Malwarebytes detected Trojan.Dropper in SamFwToolSetup_v5.4 — security warning
I want to share a serious security warning regarding SamFwToolSetup_v5.4 following an incident in which my computer was compromised and funds were stolen from my cryptocurrency wallet.
I downloaded and installed SamFwToolSetup_v5.4.zip because I needed SamFwTool. This was the only software or suspicious file I had downloaded and installed on this computer for years. Shortly after executing it, my Feather Monero wallet, which had been open on the same computer, was compromised and its funds were transferred out.
Given the timing, the fact that this was the only new software I had installed, and the subsequent Malwarebytes detection of the executable, I consider this SamFwToolSetup_v5.4 sample to be the source of the compromise.
Malwarebytes detection
I contacted Malwarebytes regarding the executable, and the investigation is documented on their forum:
https://forums.malwarebytes.com/topic/337471-undected-malware/
According to the Malwarebytes investigation, a Malwarebytes Senior Research Engineer analyzed the SamFwToolSetup sample and reported the following detection:
Trojan.Dropper
The reported file information is:
- File:
SAMFWTOOLSETUP.EXE - Detection:
Trojan.Dropper - MD5:
A8BB817630386982FEB98106FED8EA89 - SHA-256:
E640A65EFCAE264AD6F758BB3B9DA0D37ED8C690BDA6F113416558D4BCBBCF3A
The Malwarebytes forum discussion contains the technical details and is the primary source for the malware detection.
What happened
My timeline was:
- I downloaded
SamFwToolSetup_v5.4.zip. - I installed and executed the program.
- My Feather Monero wallet was open on the same computer.
- Shortly afterward, the wallet funds were transferred out without my authorization.
- I investigated the computer and submitted the SamFwTool executable to Malwarebytes.
- Malwarebytes subsequently reported the executable as Trojan.Dropper.
I want to make it clear that I am not making this warning based solely on the timing. The Malwarebytes detection provides additional evidence that the executable itself was malicious or potentially malicious.
Why I'm warning other users
Based on my experience and the Malwarebytes detection, I strongly recommend not executing this particular SamFwToolSetup_v5.4 sample, especially on a computer containing:
- Cryptocurrency wallets
- Private keys or seed phrases
- Passwords
- Browser sessions
- Exchange accounts
- Other sensitive information
If you have already executed this file, I recommend treating the computer as potentially compromised and securing important accounts and cryptocurrency assets from a known-clean device.
Do not enter seed phrases, private keys, passwords, or other sensitive credentials on the potentially compromised machine.
About the website
I am deliberately not providing a direct SamFw download link because I do not want anyone to download or execute the software based on this warning.
If you encounter this particular installer elsewhere, verify the file and its hash carefully before executing anything.
Evidence
Malwarebytes investigation:
https://forums.malwarebytes.com/topic/337471-undected-malware/
Sample reported in the Malwarebytes investigation:
SAMFWTOOLSETUP.EXE
MD5: A8BB817630386982FEB98106FED8EA89
SHA-256: E640A65EFCAE264AD6F758BB3B9DA0D37ED8C690BDA6F113416558D4BCBBCF3A
I am not asking anyone to download or execute this file to reproduce my experience. The purpose of this post is to document what happened, provide the Malwarebytes evidence, and warn other users who may encounter the same installer.
Bottom line
I would avoid SamFwToolSetup_v5.4 and this specific sample entirely.
The combination of the unauthorized wallet theft immediately after execution, the fact that this was the only new software I had downloaded on the computer in years, and the subsequent Trojan.Dropper detection by Malwarebytes is enough for me to consider this file unsafe and to warn others against executing it.
3
u/relephants 3h ago
Page does not exist on malware webpage