Malware

About “Babar.32522” infection

Malware Removal

The Babar.32522 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Babar.32522 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Manipuri
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Enumerates services, possibly for anti-virtualization
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • CAPE detected the Tofsee malware family
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Babar.32522?


File Info:

name: 34DA7CB2E69B6C4F063F.mlw
path: /opt/CAPEv2/storage/binaries/6d2dd097ddb42210f1973d6ab761862857c62eb31f5d988bafe0780a3ce32d91
crc32: AAEFADBE
md5: 34da7cb2e69b6c4f063f5a518fa0e698
sha1: 1c60858b076b91e71bdf6aaf5c3670f9cc8c7b5f
sha256: 6d2dd097ddb42210f1973d6ab761862857c62eb31f5d988bafe0780a3ce32d91
sha512: be6df74747a0f13c8c85632693adf50b8551a80ec3c192153aeae43edabbf0c5156a2e252550af4afafcab6280589f92ef9d0bc330f46ba3638572771b43c105
ssdeep: 24576:/990tITUWFaJVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVT:/9uvWF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13AD619A5FE9918F1D45801FC34BD3FD901ACD65A812DE33E985900E9E81263E3E6CE5B
sha3_384: a8100edd9ca46036d96bed1bcac3d55bcd0c6fc2fbe019979370315730d1c5d0ce515e8611e203952c730b30af162398
ep_bytes: e89b380000e989feffff8bff558bec68
timestamp: 2020-12-11 17:06:17

Version Info:

FileVersion: 39.42.11.19
Copyrighz: Copyright (C) 2022, pazkarte
ProjectVersion: 25.13.80.11

Babar.32522 also known as:

BkavW32.AIDetect.malware2
tehtrisGeneric.Malware
DrWebTrojan.Siggen17.35156
MicroWorld-eScanGen:Variant.Babar.32522
FireEyeGeneric.mg.34da7cb2e69b6c4f
CAT-QuickHealTrojan.StrabPMF.S27599846
ALYacGen:Variant.Babar.32522
VIPREGen:Variant.Babar.32522
K7AntiVirusTrojan ( 00591e391 )
K7GWTrojan ( 00590aac1 )
Cybereasonmalicious.b076b9
CyrenW32/Filecoder.DG.gen!Eldorado
SymantecPacked.Generic.525
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HPCT
ClamAVWin.Packed.Tofsee-9951336-0
KasperskyHEUR:Backdoor.Win32.Gulpix.gen
BitDefenderGen:Variant.Babar.32522
AvastWin32:AceCrypter-T [Cryp]
TencentTrojan.Win32.Strab.za
Ad-AwareGen:Variant.Babar.32522
SophosML/PE-A + Troj/Krypt-IR
SentinelOneStatic AI – Malicious PE
EmsisoftGen:Variant.Babar.32522 (B)
IkarusTrojan.Crypter
GDataWin32.Trojan.PSE.11759A6
JiangminBackdoor.Mokes.fqp
AviraTR/Crypt.XPACK.Gen
MicrosoftRansom:Win32/StopCrypt.PBF!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.MalPE.R482634
Acronissuspicious
McAfeePacked-GDT!34DA7CB2E69B
VBA32BScope.Malware-Cryptor.Hlux
MalwarebytesTrojan.MalPack.GS
APEXMalicious
RisingTrojan.Kryptik!1.D977 (CLASSIC)
MAXmalware (ai score=86)
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Packed.GDT!tr
AVGWin32:AceCrypter-T [Cryp]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Babar.32522?

Babar.32522 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment