Malware

Cerbu.155323 malicious file

Malware Removal

The Cerbu.155323 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Cerbu.155323 virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Cerbu.155323?


File Info:

name: 9C054FECFBCCFEF0A9B8.mlw
path: /opt/CAPEv2/storage/binaries/9dfc9b153746eea77e8f97890de55ed38e161adc57e06bbcdd7e7efb59da2ee8
crc32: 57F1D6E2
md5: 9c054fecfbccfef0a9b8a347734c5484
sha1: 8b46e7fd5bf1403da4b0dbb0346f1c04f2fe9586
sha256: 9dfc9b153746eea77e8f97890de55ed38e161adc57e06bbcdd7e7efb59da2ee8
sha512: b334df789a6056704b24438d7e68fa82ed86aa1e4555015635c5978b57fc1c937f344e1742142fb53bb2fd42815f35e4930cec989175bb9c314c4474ea42bee7
ssdeep: 6144:C3KH5s9qX/9PY8fO3b2gpJkBq9TBOvIVirv40P0:Co5s9qlPY8fvuJgq9TovAir4
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T15064BEA1B3A44CF5DC77823EC8518916D6B27C5A0B60C64F13A8365A9F733A14C3DBA9
sha3_384: c21f4dd8faf77220a3111988a513e9b316eeaaac7d7ecbc9b39ac800ac019649b47b2835d279b380bdbe32dee8b4582b
ep_bytes: e848feffffc82000004c897c24f84883
timestamp: 2020-12-09 14:10:08

Version Info:

CompanyName: Oracle Corporation
FileDescription: Java(TM) Platform SE binary
FileVersion: 8.0.2810.9
Full Version: 1.8.0_281-b09
InternalName: javaw
LegalCopyright: Copyright © 2020
OriginalFilename: javaw.exe
ProductName: Java(TM) Platform SE 8
ProductVersion: 8.0.2810.9
Translation: 0x0000 0x04b0

Cerbu.155323 also known as:

LionicTrojan.Win32.Convagent.j!c
MicroWorld-eScanGen:Variant.Cerbu.155323
FireEyeGen:Variant.Cerbu.155323
McAfeeArtemis!9C054FECFBCC
CylanceUnsafe
AlibabaTrojan:Win64/Filecoder.07e9a1b0
CrowdStrikewin/malicious_confidence_60% (W)
CyrenW64/Ransom.QW.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win64/Filecoder.GG
Paloaltogeneric.ml
KasperskyVHO:Trojan-Ransom.Win32.Convagent.gen
BitDefenderGen:Variant.Cerbu.155323
AvastWin64:Trojan-gen
TencentWin32.Trojan.Filecoder.Snkl
Ad-AwareGen:Variant.Cerbu.155323
EmsisoftGen:Variant.Cerbu.155323 (B)
F-SecureTrojan.TR/FileCoder.fxmlx
TrendMicroRansom_Convagent.R002C0PK322
McAfee-GW-EditionRDN/Ransom
SophosMal/Generic-S
GDataGen:Variant.Cerbu.155323
JiangminTrojan.Blocker.urx
WebrootW32.Ransom.Gen
GoogleDetected
AviraTR/FileCoder.fxmlx
MAXmalware (ai score=86)
ArcabitTrojan.Cerbu.D25EBB
ZoneAlarmVHO:Trojan-Ransom.Win32.Convagent.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Ransom.R532639
Acronissuspicious
ALYacGen:Variant.Cerbu.155323
MalwarebytesGeneric.Malware/Suspicious
RisingRansom.Agent!8.6B7 (CLOUD)
IkarusWorm.Win32.Soulclose
FortinetW64/Filecoder.GG!tr
AVGWin64:Trojan-gen
PandaTrj/RansomGen.A

How to remove Cerbu.155323?

Cerbu.155323 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment