Backdoor

Backdoor.HawkEyeKeyLogger (file analysis)

Malware Removal

The Backdoor.HawkEyeKeyLogger is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.HawkEyeKeyLogger virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Steals private information from local Internet browsers
  • Exhibits behavior characteristic of Pony malware
  • Collects information about installed applications
  • Harvests credentials from local FTP client softwares
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor.HawkEyeKeyLogger?


File Info:

crc32: BE3F6FB1
md5: ec3badf6a8587f29f1cd4a74ac981324
name: EC3BADF6A8587F29F1CD4A74AC981324.mlw
sha1: 8027e790fd8cd43054f20f76728eb0fb0e2428fa
sha256: ad0499d408c24f5d8378f809cc3c7b6f340331761139d124b4630f5ba88a87c6
sha512: 84d1cbeee794da26fa697d3ded27b71e1de7f06877bd5c5a9bbaa009105fdb4ec2aa10f9d83bcac2bac1fbc55ff71e5fe8a70092e8de4ee4dbe816d3acab8130
ssdeep: 24576:olX5ZSOxori2fKIas9zwXkkaO1MbGaB1r4gYgXUxza1OYd9Mf749anlSefjtrR:ojZJurJNaozwX7aOYGWNK5COsWccn4en
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xc2xa91999-2015 Jonathan Bennett & AutoIt Team
InternalName: Au3Info.exe
FileVersion: 3, 3, 14, 2
CompanyName: AutoIt Team
Comments: http://www.autoitscript.com/autoit3/
ProductName: Au3Info
ProductVersion: 3, 3, 14, 2
FileDescription: Au3Info
OriginalFilename: Au3Info.exe
Translation: 0x0809 0x04b0

Backdoor.HawkEyeKeyLogger also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0051c1c11 )
LionicTrojan.MSIL.Generic.m!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.17779
CynetMalicious (score: 100)
CAT-QuickHealBackdoor.MsilIH.S18501285
ALYacTrojan.Agent.CQIT
CylanceUnsafe
ZillyaBackdoor.Androm.Win32.47659
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/Lokibot.51b505fa
K7GWTrojan ( 0051c1c11 )
Cybereasonmalicious.6a8587
CyrenW32/Fareit.LQES-9106
SymantecInfostealer.Lokibot!13
ESET-NOD32a variant of Win32/Injector.DTOX
ZonerTrojan.Win32.66296
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Cqit-6999290-0
KasperskyHEUR:Backdoor.MSIL.Generic
BitDefenderTrojan.Agent.CQIT
NANO-AntivirusTrojan.Win32.Androm.euzlbn
ViRobotTrojan.Win32.Agent.679936.V
MicroWorld-eScanTrojan.Agent.CQIT
TencentMalware.Win32.Gencirc.10b3b410
Ad-AwareTrojan.Agent.CQIT
SophosMal/Generic-R + Troj/Fareit-DWG
ComodoMalware@#18xgan0afq555
F-SecureHeuristic.HEUR/AGEN.1121814
BitDefenderThetaAI:Packer.5033DB1116
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY_NOON.AC
McAfee-GW-EditionBehavesLike.Win32.Fareit.tc
FireEyeGeneric.mg.ec3badf6a8587f29
EmsisoftTrojan.Agent.CQIT (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan-Spy.Noon.c
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1121814
eGambitGeneric.Malware
Antiy-AVLTrojan/Generic.ASMalwS.22A8DA5
MicrosoftTrojan:Win32/Lokibot.JES!MTB
GridinsoftTrojan.Win32.Injector.bot!s1
ArcabitTrojan.Agent.CQIT
GDataTrojan.Agent.CQIT
AhnLab-V3Suspicious/Win.Delphiless.X2094
Acronissuspicious
McAfeeTrojan-FOGX!EC3BADF6A858
MAXmalware (ai score=100)
VBA32TScope.Trojan.Delf
MalwarebytesBackdoor.HawkEyeKeyLogger
PandaTrj/CI.A
TrendMicro-HouseCallTSPY_NOON.AC
RisingTrojan.Injector!1.AF18 (CLASSIC)
YandexTrojan.GenAsa!eUxE4ruS6fs
IkarusTrojan-Spy.Fareit
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.DTAI!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.Generic.HwUBAdsA

How to remove Backdoor.HawkEyeKeyLogger?

Backdoor.HawkEyeKeyLogger removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment