Malware

Cerbu.110155 (B) (file analysis)

Malware Removal

The Cerbu.110155 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Cerbu.110155 (B) virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (10 unique times)
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Russian
  • Looks up the external IP address
  • Network activity contains more than one unique useragent.
  • Attempts to modify proxy settings
  • Attempts to create or modify system certificates
  • Anomalous binary characteristics

Related domains:

ipinfo.io
ipqualityscore.com
s3.tebi.io
ingstorage.com
duzlwewk2uk96.cloudfront.net
7e10a716-f462-4371-a152-105d67ce51a8.s3.ap-south-1.amazonaws.com
cdn.discordapp.com
perfect-request-smart.com
the-flash-man.com
eduarroma.tumblr.com
secure.globalsign.com
ocsp.digicert.com
crt.usertrust.com
ocsp.comodoca.com
ocsp.usertrust.com
ocsp.sectigo.com

How to determine Cerbu.110155 (B)?


File Info:

crc32: BB5C63DE
md5: d4359d5d0bbe9828a1340fb1d8537a74
name: D4359D5D0BBE9828A1340FB1D8537A74.mlw
sha1: 5c8805bd3c08d9866748ac033d9e0497bb84761c
sha256: 57e2f9ee6aaad4097ac2b1151fe1cf9546c8fbc470670b73c8039285f4fd4db5
sha512: 3ea8565784f17f44f1236d4176146e335e409f84514fff3c8d3a0099d8e7fe02dde340319e910b04296010df5e050835aa68bb62b40c1d18cd2c985ab23c2751
ssdeep: 98304:pAI+SlhLuZHUt0eb4gECc3TKnUESV/eqRrqmfgSmhML0CzSbquFwa1//NbAxg6gJ:itBUieh7c56qRTL0oLKw+NcA4BzicQ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: GameBox INC
FileDescription: GameBox 5 Installation
FileVersion: 5
Comments:
CompanyName: GameBox INC
Translation: 0x0409 0x04e4

Cerbu.110155 (B) also known as:

DrWebTrojan.PWS.Stealer.29268
CAT-QuickHealTrojan.Win32
ALYacGen:Variant.Cerbu.110155
CylanceUnsafe
K7GWAdware ( 0057601f1 )
K7AntiVirusAdware ( 0057601f1 )
CyrenW32/MSIL_Troj.AQM.gen!Eldorado
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:DropperX-gen [Drp]
CynetMalicious (score: 100)
KasperskyTrojan-PSW.Win32.Tepfer.psysyv
BitDefenderGen:Variant.Cerbu.110155
MicroWorld-eScanGen:Variant.Cerbu.110155
TencentWin32.Trojan-downloader.Agent.Wozd
Ad-AwareGen:Variant.Cerbu.110155
SophosGeneric ML PUA (PUA)
FireEyeGeneric.mg.d4359d5d0bbe9828
EmsisoftGen:Variant.Cerbu.110155 (B)
SentinelOneStatic AI – Suspicious PE
AviraTR/Dldr.Agent.qqlrd
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Variant.Cerbu.110155
MAXmalware (ai score=86)
VBA32BScope.Trojan.Downloader
MalwarebytesMalware.AI.2429408844
IkarusTrojan.MSIL.Crypt
MaxSecureTrojan-Ransom.Win32.Crypmod.zfq
AVGWin32:DropperX-gen [Drp]

How to remove Cerbu.110155 (B)?

Cerbu.110155 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment