Backdoor

Backdoor.Win32.Emotet.aina (file analysis)

Malware Removal

The Backdoor.Win32.Emotet.aina is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Emotet.aina virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)

How to determine Backdoor.Win32.Emotet.aina?


File Info:

crc32: F37AF7D0
md5: fd6448c62f6929f2f277a16ea40493dd
name: upload_file
sha1: ef2e80c8beb7348957aa05a8c656f9232effaa11
sha256: e41c5142a6f1d3cfc570f63c4577066827820147509ab1bc0f37c35a5bc83e5e
sha512: 8e4ecde0ef2bfbaa0740e5c1c146d6f164453af562adff6a2068a153f6d0d244c68abe2dd5b806e5c985f0cffa6e63d11bf8a230d690e41c6d0615a45f9b1abf
ssdeep: 12288:dI5z0DLVQP+GFv1iQ3Gf0TzZbMhLshD0WBDJdajFVNgvYee7T640Hpb1p:Mz0lQG2m0TzZK4hhJduFVNg8Tub/
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor.Win32.Emotet.aina also known as:

Elasticmalicious (high confidence)
DrWebTrojan.DownLoader34.9669
MicroWorld-eScanTrojan.GenericKDZ.69110
FireEyeGeneric.mg.fd6448c62f6929f2
Qihoo-360Generic/Trojan.cf0
ALYacTrojan.GenericKDZ.69110
MalwarebytesTrojan.MalPack.TRE
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 005600f21 )
BitDefenderTrojan.GenericKDZ.69110
K7GWTrojan ( 005600f21 )
Cybereasonmalicious.8beb73
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaF.34144.RqW@aa1U6xdj
CyrenW32/Emotet.AOD.gen!Eldorado
SymantecTrojan.Emotet
APEXMalicious
KasperskyBackdoor.Win32.Emotet.aina
AlibabaTrojan:Win32/Emotet.1fb6e8b3
ViRobotTrojan.Win32.Emotet.704512.A
AegisLabTrojan.Win32.Emotet.L!c
RisingTrojan.Kryptik!1.C71F (CLOUD)
Ad-AwareTrojan.GenericKDZ.69110
SophosTroj/Emotet-CKJ
F-SecureTrojan.TR/AD.Emotet.MU
TrendMicroTROJ_GEN.R002C0DGU20
EmsisoftTrojan.Emotet (A)
IkarusTrojan-Banker.Emotet
F-ProtW32/Emotet.AOD.gen!Eldorado
AviraTR/AD.Emotet.MU
FortinetW32/Emotet.FHGO!tr
ArcabitTrojan.Generic.D10DF6
ZoneAlarmBackdoor.Win32.Emotet.aina
MicrosoftTrojan:Win32/Emotet.ARJ!MTB
AhnLab-V3Trojan/Win32.Emotet.R346334
McAfeeEmotet-FRI!FD6448C62F69
MAXmalware (ai score=85)
PandaTrj/Genetic.gen
ESET-NOD32Win32/Emotet.CD
TrendMicro-HouseCallTROJ_GEN.R002C0DGU20
GDataWin32.Trojan-Spy.Emotet.QZZAXM
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Backdoor.Win32.Emotet.aina?

Backdoor.Win32.Emotet.aina removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment