Backdoor

About “Backdoor:Win32/Berbew!pz” infection

Malware Removal

The Backdoor:Win32/Berbew!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Berbew!pz virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • Uses Windows utilities for basic functionality
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Berbew!pz?


File Info:

name: 355285E7C0B35C766A20.mlw
path: /opt/CAPEv2/storage/binaries/7ca9fb686993806fba6a9798990f7f9bc5f2bbe3e5cdf8e087d5aa7bc0f2c3ca
crc32: 8723E54D
md5: 355285e7c0b35c766a20e0e3ee5ec9c4
sha1: 4144b04f95f17b43b3464fc4381bd2c7488e4b1b
sha256: 7ca9fb686993806fba6a9798990f7f9bc5f2bbe3e5cdf8e087d5aa7bc0f2c3ca
sha512: 347d13ecac7b9a22876ee3f0a8dab4836ca3c1d7585b881258ddd28ac3c8b1fc0819b6c402d8e69c7eec2ac4b355d6639bf5136370f1307d323e259d48d78eb7
ssdeep: 1536:OABw6T5mxetTXV71Zlx/ggXEC5pNsJifTduD4oTxw:OwwQ1oct5PsJibdMTxw
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14C636CB6624E26E1C0030773167ED0BAA7FB846D8FAD889058D4C92F359EF5E667C341
sha3_384: ab0ccde549b64badfbef736dad3dd08f71d32c56a640c4f92f3f51ce8ae281d86c0db1ab793e6619264a07f37e1cc6d6
ep_bytes: 609090909090b8001040009090bbf87e
timestamp: 2022-03-16 18:29:59

Version Info:

0: [No Data]

Backdoor:Win32/Berbew!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Qukart.4!c
tehtrisGeneric.Malware
MicroWorld-eScanBackdoor.Hangup.B
ClamAVWin.Trojan.Crypted-28
FireEyeGeneric.mg.355285e7c0b35c76
SkyhighBehavesLike.Win32.Generic.kh
ALYacBackdoor.Hangup.B
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Qukart.Win32.2100939
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
AlibabaTrojanSpy:Win32/Qukart.654fcea6
K7GWTrojan ( 005780dd1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.CC3D5BBB21
VirITWorm.Win32.Berbew.G
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Spy.Qukart
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Spy.Win32.Qukart.af
BitDefenderBackdoor.Hangup.B
NANO-AntivirusTrojan.Win32.Qukart.jptaza
AvastWin32:TrojanX-gen [Trj]
TencentTrojan-Ransom.Win32.Pornoasset.a
TACHYONBackdoor/W32.Padodor
SophosMal/Padodor-A
BaiduWin32.Trojan-Spy.Quart.a
F-SecureTrojan.TR/Spy.Qukart.NB
DrWebBackDoor.HangUp.43832
VIPREBackdoor.Hangup.B
TrendMicroTROJ_GEN.R002C0DJH23
Trapminemalicious.high.ml.score
EmsisoftBackdoor.Hangup.B (B)
IkarusTrojan.Crypt
JiangminTrojanSpy.Qukart.ahax
GoogleDetected
AviraTR/Spy.Qukart.NB
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Berbew!pz
ArcabitBackdoor.Hangup.B
ZoneAlarmTrojan-Spy.Win32.Qukart.af
GDataBackdoor.Hangup.B
VaristW32/Qukart.K.gen!Eldorado
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
McAfeeTrojan-FVOJ!355285E7C0B3
MAXmalware (ai score=89)
VBA32BScope.Backdoor.Berbew
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DJH23
RisingBackdoor.Berbew!1.AE0A (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Qukart.A!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.f95f17
DeepInstinctMALICIOUS

How to remove Backdoor:Win32/Berbew!pz?

Backdoor:Win32/Berbew!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment