Malware

Should I remove “Babar.67248”?

Malware Removal

The Babar.67248 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Babar.67248 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • NtSetInformationThread: attempt to hide thread from debugger
  • Dynamic (imported) function loading detected
  • Enumerates the modules from a process (may be used to locate base addresses in process injection)
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Creates a hidden or system file
  • CAPE detected the EnigmaStub malware family
  • Deletes executed files from disk
  • Harvests cookies for information gathering

How to determine Babar.67248?


File Info:

name: 7C531FE58176B3401E52.mlw
path: /opt/CAPEv2/storage/binaries/ac9943eec1f3d0e1c1fa8716b70c7ddbf5beb99a0b737b91955d50dc361cc320
crc32: 5A164113
md5: 7c531fe58176b3401e529de2693bb4f2
sha1: 46b051b35ad7e7171a059493e7ba4db72dd570d2
sha256: ac9943eec1f3d0e1c1fa8716b70c7ddbf5beb99a0b737b91955d50dc361cc320
sha512: b92642215f7e8c9650bc2429233ab6289412296b86bae5cda68aff7c9521454603d9202096fc0bce0a6e03cd0acc0612a08d76a5e734200577f8b690b3f8cc3c
ssdeep: 196608:px6mqSXoYwLbS0wEo5RpgYO0Ntv8twfFP6mgJd7FmW9BtKFVLIlYugW:psmq4oYQb5oRNrvSwti37HBIUrgW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T188A6331951A8A54BEF514A3F193B764E9CE06E28483AC2975CB17EAF507C00BDB342F7
sha3_384: 3f13216679df3d822dc76d9e8505a5935b3505d5acd2a58aadf806287e6a642a67d6b3d8e393a26df9711b047e84470a
ep_bytes: eb08000878000000000060e800000000
timestamp: 2022-08-07 15:49:58

Version Info:

FileDescription: Krnl
ProductName: Krnl
FileVersion: 1.0.0.0
ProductVersion: 1.0.0.0
LegalCopyright: Copyright © 2022
OriginalFilename: Krnl.exe
Translation: 0x0409 0x0000

Babar.67248 also known as:

tehtrisGeneric.Malware
CynetMalicious (score: 99)
CylanceUnsafe
BitDefenderGen:Variant.Babar.67248
CrowdStrikewin/malicious_confidence_60% (D)
ArcabitTrojan.Babar.D106B0
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.Enigma.FR
APEXMalicious
KasperskyHEUR:Backdoor.Win32.DCRat.gen
MicroWorld-eScanGen:Variant.Babar.67248
Ad-AwareGen:Variant.Babar.67248
EmsisoftGen:Variant.Babar.67248 (B)
VIPREGen:Variant.Babar.67248
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.7c531fe58176b340
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1251154
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Variant.Babar.67248
AhnLab-V3Trojan/Win.Generic.R471170
BitDefenderThetaGen:NN.ZexaF.34582.@B0@auxBqVi
ALYacGen:Variant.Babar.67248
MAXmalware (ai score=82)
MalwarebytesTrojan.MalPack
ZonerProbably Heur.ExeHeaderL
RisingMalware.Undefined!8.C (TFE:dGZlOgVbZysZPR42Ng)
AVGWin32:Evo-gen [Susp]
AvastWin32:Evo-gen [Susp]

How to remove Babar.67248?

Babar.67248 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment