Backdoor

Backdoor.Win32.Emotet.ajuh (file analysis)

Malware Removal

The Backdoor.Win32.Emotet.ajuh is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Emotet.ajuh virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Russian
  • Attempts to modify proxy settings

How to determine Backdoor.Win32.Emotet.ajuh?


File Info:

crc32: 2BC0E479
md5: cb7d3c9b00c8649db4a14d935e78abd5
name: upload_file
sha1: 608e904a2a60c5bfbc0c2912dbefca9591b4f73f
sha256: 635a239ea0b9ceeef84b058e5f3479c5bd127fa6b3337322dc69ec4a30194969
sha512: cc22275b1c23be852e68fa18743e45034953bee35de451933a6245518e1915f24287b940d5250098ffca02ab64ee953f5e80fc7766b91db6a120daf789ecbd44
ssdeep: 6144:6IuOkoX33WyZEwtWNRByDlPdOT6ncZe9y:6XOkoXnLETNnypWYcZeI
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2003
InternalName: FileTreeDialog
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: FileTreeDialog Application
ProductVersion: 1, 0, 0, 1
FileDescription: FileTreeDialog MFC Application
OriginalFilename: FileTreeDialog.EXE
Translation: 0x0409 0x04b0

Backdoor.Win32.Emotet.ajuh also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.34255738
FireEyeTrojan.GenericKD.34255738
McAfeeEmotet-FRI!CB7D3C9B00C8
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 0056b6f11 )
BitDefenderTrojan.GenericKD.34255738
K7GWTrojan ( 0056b6f11 )
TrendMicroTROJ_GEN.R002C0DGU20
F-ProtW32/Emotet.AOC.gen!Eldorado
SymantecTrojan.Emotet
APEXMalicious
AvastWin32:BankerX-gen [Trj]
KasperskyBackdoor.Win32.Emotet.ajuh
AlibabaMalware:Win32/BankerX.be19a885
RisingTrojan.Kryptik!1.C89F (CLASSIC)
Ad-AwareTrojan.GenericKD.34255738
SophosTroj/Emotet-CKK
DrWebTrojan.DownLoader34.9808
Invinceaheuristic
EmsisoftTrojan.Emotet (A)
CyrenW32/Emotet.AOC.gen!Eldorado
FortinetW32/GenKryptik.EOMR!tr
ArcabitTrojan.Generic.D20AB37A
ZoneAlarmBackdoor.Win32.Emotet.ajuh
MicrosoftTrojan:Win32/Emotet.ARJ!MTB
AhnLab-V3Trojan/Win32.Emotet.R346328
ALYacTrojan.GenericKD.34255738
MalwarebytesTrojan.MalPack.TRE
PandaTrj/Emotet.C
ESET-NOD32a variant of Win32/Kryptik.HFGD
TrendMicro-HouseCallTROJ_GEN.R002C0DGU20
MAXmalware (ai score=89)
GDataTrojan.GenericKD.34255738
AVGWin32:BankerX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Generic/Trojan.e03

How to remove Backdoor.Win32.Emotet.ajuh?

Backdoor.Win32.Emotet.ajuh removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment