Malware

Babar.168650 malicious file

Malware Removal

The Babar.168650 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Babar.168650 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Portuguese
  • Authenticode signature is invalid
  • CAPE detected the Tofsee malware family
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Babar.168650?


File Info:

name: 15E8599E1003E8AFD113.mlw
path: /opt/CAPEv2/storage/binaries/90741bbf17ff08024a228e7ba54605af90e859cef491ef033d3704a800115f59
crc32: 59FE8FF8
md5: 15e8599e1003e8afd113748dd4f3a2d0
sha1: 840625f00f3766db67e38dab5b90cb29bdeea414
sha256: 90741bbf17ff08024a228e7ba54605af90e859cef491ef033d3704a800115f59
sha512: 3dba3318185da443fa69be307e863ad718a5fb0ca1fb5131221fcf2ad64b7e3bd0372dafafa2033ad18f4ce635de4a6b7a972aede18a38cc286a4863d45feeeb
ssdeep: 98304:ArFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF3:
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T182E6FF4387A23CC4F91A8B739F1ECAF8779EF9508E4A7B751258EA2F00B5176C153690
sha3_384: 22144368fe6a3904a8dbe4ec49a91bc665d4a3a5593297bdb302d62f56fba13ba4073038bf7a6aec4971df69a3ff1787
ep_bytes: e82e680000e989feffff8bff558bec8b
timestamp: 2022-07-04 13:11:33

Version Info:

FileDescriptions: Somewhere
FileVersion: 46.76.12.71
InternalName: Literally.exe
LegalCopyrights: Challangers kamboja
ProductName: Gommy
ProductVersions: 10.55.70.52
Translation: 0x424f 0x043a

Babar.168650 also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Babar.168650
FireEyeGeneric.mg.15e8599e1003e8af
ALYacGen:Variant.Babar.168650
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00516fdf1 )
K7GWTrojan ( 00516fdf1 )
Cybereasonmalicious.00f376
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Variant.Babar.168650
EmsisoftGen:Variant.Babar.168650 (B)
VIPREGen:Variant.Babar.168650
TrendMicroMal_Tofsee
McAfee-GW-EditionBehavesLike.Win32.Expiro.tt
Trapminemalicious.high.ml.score
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Babar.168650
JiangminTrojanSpy.Windigo.agv
ArcabitTrojan.Babar.D292CA
MicrosoftTrojan:Script/Phonzy.C!ml
AhnLab-V3Trojan/Win.Generic.R600412
Acronissuspicious
McAfeePacked-GDR!15E8599E1003
MAXmalware (ai score=86)
Cylanceunsafe
TrendMicro-HouseCallMal_Tofsee
RisingTrojan.Generic@AI.100 (RDML:Hw/eTd++PRVeboRnyCvMJA)
IkarusTrojan.Win32.Glupteba
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Babar.168650?

Babar.168650 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment