Backdoor

Backdoor:Win32/Drateam.B information

Malware Removal

The Backdoor:Win32/Drateam.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Drateam.B virus can do?

  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Backdoor:Win32/Drateam.B?


File Info:

name: BC097D765BF53B3CD30C.mlw
path: /opt/CAPEv2/storage/binaries/be1e2a85fc3f87a19cb447867f54a35406ec7d1da051671522dc67ba8f3c2c62
crc32: FBF584A0
md5: bc097d765bf53b3cd30c425180534faa
sha1: b1b7ea25532d37167cc8afabc8b411e6df665b2c
sha256: be1e2a85fc3f87a19cb447867f54a35406ec7d1da051671522dc67ba8f3c2c62
sha512: 0a40f4dcac98991782f5e4bb6ec2941db65e232f78353354ad9669e5c0950f319c2e8ffa8347b75a7543e5cb0e7ae79532ffafc4f97f9a1642e7c32436c53048
ssdeep: 1536:38mqLtshOtqbm4QcE8e/fGe8QHrvOjxYv4dk6Hd6twQamU1SeFAATPk:szJtqbA/GebvtvIk4QxU1SeF7s
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T123A34A16F6C188B3D11409BD4C8FE2FAA9397A142D2975A7B5EE8F4D887D3C2161C2D3
sha3_384: e3aefd1769b980b3dbdfb0c5ccef359681fa86947c65671f88ded81d1ab86057f7cf7d253cee178866d36c8d5b747d00
ep_bytes: 8d6c01008b45900f840000000085c00f
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Backdoor:Win32/Drateam.B also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Hupigon.lts7
MicroWorld-eScanGenPack:Generic.Hupigon.AND.DB9D4CCE
ClamAVWin.Trojan.Hupigon-34677
FireEyeGeneric.mg.bc097d765bf53b3c
CAT-QuickHealBackdoor.Drateam.B8
SkyhighBehavesLike.Win32.Ipamor.nh
McAfeeBackDoor-AWQ.gen.aa
MalwarebytesGeneric.Malware.AI.DDS
VIPREGenPack:Generic.Hupigon.AND.DB9D4CCE
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 7000000f1 )
AlibabaBackdoor:Win32/Drateam.9ff4aba0
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.5532d3
BitDefenderThetaAI:Packer.C524BE9424
VirITBackdoor.Win32.Generic.AWWB
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Delf.OFA
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Ransom.Win32.Convagent.gen
BitDefenderGenPack:Generic.Hupigon.AND.DB9D4CCE
NANO-AntivirusTrojan.Win32.Beizhu.bjqnx
AvastWin32:OnLineGames-FOH [Trj]
TencentMalware.Win32.Gencirc.10bf94e5
TACHYONBackdoor/W32.Hupigon.101321
SophosMal/Silvana-A
F-SecureDropper.DR/Delphi.Gen
DrWebTrojan.Siggen19.30647
ZillyaBackdoor.Hupigon.Win32.44634
TrendMicroTROJ_DELF.AT
Trapminemalicious.moderate.ml.score
EmsisoftGenPack:Generic.Hupigon.AND.DB9D4CCE (B)
IkarusTrojan.Win32.Agent
GDataGenPack:Generic.Hupigon.AND.DB9D4CCE
JiangminBackdoor/Hupigon.aazd
GoogleDetected
AviraDR/Delphi.Gen
Antiy-AVLTrojan[Backdoor]/Win32.Hupigon
KingsoftWin32.HeurC.KVM005.a
XcitiumBackdoor.Win32.Hupigon.~v012@1qooa6
ArcabitGenPack:Generic.Hupigon.AND.DB9D4CCE
ZoneAlarmHEUR:Trojan-Ransom.Win32.Convagent.gen
MicrosoftBackdoor:Win32/Drateam.B
VaristW32/Risk.HDGP-8055
ALYacGenPack:Generic.Hupigon.AND.DB9D4CCE
MAXmalware (ai score=99)
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_DELF.AT
RisingTrojan.AntiAV!1.647B (CLASSIC)
YandexBackdoor.Drateam!ZjmICJbwvR8
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.2588.susgen
FortinetW32/SpyAgent.F!tr
AVGWin32:OnLineGames-FOH [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor:Win32/Drateam.B?

Backdoor:Win32/Drateam.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment