Malware

Babar.72108 (file analysis)

Malware Removal

The Babar.72108 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Babar.72108 virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Babar.72108?


File Info:

name: 70BC819E4B8C35B2F08C.mlw
path: /opt/CAPEv2/storage/binaries/d82f970cc1b32a0f553112f1dddcaa693b414e7b60018054944fc40ec96c58fb
crc32: 4C4A15CD
md5: 70bc819e4b8c35b2f08c0a7ce68f3002
sha1: 43208f5006fb37e224183551d2652511a71c012c
sha256: d82f970cc1b32a0f553112f1dddcaa693b414e7b60018054944fc40ec96c58fb
sha512: c36da91e54379d08dc9680f7f55e6d475fc47ca6cd2591742d3193a4445392654138fbda92c6d6d831ca18120bb8636d2c74a0840c5ea8fae286000664dbef7c
ssdeep: 12288:l+SAoy/xl6pkpsDBk4RVExv4B//CDolZiFUXduHyGbOtDk5da/9:laL6pkpsDBk4RVp/+MXXwmk5g9
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1E2359D20B88551B3EFE221B342DEBA250BFDA9A0075C45CF079517EEEA245C17BF3691
sha3_384: 5fe05f993c1a5851c9da2d1ecb6e30519231b65feb4cda81adc6b9f8175c41f6093cc6c95a2237afbb84e7f329d46b16
ep_bytes: e96cd30300e9d63f0500e97b560400e9
timestamp: 2023-09-29 04:50:57

Version Info:

0: [No Data]

Babar.72108 also known as:

BkavW32.AIDetectMalware
DrWebTrojan.KillProc2.21533
MicroWorld-eScanGen:Variant.Babar.72108
FireEyeGen:Variant.Babar.72108
MalwarebytesSpyware.RedLineStealer
SangforTrojan.Win32.Save.a
BitDefenderThetaGen:NN.ZexaF.36738.czW@aiKWBz
CyrenW32/Kryptik.KRU.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HUUC
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-PSW.Win32.Stealerc.gen
BitDefenderGen:Variant.Babar.72108
AvastWin32:TrojanX-gen [Trj]
EmsisoftGen:Variant.Babar.72108 (B)
VIPREGen:Variant.Babar.72108
GDataGen:Variant.Babar.72108
Antiy-AVLTrojan/Win32.Sabsik
ArcabitTrojan.Babar.D119AC
ZoneAlarmHEUR:Trojan-PSW.Win32.Stealerc.gen
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R608430
ALYacGen:Variant.Babar.72108
MAXmalware (ai score=82)
RisingTrojan.Generic@AI.90 (RDML:kp7/7PrGd1DuKgY9//T7Fg)
FortinetW32/Injector.ETFD!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Babar.72108?

Babar.72108 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment