Malware

Babar.28598 information

Malware Removal

The Babar.28598 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Babar.28598 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Uzbek (Latin)
  • The binary likely contains encrypted or compressed data.
  • Checks for the presence of known windows from debuggers and forensic tools
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to identify installed AV products by installation directory
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Attempts to modify proxy settings
  • Attempts to create or modify system certificates
  • Anomalous binary characteristics

Related domains:

iplogger.org
wushupalace.top

How to determine Babar.28598?


File Info:

crc32: C22CD9C4
md5: 95583529b3b5bc0d651d323d3031034a
name: 95583529B3B5BC0D651D323D3031034A.mlw
sha1: a72b56fb1c75eea331758c5798b0886b40f2f011
sha256: dfdeb185888f3467b917d09ab5ac29a0493f84c0286759e07702f56fc8bb3a2b
sha512: 580330eb83d214416ede6e6c954a0dea730635fbc885e5f3ac4dc45382874fb1da8c11834e027f92e317bf92e8b107b91adfebc5237246bf534ffbeb76310cf7
ssdeep: 12288:3pYifuUWtdhKw1sWT1WMskUcOR7UFlAna+WEQgSNlMvjxWAjtF6yL:JuUWnQwDsofe7sAadNlMvBHL
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: sojbmoemonu.uhe
ProductVersion: 8.19.590.38
Copyright: Copyrighz (C) 2021, fudkagata
Translation: 0x0129 0x0167

Babar.28598 also known as:

K7AntiVirusTrojan ( 0056ac331 )
Elasticmalicious (high confidence)
CAT-QuickHealRansom.Stop.P5
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Variant.Babar.28598
K7GWTrojan ( 0056ac331 )
CyrenW32/Kryptik.EWJ.gen!Eldorado
SymantecPacked.Generic.525
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:Trojan-Spy.Win32.Stealer.gen
MicroWorld-eScanGen:Variant.Babar.28598
Ad-AwareGen:Variant.Babar.28598
SophosML/PE-A
McAfee-GW-EditionBehavesLike.Win32.SoftPulse.hc
FireEyeGeneric.mg.95583529b3b5bc0d
EmsisoftGen:Variant.Babar.28598 (B)
SentinelOneStatic AI – Malicious PE
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
GDataGen:Variant.Babar.28598
Acronissuspicious
MAXmalware (ai score=86)
RisingTrojan.Kryptik!1.D977 (CLASSIC)
IkarusTrojan-Dropper.Win32.Danabot
MaxSecureTrojan.Malware.300983.susgen
Paloaltogeneric.ml

How to remove Babar.28598?

Babar.28598 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment