Backdoor

Backdoor:Win32/Vawtrak (file analysis)

Malware Removal

The Backdoor:Win32/Vawtrak is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Vawtrak virus can do?

  • Sample contains Overlay data
  • Unconventionial language used in binary resources: Georgian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Backdoor:Win32/Vawtrak?


File Info:

name: D02B09B6DA2F58D22E5D.mlw
path: /opt/CAPEv2/storage/binaries/7bea5a35c0cea1a371d4014178c9f5039252808a4621f1e9f0d0c581b0aeac10
crc32: CADC8C6A
md5: d02b09b6da2f58d22e5d3e128d55b247
sha1: 7680a64d04d40deec22bd6b104d4f159a2b19b67
sha256: 7bea5a35c0cea1a371d4014178c9f5039252808a4621f1e9f0d0c581b0aeac10
sha512: 8452dfebe367f4704ceecd0db598fef83b86b2dc46383e1e9cb442b35a68dd3740c1d8023c65471e3d0351defc3164be5d4c4416518d59183e78a8bac72c5315
ssdeep: 3072:Ded+UxfPiMqbMbrNAPDO+BKpfpUkgKtznFGpB6AQs9OMS6w+Oes/GDxiFf2ClqS5:DmTbbrqPxefpUnEFGLwsPpeeDx+fDH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F814F10CE44AD0B7D9E606F679858BD3931C124C233B2C5F2B1EAB1666A14CF0D61BED
sha3_384: fb9f1a5c9fca722f7c98b47351e9e98bb5a2597a9997d22ea75d0a3be62b6c352e74b0c2ebd31ec38f03548c07791a1a
ep_bytes: 6a7068d8f14200e8de01000033db538b
timestamp: 2005-07-22 07:21:35

Version Info:

Comments:
CompanyName: Microsoft Bursting
FileDescription: Complimented
FileVersion: 223, 80, 127, 250
InternalName: Vocals
LegalCopyright: Copyright © 2014
LegalTrademarks:
OriginalFilename: Ban.exe
PrivateBuild:
ProductName: Microsoft Caseload
ProductVersion: 8, 76, 123, 154
SpecialBuild:

Backdoor:Win32/Vawtrak also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.mAsy
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.FFVZ
ClamAVWin.Packed.Ursu-7372399-0
FireEyeTrojan.Agent.FFVZ
CAT-QuickHealBackdoor.VawtrakCS.S452016
McAfeeGenericRXBA-JH!D02B09B6DA2F
Cylanceunsafe
ZillyaBackdoor.Androm.Win32.27664
SangforSuspicious.Win32.Save.ins
K7AntiVirusSpyware ( 0055b8741 )
AlibabaTrojan:Win32/Vawtrak.90dd
K7GWSpyware ( 0055b8741 )
Cybereasonmalicious.d04d40
ArcabitTrojan.Agent.FFVZ
VirITTrojan.Win32.Dnldr17.BQDV
CyrenW32/S-ec502958!Eldorado
SymantecInfostealer.Shifu
tehtrisGeneric.Malware
APEXMalicious
CynetMalicious (score: 100)
BitDefenderTrojan.Agent.FFVZ
ViRobotTrojan.Win32.Inject.208912
AvastWin32:Shifu-D [Trj]
TencentMalware.Win32.Gencirc.10b2f7f9
SophosTroj/Tinba-FL
F-SecureTrojan.TR/AD.Shifu.bdmlu
DrWebTrojan.DownLoader17.28491
VIPRETrojan.Agent.FFVZ
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
EmsisoftTrojan.Agent.FFVZ (B)
IkarusBackdoor.Win32.Vawtrak
JiangminTrojan.Generic.jmb
AviraTR/AD.Shifu.bdmlu
MAXmalware (ai score=85)
Antiy-AVLTrojan[Backdoor]/Win32.Androm
XcitiumTrojWare.Win32.Spy.Shiz.ND@6uylou
MicrosoftBackdoor:Win32/Vawtrak
SUPERAntiSpywareTrojan.Agent/Gen-Cripack
GDataWin32.Trojan.PSE.BT9IQ
GoogleDetected
AhnLab-V3Trojan/Win32.Agent.C1032537
Acronissuspicious
ALYacTrojan.Agent.FFVZ
TACHYONTrojan/W32.Agent.208901.B
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/CI.A
RisingBackdoor.Vawtrak!1.AE6A (CLASSIC)
SentinelOneStatic AI – Malicious PE
FortinetW32/Scribble.B!tr
AVGWin32:Shifu-D [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor:Win32/Vawtrak?

Backdoor:Win32/Vawtrak removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment