Malware

Cerbu.122568 (file analysis)

Malware Removal

The Cerbu.122568 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Cerbu.122568 virus can do?

  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs
  • Binary compilation timestomping detected

How to determine Cerbu.122568?


File Info:

name: 28BF64FC2CD7957DBEBC.mlw
path: /opt/CAPEv2/storage/binaries/616cf6a69e6cd02193404a42c17e1c629e112c068b9ed7386302027ee5a3f83e
crc32: 12E794C5
md5: 28bf64fc2cd7957dbebc10a04b4f1e0b
sha1: 29a1377fb2dc234f970cb9914b7fed19cd9e4d4b
sha256: 616cf6a69e6cd02193404a42c17e1c629e112c068b9ed7386302027ee5a3f83e
sha512: 8057f612db72be0a1484141b49be62e3f6c8d8eb0984b244ca9ce875fefc614e2716a31bf0262b3c87474aff51e6241bdce6d2e181282d76e7900bb597b4dd1f
ssdeep: 12288:iBpkmIV2rdkmlgP5aMdU5crCteclPu+QIIrZXuLbKPC:iMmICFsI+P
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13B94923439FB601DF3B3AE665FE4B5AF9E1EF633270B64A910A1034A4722940DD91739
sha3_384: fde39967865a02a178595a0a5855e78c543affe1997af99f09f854d4469f181cd65de003592799bd4204c4f7a5c79c70
ep_bytes: ff2500204000554889e5ffd15d4889ec
timestamp: 2079-10-12 14:22:38

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: Console Compile Host
FileVersion: 1.0.0.0
InternalName: Console Compile Host.exe
LegalCopyright: Copyright © 2021
LegalTrademarks:
OriginalFilename: Console Compile Host.exe
ProductName: Console Compile Host
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Cerbu.122568 also known as:

LionicTrojan.Win32.Donut.4!c
Elasticmalicious (high confidence)
ClamAVWin.Packed.Bulz-9877042-0
ALYacGen:Variant.Cerbu.122568
MalwarebytesBackdoor.DCRat
K7AntiVirusTrojan ( 005817331 )
BitDefenderGen:Variant.Cerbu.122568
K7GWTrojan ( 005817331 )
CrowdStrikewin/malicious_confidence_90% (W)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.ABQQ
APEXMalicious
AvastWin32:CrypterX-gen [Trj]
CynetMalicious (score: 99)
KasperskyHEUR:Backdoor.MSIL.Crysan.gen
AlibabaBackdoor:MSIL/Crysan.39e62a26
MicroWorld-eScanGen:Variant.Cerbu.122568
TencentWin32.Trojan.Generic.Htcx
Ad-AwareGen:Variant.Cerbu.122568
SophosMal/Generic-S
DrWebBackDoor.AsyncRATNET.2
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.28bf64fc2cd7957d
EmsisoftGen:Variant.Cerbu.122568 (B)
IkarusTrojan.MSIL.Crypt
GDataGen:Variant.Cerbu.122568
AviraTR/Kryptik.mxivc
MAXmalware (ai score=88)
GridinsoftRansom.Win32.Sabsik.sa
ArcabitGeneric.Exploit.Donut.2.D570A8CE
MicrosoftVirTool:Win32/Wovdnut.gen!A
AhnLab-V3Exploit/Win.Donut.C4785569
McAfeeGenericRXQV-PK!28BF64FC2CD7
VBA32TScope.Trojan.MSIL
TrendMicro-HouseCallTROJ_GEN.R002H0CKM21
SentinelOneStatic AI – Malicious PE
FortinetMSIL/Kryptik.ABQQ!tr
BitDefenderThetaGen:NN.ZemsilF.34294.zm0@a40onMf
AVGWin32:CrypterX-gen [Trj]
Cybereasonmalicious.fb2dc2
Paloaltogeneric.ml

How to remove Cerbu.122568?

Cerbu.122568 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment