Malware

Babar.223180 (file analysis)

Malware Removal

The Babar.223180 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Babar.223180 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Babar.223180?


File Info:

name: BD93A37255D2426BE92C.mlw
path: /opt/CAPEv2/storage/binaries/1be821c1ea872f5a6b8d8530e395ccc12ae0010f259c58a68ef9ad76e1460d86
crc32: 2055C7A5
md5: bd93a37255d2426be92ca27959c7ce91
sha1: 4a276331f570093a4733f6708aa173d539e7ed6f
sha256: 1be821c1ea872f5a6b8d8530e395ccc12ae0010f259c58a68ef9ad76e1460d86
sha512: a4b33fbe6e14694064e4c60067e1bd363eab0d427e444f10e145472d332705a34a70f1e755aff7e696e3002bb9fa49316a61de7ff8e7718bc23fbd0b9393f28f
ssdeep: 49152:ztIJMO4aKAyDQqdwk0cQHGiYYSzSY5voVU7zQYGZpJqOzRd:IqAqQqdwkLQHHhsSYt8nZpJdH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F5064902BA79C8B1D2140130CEABDFF46A24BD67E9114643B3B1FEBEFDB53509916258
sha3_384: decb4b6769b63fbd510dcc57dc90577b1fd88c9ee6bdd0a091b653dd524f9e8c0098c6de6bf0fbb7d9c8dba8a90053f5
ep_bytes: 558bec6aff6818857400685438510064
timestamp: 2013-04-03 01:48:22

Version Info:

FileVersion: 1.0.0.0
FileDescription: 杭州明春物流有限公司ERP
ProductName: 杭州明春物流有限公司ERP
ProductVersion: 1.0.0.0
CompanyName: PCGO QQ:97411
LegalCopyright: 程序由PCGO独立开发 QQ:97411
Comments: 杭州明春物流有限公司ERP
Translation: 0x0804 0x04b0

Babar.223180 also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Babar.223180
ClamAVWin.Trojan.Flystudio-9943951-0
SkyhighBehavesLike.Win32.Generic.wh
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.BlackMoon
K7AntiVirusTrojan ( 005246d51 )
K7GWTrojan ( 005246d51 )
CrowdStrikewin/malicious_confidence_70% (D)
ArcabitTrojan.Babar.D367CC
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Variant.Babar.223180
EmsisoftGen:Variant.Babar.223180 (B)
VIPREGen:Variant.Babar.223180
FireEyeGeneric.mg.bd93a37255d2426b
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
GoogleDetected
MAXmalware (ai score=84)
Antiy-AVLTrojan/Win32.FlyStudio.a
Kingsoftmalware.kb.a.1000
XcitiumWorm.Win32.Dropper.RA@1qraug
MicrosoftProgram:Win32/Wacapew.C!ml
GDataWin32.Trojan.PSE.G95U2W
VaristW32/Trojan.CLL.gen!Eldorado
VBA32BScope.TrojanPSW.Gamania
ALYacGen:Variant.Babar.223180
Cylanceunsafe
FortinetW32/CoinMiner.ESFJ!tr
Cybereasonmalicious.1f5700
DeepInstinctMALICIOUS

How to remove Babar.223180?

Babar.223180 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment