Backdoor

Backdoor:Win32/Delf.WC (file analysis)

Malware Removal

The Backdoor:Win32/Delf.WC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Delf.WC virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects Bochs through the presence of a registry key
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Backdoor:Win32/Delf.WC?


File Info:

name: DBB628324BDD0E77F0F4.mlw
path: /opt/CAPEv2/storage/binaries/7ce5d5581229b3c39e4dcec50812abc957f6e45f2c0ef8dd0cd5bc271dbcff02
crc32: F56D42FD
md5: dbb628324bdd0e77f0f452c99d7d0f01
sha1: e95d51fc442909b54d379ab15ca9b60dac53f199
sha256: 7ce5d5581229b3c39e4dcec50812abc957f6e45f2c0ef8dd0cd5bc271dbcff02
sha512: d100e14343ef43fdf1432c06eb0d66b2220a6cc469d62cb7d7b54ac4e78e1bd4a6ebd19f0c4339d29911d3a1588e9268f6a9995f47a4b074f5c1079abb4028b6
ssdeep: 12288:CJLx0kL4opUHecrCAsBmoKF3Z4mxxNDqVTVOCv:ClxdMopKrToKQmXMVTzv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T184E4237E17558C9AED5395335237AC068613EF96224B3198F3F5BC172AB744238AB80F
sha3_384: 4f389ba7637410c88ebc0e375542faa209d37b37100738750506910c160ce784d5b2606412b5a0c8635d3d4a83e26fb6
ep_bytes: 6801a05800e801000000c3c33b952a7b
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Backdoor:Win32/Delf.WC also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Heur.Zilix.1
FireEyeGeneric.mg.dbb628324bdd0e77
SkyhighBehavesLike.Win32.Pluto.jc
McAfeeArtemis!DBB628324BDD
MalwarebytesMachineLearning/Anomalous.94%
VIPREGen:Heur.Zilix.1
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 0001140e1 )
AlibabaBackdoor:Win32/Black.cc3401da
K7GWTrojan ( 0001140e1 )
Cybereasonmalicious.24bdd0
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Packed.ASProtect.AAB
APEXMalicious
TrendMicro-HouseCallTROJ_DLLSERV.MCL
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Heur.Zilix.1
NANO-AntivirusTrojan.Win32.Hupigon.ddczsq
AvastWin32:Evo-gen [Trj]
SophosMal/Behav-270
GoogleDetected
F-SecureTrojan.TR/Crypt.ASPM.Gen
DrWebTrojan.Ideo.187
ZillyaBackdoor.PePatch.Win32.30026
TrendMicroTROJ_DLLSERV.MCL
Trapminemalicious.high.ml.score
EmsisoftGen:Heur.Zilix.1 (B)
IkarusTrojan.Win32.ASProtect
JiangminPacked.Black.klm
VaristW32/Hupigon.G.gen!Eldorado
AviraTR/Crypt.ASPM.Gen
Kingsoftmalware.kb.b.988
MicrosoftBackdoor:Win32/Delf.WC
XcitiumMalware@#3fnd92q9q5cdh
ArcabitTrojan.Zilix.1
ZoneAlarmPacked.Win32.Black.d
GDataGen:Heur.Zilix.1
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.Hupigon.R1432
VBA32Trojan.Iauh
PandaGeneric Malware
RisingMalware.FakeXLS/ICON!1.6AC3 (CLASSIC)
YandexBackdoor.Hupigon!U4Ljt/you58
SentinelOneStatic AI – Malicious PE
BitDefenderThetaAI:Packer.550C8A141D
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (D)
alibabacloudTrojan

How to remove Backdoor:Win32/Delf.WC?

Backdoor:Win32/Delf.WC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment