Backdoor

Backdoor.Hangup.B (B) malicious file

Malware Removal

The Backdoor.Hangup.B (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Hangup.B (B) virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Binary compilation timestomping detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor.Hangup.B (B)?


File Info:

name: 2FDDC67E65CA9EC18648.mlw
path: /opt/CAPEv2/storage/binaries/60d03d4d25125885856d94194ea40d29a1c0dd50d6e9a3586b00c46ce6fde6ec
crc32: 8F0D4F47
md5: 2fddc67e65ca9ec18648d978c2f6564f
sha1: 14cfda76fb98b6b5d4784c285a1e8531766d8807
sha256: 60d03d4d25125885856d94194ea40d29a1c0dd50d6e9a3586b00c46ce6fde6ec
sha512: dd255748babe7dd4e42502b07de606c3e8602198163abd7800359f516f1c2bcff65224930dac60b915d2660fd1f35b923ea004a4bba06acfbf0ff04e694681e6
ssdeep: 1536:o8cErLdDO8RZBTn7rg0l8/7rNiBipar+FEldWVBMS:fTI8NTn7rg5diBxyFEl8/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T120933CD772463772C1AF0273298F49E2772D9579D37684A018DC802DD6A2E6FB1FA384
sha3_384: 72b73ddfdc71a96b4bdbbb2f36ee53f67825daa09d3023427657c60ae69cc89a5fc2b475123ef34f635b624a8832c25d
ep_bytes: 609090909090b8001040009090bbf87e
timestamp: 2026-04-24 18:29:59

Version Info:

0: [No Data]

Backdoor.Hangup.B (B) also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanBackdoor.Hangup.B
ClamAVWin.Trojan.Crypted-28
FireEyeGeneric.mg.2fddc67e65ca9ec1
McAfeeBackDoor-AXJ.d
Cylanceunsafe
ZillyaTrojan.Qukart.Win32.1641466
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Trojan-Spy.Quart.a
VirITWorm.Win32.Berbew.G
CyrenW32/Qukart.K.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Spy.Qukart
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Spy.Win32.Qukart.af
BitDefenderBackdoor.Hangup.B
NANO-AntivirusTrojan.Win32.Qukart.jvtijy
AvastWin32:TrojanX-gen [Trj]
TencentTrojan-Ransom.Win32.Pornoasset.a
TACHYONBackdoor/W32.Padodor
SophosTroj/Padodo-Gen
F-SecureTrojan.TR/Spy.Qukart.NB
DrWebBackDoor.HangUp.43832
VIPREBackdoor.Hangup.B
McAfee-GW-EditionBehavesLike.Win32.Generic.mh
Trapminemalicious.high.ml.score
EmsisoftBackdoor.Hangup.B (B)
IkarusTrojan.Spy.Qukart
GDataBackdoor.Hangup.B
AviraTR/Spy.Qukart.NB
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
ArcabitBackdoor.Hangup.B
ZoneAlarmTrojan-Spy.Win32.Qukart.af
MicrosoftBackdoor:Win32/Berbew
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
BitDefenderThetaAI:Packer.A9414BEC21
ALYacBackdoor.Hangup.B
MAXmalware (ai score=80)
VBA32BScope.Backdoor.Berbew
MalwarebytesCrypt.Trojan.Malicious.DDS
PandaTrj/Genetic.gen
RisingBackdoor.Berbew!1.AE0A (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Qukart.A!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.e65ca9
DeepInstinctMALICIOUS

How to remove Backdoor.Hangup.B (B)?

Backdoor.Hangup.B (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment