Backdoor

Backdoor:Win64/TurtleLoader.UIN!dha information

Malware Removal

The Backdoor:Win64/TurtleLoader.UIN!dha is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win64/TurtleLoader.UIN!dha virus can do?

  • Sample contains Overlay data
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • CAPE detected the CobaltStrikeBeacon malware family
  • Collects information to fingerprint the system
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Backdoor:Win64/TurtleLoader.UIN!dha?


File Info:

name: A4AD7C2FD3844C1AEBC1.mlw
path: /opt/CAPEv2/storage/binaries/0d7f68be5a79e4bc159a2311fc2a050ab7e0a0c2bbbb9276e55ab39df3dca75f
crc32: 310D76CD
md5: a4ad7c2fd3844c1aebc1c3c7084c7367
sha1: 3f9de61d5c5b753d24a9c7c1452241dc4d3a6151
sha256: 0d7f68be5a79e4bc159a2311fc2a050ab7e0a0c2bbbb9276e55ab39df3dca75f
sha512: 177beb5168b175fab05bb838514781144e95aaf2c35a812dba2b245d2ee45748e16843b42c3382c7d4d9bf44f0b91e52effb0e8c8d861ebeeb238c6b15ca4198
ssdeep: 12288:umYH+FKjwjH4SgNA9ij96cxCtNDtoSmPuE716q+wNXb9Q8J:OEKjwjB+21yPr6q+kZQ8J
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T19B451940728E1D76E48252F141D5D912B7DCB25839B5ABB3E61F4E367DAA0C1BF8B2C0
sha3_384: 4630c7445ab346d743a651acabf432619f62368caea080bef4b90e1ccbaa94669f092db862417d4699d3d163a013ba08
ep_bytes: 53565755488d354a5efaff488dbedb6f
timestamp: 2021-07-10 18:57:17

Version Info:

0: [No Data]

Backdoor:Win64/TurtleLoader.UIN!dha also known as:

LionicTrojan.Win32.Jobutyve.4!c
MicroWorld-eScanTrojan.GenericKD.46611552
ALYacTrojan.GenericKD.46611552
MalwarebytesMalware.AI.3604117130
ZillyaTrojan.GenKryptik.Win64.8478
SangforBackdoor.Win64.Jobutyve.V95w
K7AntiVirusTrojan ( 0058164f1 )
AlibabaBackdoor:Win64/Jobutyve.90d6b9a6
K7GWTrojan ( 0058164f1 )
Cybereasonmalicious.d5c5b7
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win64/GenKryptik.GFGP
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Jobutyve.aek
BitDefenderTrojan.GenericKD.46611552
AvastWin64:Malware-gen
TencentWin32.Trojan.Jobutyve.Cdhl
EmsisoftTrojan.GenericKD.46611552 (B)
VIPRETrojan.GenericKD.46611552
TrendMicroTROJ_GEN.R002C0DDM23
McAfee-GW-EditionBehavesLike.Win64.Generic.th
FireEyeGeneric.mg.a4ad7c2fd3844c1a
SophosGeneric Reputation PUA (PUA)
SentinelOneStatic AI – Suspicious PE
GDataTrojan.GenericKD.46611552
MAXmalware (ai score=87)
Antiy-AVLTrojan/Win64.GenKryptik
ArcabitTrojan.Generic.D2C73C60
ZoneAlarmTrojan.Win32.Jobutyve.aek
MicrosoftBackdoor:Win64/TurtleLoader.UIN!dha
McAfeeArtemis!A4AD7C2FD384
VBA32Trojan.Jobutyve
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0DDM23
RisingBackdoor.TurtleLoader!8.12663 (CLOUD)
YandexTrojan.Jobutyve!gcWE5fGqVew
MaxSecureTrojan.Malware.119572839.susgen
FortinetW32/PossibleThreat
AVGWin64:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Backdoor:Win64/TurtleLoader.UIN!dha?

Backdoor:Win64/TurtleLoader.UIN!dha removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment