUSERSPROFILE%\Microsoft\Updater\heal.cmd" /sc minute /mo 60
'<SYSTEM32>\schtasks.exe' /create /f /tn PhantomX4F9_B /tr "%ALLUSERSPROFILE%\Microsoft\Updater\heal.cmd" /sc onstart /ru SYSTEM /rl HIGHEST
'<SYSTEM32>\schtasks.exe' /create /f /tn PhantomX4F9_W /tr "powershell -nop -w hidden -exec bypass -file "%ALLUSERSPROFILE%\Microsoft\Updater\svchost.exe.wmi.ps1"" /sc once /st 00:00 /ru SYSTEM /rl HIGHEST
'<SYSTEM32>\schtasks.exe' /run /tn PhantomX4F9_W
'<SYSTEM32>\cmd.exe' /c wmic cpu get name /value 2>nul
'<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -w hidden -exec bypass -file %ALLUSERSPROFILE%\Microsoft\Updater\svchost.exe.wmi.ps1
'<SYSTEM32>\wbem\wmic.exe' cpu get name /value
'<SYSTEM32>\cmd.exe' /c wmic path win32_videocontroller get name /value 2>nul
'<SYSTEM32>\wbem\wmic.exe' path win32_videocontroller get name /value
'<SYSTEM32>\cmd.exe' /c wmic diskdrive get model,serialnumber /value 2>nul
'<SYSTEM32>\wbem\wmic.exe' diskdrive get model,serialnumber /value
'<SYSTEM32>\cmd.exe' /c wmic nic where "netenabled=true" get macaddress /value 2>nul
'<SYSTEM32>\wbem\wmic.exe' nic where "netenabled=true" get macaddress /value
'<SYSTEM32>\cmd.exe' /c arp -a
'<SYSTEM32>\arp.exe' -a
'<SYSTEM32>\cmd.exe' /c netstat -ano | findstr ESTABLISHED
'<SYSTEM32>\netstat.exe' -ano
'<SYSTEM32>\findstr.exe' ESTABLISHED
'<SYSTEM32>\cmd.exe' /c netsh wlan show profiles
'<SYSTEM32>\netsh.exe' wlan show profiles
'<SYSTEM32>\cmd.exe' /c reg query "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall" /s /f DisplayName 2>nul
'<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall" /s /f DisplayName
'<SYSTEM32>\cmd.exe' /c reg query "HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall" /s /f DisplayName 2>nul
'<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall" /s /f DisplayName
'<SYSTEM32>\cmd.exe' /c tasklist /v /fo csv
'<SYSTEM32>\tasklist.exe' /v /fo csv
'<SYSTEM32>\cmd.exe' /c dir /b "%APPDATA%\Microsoft\Windows\Recent" 2>nul
'<SYSTEM32>\cmd.exe' /c net users
'<SYSTEM32>\net.exe' users
'<SYSTEM32>\net1.exe' users
Recommandations pour le traitement
Windows
macOS
Linux
Android
Si le système d'exploitation peut être démarré (en mode normal ou en mode sans échec), téléchargez Dr.Web Security Space et lancez un scan complet de votre ordinateur et de tous les supports amovibles que vous utilisez. En savoir plus sur Dr.Web Security Space .
Si le démarrage du système d'exploitation est impossible, veuillez modifier les paramètres du BIOS de votre ordinateur pour démarrer votre ordinateur via CD/DVD ou clé USB. Téléchargez l'image du disque de secours de restauration du système Dr.Web® LiveDisk ou l'utilitaire pour enregistrer Dr.Web® LiveDisk sur une clé USB, puis préparez la clé USB appropriée. Démarrez l'ordinateur à l'aide de cette clé et lancez le scan complet et le traitement des menaces détectées.
Si votre appareil mobile fonctionne correctement, veuillez télécharger et installer sur votre appareil mobile Dr.Web pour Android . Lancez un scan complet et suivez les recommandations sur la neutralisation des menaces détectées.
Si l'appareil mobile est bloqué par le Trojan de la famille Android.Locker (un message sur la violation grave de la loi ou la demande d'une rançon est affiché sur l'écran de l'appareil mobile), procédez comme suit:
démarrez votre Smartphone ou votre tablette en mode sans échec (si vous ne savez pas comment faire, consultez la documentation de l'appareil mobile ou contactez le fabricant) ;
puis téléchargez et installez sur votre appareil mobile Dr.Web pour Android et lancez un scan complet puis suivez les recommandations sur la neutralisation des menaces détectées ;
Débranchez votre appareil et rebranchez-le.
En savoir plus sur Dr.Web pour Android
Téléchargez Dr.Web pour Android
Gratuit pour 3 mois
Tous les composants de protection
Renouvellement de la démo via AppGallery/Google Pay
Nous utilisons des cookies sur notre site web à des fins uniques d’analyse de la fréquentation et de récolte de données statistiques. En naviguant sur notre site, vous pouvez accepter ou refuser l’utilisation de ces fichiers cookies.
En savoir plus : Politique de confidentialité
Accepter
Refuser