Backdoor

Backdoor:Win32/Berbew!pz (file analysis)

Malware Removal

The Backdoor:Win32/Berbew!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Berbew!pz virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win32/Berbew!pz?


File Info:

name: EF1CBFF96643A3925BC6.mlw
path: /opt/CAPEv2/storage/binaries/d4b708f8840c34e3c769038e51285e8f9318650f846b49f59c4bf7539f862a8d
crc32: EE8838D1
md5: ef1cbff96643a3925bc65ef58d52fab7
sha1: dc870ed7e6b67cd541e0c1c66bd360661b621f45
sha256: d4b708f8840c34e3c769038e51285e8f9318650f846b49f59c4bf7539f862a8d
sha512: 1c92b6c6419cdf792579ff56c5329a55597c25a4211b291fcc3b5615a39711e74d0f70f24e3f8e8801518b430673639b281f6df2930edcf407ded9e6cc756a5b
ssdeep: 3072:iwCeY9BnWbTkoUduY94HeMp1ij4Sp+7H7wWkqrifbdB7dYk1Bx8DpsV6OzrCIwfE:UfSTkNanTijBOHhkym/89bKws
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15D149D1A92C80FB6FAC502718409477E76E0531BEE6B8F63E455402F31B2AED91FE791
sha3_384: 6a62a5ec30393328f550ddbf4879447b5c56574c267781946080d48ce14575fe185705c4d0a3381ed7a10c2c5844207e
ep_bytes: 90b80010400090bb38de400090b9dd5a
timestamp: 1987-08-01 05:39:38

Version Info:

0: [No Data]

Backdoor:Win32/Berbew!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Padodor.m!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Trojan.ShellObject.mWZ@aeFgVVo
CAT-QuickHealTrojan.GenericIH.S13286062
SkyhighBehavesLike.Win32.Generic.ch
McAfeeGenericRXPE-AP!BF5E1A2852D3
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Padodor.Win32.2240883
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
AlibabaBackdoor:Win32/Padodor.a89e9c10
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.7e6b67
ArcabitTrojan.ShellObject.E33FF2
BitDefenderThetaAI:Packer.20D60B8521
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Padodor.AB
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Lazy-10005438-0
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGen:Trojan.ShellObject.mWZ@aeFgVVo
NANO-AntivirusTrojan.Win32.Padodor.ivsqcx
AvastWin32:Padodor-V [Trj]
TencentBackdoor.Win32.Padodor.kp
EmsisoftGen:Trojan.ShellObject.mWZ@aeFgVVo (B)
F-SecureTrojan.TR/Crypt.XDR.Gen
DrWebBackDoor.Wdozer
VIPREGen:Trojan.ShellObject.mWZ@aeFgVVo
TrendMicroTROJ_GEN.R002C0DL623
SophosMal/Padodor-A
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Padodor.exys
VaristW32/Backdoor.DKIC-2994
AviraTR/Crypt.XDR.Gen
MAXmalware (ai score=82)
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Berbew!pz
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataGen:Trojan.ShellObject.mWZ@aeFgVVo
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32Backdoor.Padodor
TACHYONBackdoor/W32.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DL623
RisingBackdoor.Padodor!8.118 (TFE:5:fgpvVm3eZVO)
IkarusBackdoor.Win32.Padodor
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.B077!tr
AVGWin32:Padodor-V [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor:Win32/Berbew!pz?

Backdoor:Win32/Berbew!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment