Backdoor

Backdoor:Win32/Berbew!pz (file analysis)

Malware Removal

The Backdoor:Win32/Berbew!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Berbew!pz virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Berbew!pz?


File Info:

name: E909D0A089804797776A.mlw
path: /opt/CAPEv2/storage/binaries/b3ebc57a78d9a244147a97ab4fb7a40c3b69e5d064ab943e1ac3b38b41a3a9a8
crc32: 9A406928
md5: e909d0a089804797776a61c28faa6a1e
sha1: 424a39602f7cf843fecd0d5f4938fe6bf39abde2
sha256: b3ebc57a78d9a244147a97ab4fb7a40c3b69e5d064ab943e1ac3b38b41a3a9a8
sha512: 294a22dd04e90e40533169f4f11c63de283505133b03c2d3e505ef88efc32a572cb61b75618e54253bc563c5f3cbb05397ee018f6c053e65657829f24be08cdf
ssdeep: 12288:Xjvrt+4s5t6NSN6G5tb0fX5t6NSN6G5tTvz:Xbrt+4Dc6C0ec6gvz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A6A47C5B5FAB6213C253C8B56D476961D5F487D71FA839107CEB8008ABBDA08C2F5E83
sha3_384: cdc71f68e3e727d450b2dd4ea4d88636fd07827dbc8964cf961dc1657d1bde41a03fe14baa338258b2daddc9eb499ead
ep_bytes: 906090909090b8001040009090bbf87e
timestamp: 2018-02-05 18:29:59

Version Info:

0: [No Data]

Backdoor:Win32/Berbew!pz also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanBackdoor.Hangup.B
CAT-QuickHealWorm.Dorkbot.A
SkyhighBehavesLike.Win32.Generic.gh
McAfeeTrojan-FVOJ!E909D0A08980
MalwarebytesGeneric.Malware.AI.DDS
VIPREBackdoor.Hangup.B
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
BitDefenderBackdoor.Hangup.B
K7GWTrojan ( 005780dd1 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaAI:Packer.C5B833A61E
VirITWorm.Win32.Berbew.G
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Spy.Qukart
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Crypted-30
KasperskyTrojan-Spy.Win32.Qukart.af
NANO-AntivirusTrojan.Win32.Qukart.iuawxr
TencentTrojan-Ransom.Win32.Pornoasset.a
TACHYONBackdoor/W32.Padodor
SophosMal/Padodor-A
BaiduWin32.Trojan-Spy.Quart.a
F-SecureTrojan.TR/Spy.Qukart.NB
DrWebBackDoor.HangUp.43832
ZillyaTrojan.QukartGen.Win32.1
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.e909d0a089804797
EmsisoftBackdoor.Hangup.B (B)
IkarusTrojan.Spy.Qukart
GDataWin32.Trojan.PSE.1A8ERTK
JiangminTrojanSpy.Qukart.ajlg
VaristW32/Qukart.K.gen!Eldorado
AviraTR/Spy.Qukart.NB
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
ArcabitBackdoor.Hangup.B
ZoneAlarmTrojan-Spy.Win32.Qukart.af
MicrosoftBackdoor:Win32/Berbew!pz
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
ALYacBackdoor.Hangup.B
MAXmalware (ai score=84)
DeepInstinctMALICIOUS
VBA32BScope.Backdoor.Berbew
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Berbew!1.AE0A (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Qukart.A!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.02f7cf
AvastWin32:TrojanX-gen [Trj]

How to remove Backdoor:Win32/Berbew!pz?

Backdoor:Win32/Berbew!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment