Malware

Babar.40678 (file analysis)

Malware Removal

The Babar.40678 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Babar.40678 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid

How to determine Babar.40678?


File Info:

name: DA30A010B07FD2597F15.mlw
path: /opt/CAPEv2/storage/binaries/5d261645c8a4c918070ffe45bbdcd2c54b9e88f833f7f933089f49e158e1d626
crc32: F57E2A8B
md5: da30a010b07fd2597f1532a9225e8052
sha1: 30eaaf3e7e0e4b8f7d63e24bf6eb0a094ef461ab
sha256: 5d261645c8a4c918070ffe45bbdcd2c54b9e88f833f7f933089f49e158e1d626
sha512: 60c009554389aa531261533dd54bd5eb99478c94fe09a19104e174c846c91dd80820dc7fd9078f9c70339de6d50577039f234ef9430e74f9544fbd9949445efa
ssdeep: 49152:qadUahLBy7jIf7AzACxJdqSSVhDw4GKHP1kDsIhbzEoTZGlCK+XlNZ:3thLBy78vXvWD5Y/ulN
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T13CF5F023A20240F2D6A54A7155BB7F3AB9F567124B118AFB47D4CDE41E237E0F72720A
sha3_384: 18e7c269f4ca4774ebffefb86a8758159c56a116c7da09e72d24dfbb1464e6728e49a21329db16bc19d3def9a21bd793
ep_bytes: 558bec6aff68a864580068545f4b0064
timestamp: 2022-04-26 14:34:32

Version Info:

0: [No Data]

Babar.40678 also known as:

BkavW32.AIDetect.malware1
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Babar.40678
FireEyeGeneric.mg.da30a010b07fd259
CAT-QuickHealDownloader.AdLoad.12395
ALYacGen:Variant.Babar.40678
CylanceUnsafe
Sangfor[ARMADILLO V1.71]
CrowdStrikewin/malicious_confidence_60% (D)
K7GWAdware ( 004b87ea1 )
K7AntiVirusTrojan ( 005246d51 )
ArcabitTrojan.Babar.D9EE6
BitDefenderThetaGen:NN.ZexaF.34606.wxW@aKa!Telb
CyrenW32/Agent.EW.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
BitDefenderGen:Variant.Babar.40678
AvastWin64:Malware-gen
TencentWin32.Trojan.Obfuscator.Wrga
Ad-AwareGen:Variant.Babar.40678
EmsisoftGen:Variant.Babar.40678 (B)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataWin32.Trojan.PSE.12XMZ4W
CynetMalicious (score: 100)
MAXmalware (ai score=89)
VBA32BScope.Trojan.Tiggre
MalwarebytesTrojan.MalPack.FlyStudio
RisingTrojan.MalCert!1.CAE1 (CLASSIC)
MaxSecureTrojan.Malware.121218.susgen
AVGWin64:Malware-gen
Cybereasonmalicious.e7e0e4

How to remove Babar.40678?

Babar.40678 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment