Backdoor

Backdoor:Win32/Simda!B malicious file

Malware Removal

The Backdoor:Win32/Simda!B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Simda!B virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Starts servers listening on 0.0.0.0:20017
  • Enumerates running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Network activity contains more than one unique useragent.
  • Fake User-Agent detected
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering

How to determine Backdoor:Win32/Simda!B?


File Info:

name: 4CB78BFE4EE2A0D22C3E.mlw
path: /opt/CAPEv2/storage/binaries/4ad2b53551be9641cca3e2a86b17607e60cdc74ddfd738bc409d4696d23b41db
crc32: E9FA26E4
md5: 4cb78bfe4ee2a0d22c3e5eb563afa6dc
sha1: 81a7b838c9f0d809f7e268d8f4eba2e2a9726150
sha256: 4ad2b53551be9641cca3e2a86b17607e60cdc74ddfd738bc409d4696d23b41db
sha512: 18726f34fa473fc5c7a70549ccd81572f9dddea81566f7e51a31063da89acd3a8f505e758644f86f97ead38601635b6de4680f30697858d143a1c58a5ade979b
ssdeep: 6144:l45rA5FSkJY8R/kpM3kRaWV/wEsNbqw8QlRTFiPurp+EStS3sth:vFSkB/kBubqw8vm+EKS3s
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C2747D2AA4508176E0F4223051FA7A6B2DBD2E6443ED28D377646E8D6C742F372391DF
sha3_384: 3709a16adf22111f02ec5a49813475ea27165e01ab9fb1de3007bbafc1ad1d6271d0b880a80bce0a6d1f7c9fdef64383
ep_bytes: 558bec83e4f881ec0c01000053565768
timestamp: 2011-05-26 03:20:41

Version Info:

0: [No Data]

Backdoor:Win32/Simda!B also known as:

BkavW32.AIDetect.malware2
ElasticWindows.Trojan.Zeus
MicroWorld-eScanGen:Variant.Ransom.Sodinokibi.66
FireEyeGeneric.mg.4cb78bfe4ee2a0d2
McAfeeGenericRXOK-SU!4CB78BFE4EE2
CylanceUnsafe
VIPREGen:Variant.Ransom.Sodinokibi.66
Sangfor[ARMADILLO V1.71]
CrowdStrikewin/malicious_confidence_100% (D)
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Spy.Shiz.NBX
APEXMalicious
ClamAVWin.Trojan.Generic-6323528-0
KasperskyVHO:Backdoor.Win32.Shiz.gen
BitDefenderGen:Variant.Ransom.Sodinokibi.66
AvastWin32:Shiz-JT [Trj]
Ad-AwareGen:Variant.Ransom.Sodinokibi.66
SophosML/PE-A + Mal/Emogen-Y
ComodoTrojWare.Win32.Spy.Shiz.AB@6t6eqm
DrWebTrojan.PWS.Ibank.468
TrendMicroPossible_KULUOZ-2
McAfee-GW-EditionBehavesLike.Win32.Backdoor.fh
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Ransom.Sodinokibi.66 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Invader.fju
AviraTR/Hijacker.Gen
MAXmalware (ai score=85)
MicrosoftBackdoor:Win32/Simda.gen!B
GDataWin32.Trojan.Spyshiz.A
CynetMalicious (score: 100)
Acronissuspicious
VBA32BScope.TrojanPSW.Ibank
ALYacGen:Variant.Ransom.Sodinokibi.66
MalwarebytesSimda.Backdoor.Stealer.DDS
TrendMicro-HouseCallPossible_KULUOZ-2
RisingTrojan.Generic@AI.88 (RDML:c7+vovkmVbqZyh7s0iOemw)
YandexTrojan.GenAsa!Cn3YwpEJMrc
IkarusBackdoor.Win32.Simda
MaxSecureTrojan.Malware.300983.susgen
BitDefenderThetaAI:Packer.6252219F1E
AVGWin32:Shiz-JT [Trj]
Cybereasonmalicious.e4ee2a

How to remove Backdoor:Win32/Simda!B?

Backdoor:Win32/Simda!B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment