JavaScript support is required for our site to be fully operational in your browser.
Trojan.Siggen33.11277
Added to the Dr.Web virus database:
2026-08-05
Virus description added:
2026-08-07
Technical Information
Triggers a user-defined sigma rule:
aba15bdd-657f-422a-bab3-ac2d2a0d6f1c
d5866ddf-ce8f-4aea-b28e-d96485a20d3d
20f0ee37-5942-4e45-b7d5-c5b5db9df5cd
92626ddd-662c-49e3-ac59-f6535f12d189
7a02e22e-b885-4404-b38b-1ddc7e65258a
89ca78fd-b37c-4310-b3d3-81a023f83936
5e993621-67d4-488a-b9ae-b420d08b96cb
f17211f1-1f24-4d0c-829f-31e28dc93cdd
e4a6b256-3e47-40fc-89d2-7a477edd6915
e507feb7-5f73-4ef6-a970-91bb6f6d744f
f2c64357-b1d2-41b7-849f-34d2682c0fad
8a8379b8-780b-4dbf-b1e9-31c8d112fefb
970823b7-273b-460a-8afc-3a6811998529
01d2e2a1-5f09-44f7-9fc1-24faa7479b6d
96036718-71cc-4027-a538-d1587e0006a7
36210e0d-5b19-485d-a087-c096088885f0
87e3c4e8-a6a8-4ad9-bb4f-46e7ff99a180
f4bbd493-b796-416e-bbf2-121235348529
ec82e2a5-81ea-4211-a1f8-37a0286df2c2
edf3485d-dac4-4d50-90e4-b0e5813f7e60
d223b46b-5621-4037-88fe-fda32eead684
a29c1813-ab1f-4dde-b489-330b952e91ae
ccb5742c-c248-4982-8c5c-5571b9275ad3
502b42de-4306-40b4-9596-6f590c81f073
297ae038-edc2-4b2e-bb3e-7c5fc94dd5c7
To ensure autorun and distribution
Modifies the following registry keys
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'PhantomX4F9' = '"%ALLUSERSPROFILE%\Microsoft\Updater\heal.cmd"'
[HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'PhantomX4F9' = '"%ALLUSERSPROFILE%\Microsoft\Updater\heal.cmd"'
[HKLM\Software\Microsoft\Windows\CurrentVersion\Run] 'PhantomX4F9' = '"%ALLUSERSPROFILE%\Microsoft\Updater\heal.cmd"'
Creates or modifies the following files
<SYSTEM32>\tasks\phantomx4f9_b
<SYSTEM32>\tasks\phantomx4f9_l
<SYSTEM32>\tasks\phantomx4f9_h
<SYSTEM32>\tasks\phantomx4f9_w
Sets the following service settings
[HKLM\SYSTEM\CurrentControlSet\Services\PhantomX4F9Svc] 'Start' = '00000002'
[HKLM\SYSTEM\CurrentControlSet\Services\PhantomX4F9Svc] 'ImagePath' = '"%APPDATA%\Microsoft\Network\svchost.exe"'
Creates the following services
'PhantomX4F9Svc' C:�sers�ser\AppData\Roaming\Microsoft�etwork\svchost.exe
'PhantomX4F9Svc' %APPDATA%\Microsoft\Network\svchost.exe
'PhantomX4F9Svc' <SYSTEM32>\config\systemprofile\AppData\Roaming\Microsoft�etwork\svchost.exe
Malicious functions
Terminates or attempts to terminate
the following system processes:
<SYSTEM32>\windowspowershell\v1.0\powershell.exe
Modifies file system
Creates the following files
%APPDATA%\microsoft\network\svchost.exe
%WINDIR%\temp\runtime.dat:payload
%WINDIR%\temp\__psscriptpolicytest_vkbakym3.3g5.ps1
%WINDIR%\temp\__psscriptpolicytest_0nzrwfcf.rg1.psm1
<SYSTEM32>\config\systemprofile\appdata\local\microsoft\windows\powershell\startupprofiledata-noninteractive
Sets the 'hidden' attribute to the following files
%APPDATA%\microsoft\network\svchost.exe
Deletes following files that it created itself
%WINDIR%\temp\__psscriptpolicytest_vkbakym3.3g5.ps1
%WINDIR%\temp\__psscriptpolicytest_0nzrwfcf.rg1.psm1
Network activity
Connects to
'ap#.#pify.org':443
'di##ord.com':443
TCP
Other
'ap#.#pify.org':443
'di##ord.com':443
UDP
DNS ASK ap#.#pify.org
DNS ASK di##ord.com
Miscellaneous
Searches for the following windows
ClassName: '' WindowName: ''
Creates and executes the following
'%APPDATA%\microsoft\network\svchost.exe'
Executes the following
'<SYSTEM32>\schtasks.exe' /create /f /tn PhantomX4F9_L /tr "%ALLUSERSPROFILE%\Microsoft\Updater\heal.cmd" /sc onlogon
'<SYSTEM32>\schtasks.exe' /create /f /tn PhantomX4F9_H /tr "%ALLUSERSPROFILE%\Microsoft\Updater\heal.cmd" /sc minute /mo 60
'<SYSTEM32>\schtasks.exe' /create /f /tn PhantomX4F9_B /tr "%ALLUSERSPROFILE%\Microsoft\Updater\heal.cmd" /sc onstart /ru SYSTEM /rl HIGHEST
'<SYSTEM32>\schtasks.exe' /create /f /tn PhantomX4F9_W /tr "powershell -nop -w hidden -exec bypass -file "%ALLUSERSPROFILE%\Microsoft\Updater\svchost.exe.wmi.ps1"" /sc once /st 00:00 /ru SYSTEM /rl HIGHEST
'<SYSTEM32>\schtasks.exe' /run /tn PhantomX4F9_W
'<SYSTEM32>\cmd.exe' /c wmic cpu get name /value 2>nul
'<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -w hidden -exec bypass -file %ALLUSERSPROFILE%\Microsoft\Updater\svchost.exe.wmi.ps1
'<SYSTEM32>\wbem\wmic.exe' cpu get name /value
'<SYSTEM32>\cmd.exe' /c wmic path win32_videocontroller get name /value 2>nul
'<SYSTEM32>\wbem\wmic.exe' path win32_videocontroller get name /value
'<SYSTEM32>\cmd.exe' /c wmic diskdrive get model,serialnumber /value 2>nul
'<SYSTEM32>\wbem\wmic.exe' diskdrive get model,serialnumber /value
'<SYSTEM32>\cmd.exe' /c wmic nic where "netenabled=true" get macaddress /value 2>nul
'<SYSTEM32>\wbem\wmic.exe' nic where "netenabled=true" get macaddress /value
'<SYSTEM32>\cmd.exe' /c arp -a
'<SYSTEM32>\arp.exe' -a
'<SYSTEM32>\cmd.exe' /c netstat -ano | findstr ESTABLISHED
'<SYSTEM32>\netstat.exe' -ano
'<SYSTEM32>\findstr.exe' ESTABLISHED
'<SYSTEM32>\cmd.exe' /c netsh wlan show profiles
'<SYSTEM32>\netsh.exe' wlan show profiles
'<SYSTEM32>\cmd.exe' /c reg query "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall" /s /f DisplayName 2>nul
'<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall" /s /f DisplayName
'<SYSTEM32>\cmd.exe' /c reg query "HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall" /s /f DisplayName 2>nul
'<SYSTEM32>\reg.exe' query "HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall" /s /f DisplayName
'<SYSTEM32>\cmd.exe' /c tasklist /v /fo csv
'<SYSTEM32>\tasklist.exe' /v /fo csv
'<SYSTEM32>\cmd.exe' /c dir /b "%APPDATA%\Microsoft\Windows\Recent" 2>nul
'<SYSTEM32>\cmd.exe' /c net users
'<SYSTEM32>\net.exe' users
'<SYSTEM32>\net1.exe' users
Curing recommendations
Windows
macOS
Linux
Android
If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space .
If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.
If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
Switch off your device and turn it on as normal.
Find out more about Dr.Web for Android
Download Dr.Web for Android
Free three-month trial
All protection features available
Renew your trial license in AppGallery/on Google Pay
By continuing to use this website, you are consenting to Doctor Web’s use of cookies and other technologies related to the collection of visitor statistics. Learn more
OK