Backdoor

Backdoor.Win32.Emotet.amdk (file analysis)

Malware Removal

The Backdoor.Win32.Emotet.amdk is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Emotet.amdk virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Russian
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor.Win32.Emotet.amdk?


File Info:

crc32: B8CDD3D2
md5: d6fbe55403ab2655f195088c6001800b
name: upload_file
sha1: d0c497bf6cf6fbab2c63d946779cebb84541b048
sha256: 193c6c2a3da5ae07460374c3aab42963b4c2b46c294c9be4b79ab366d36529ae
sha512: e8c4df2742956a4573edf371dab53da810c399632246cd29cf195a1891e8544c3d1163c2afd78bb9d3b5df5a41e11bd968a2d1efd74817e3252efe73ab97536e
ssdeep: 6144:GPHIFvHxVBxWrhtOjMcD+t14e13gvXr7fa+CYSJWy:GPoFPxVB0r/OjMciV1yja+3u
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: nlsbres.dll
FileVersion: 6.1.7601.23572 (win7sp1_ldr.161011-0600)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 6.1.7601.23572
FileDescription: NLSBuild resource DLL
OriginalFilename: nlsbres.dll
Translation: 0x0409 0x04b0

Backdoor.Win32.Emotet.amdk also known as:

Elasticmalicious (high confidence)
DrWebTrojan.DownLoader34.10090
MicroWorld-eScanTrojan.GenericKDZ.69120
FireEyeTrojan.GenericKDZ.69120
ALYacTrojan.Agent.EUGP
K7AntiVirusTrojan ( 0056b94b1 )
BitDefenderTrojan.GenericKDZ.69120
K7GWTrojan ( 0056b94b1 )
TrendMicroTrojan.Win32.WACATAC.THGCOBO
BitDefenderThetaGen:NN.Zextet.34144.vq0@aaqpx8dk
F-ProtW32/Kryptik.BRY.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyBackdoor.Win32.Emotet.amdk
AlibabaTrojan:Win32/Emotet.e1ad8b4a
Ad-AwareTrojan.GenericKDZ.69120
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
Invinceaheuristic
FortinetW32/GenKryptik.EPAZ!tr
EmsisoftTrojan.Emotet (A)
IkarusTrojan.Win32.Krypt
CyrenW32/Kryptik.BRY.gen!Eldorado
MAXmalware (ai score=88)
ArcabitTrojan.Generic.D10E00
ZoneAlarmBackdoor.Win32.Emotet.amdk
MicrosoftTrojan:Win32/Emotet.DGK!MTB
AhnLab-V3Trojan/Win32.Kryptik.R346329
McAfeeEmotet-FRO!D6FBE55403AB
MalwarebytesTrojan.MalPack.TRE
ESET-NOD32a variant of Win32/GenKryptik.EPHQ
TrendMicro-HouseCallTrojan.Win32.WACATAC.THGCOBO
RisingTrojan.Kryptik!1.C82B (CLOUD)
GDataTrojan.GenericKDZ.69120
AVGFileRepMalware
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.6d8

How to remove Backdoor.Win32.Emotet.amdk?

Backdoor.Win32.Emotet.amdk removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment