Malware

Cerbu.156416 (file analysis)

Malware Removal

The Cerbu.156416 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Cerbu.156416 virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with Themida
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Cerbu.156416?


File Info:

name: 4490B140CC25FA3F68B1.mlw
path: /opt/CAPEv2/storage/binaries/b7e7ba1c3ab5258aa93be137da896fa6a125ccb6f961f4da79cf63201f943157
crc32: 04189CD7
md5: 4490b140cc25fa3f68b1703cd7d26ff4
sha1: a0514952751a0bf0652d72b9ed3023c919db3a10
sha256: b7e7ba1c3ab5258aa93be137da896fa6a125ccb6f961f4da79cf63201f943157
sha512: a6f1eb3d9ed4e1e7ebac4422c21dd953f4e6dd256281fc1f5c0823d1a26ff18a921253fb9af46dff729fa5dec1ba347c89dbb5a2ddf8ee1363a531b5d6bb57f7
ssdeep: 98304:Gq5G+vNo9fcOJQdQI7QbtTEG4Hyfz6MkpKvYhb6epx19qlvCliyEaSh:Gq55No9kKiQbVhGGzYp1EepxjdXSh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1973633311245C8E7C2579ABA7C9F00164BAA13616FB13D568D4F8E5A06B0B3D13AF73E
sha3_384: f86b47a93fe45f07e9cf97c7afcc0b77933ed748fe13584bcd505ce930a8028aced257262bb36d66423ed2b583b1ec46
ep_bytes: e84b0100005389e3538b73088b7b10fc
timestamp: 2023-05-20 12:23:54

Version Info:

0: [No Data]

Cerbu.156416 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Sdum.4!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Cerbu.156416
FireEyeGeneric.mg.4490b140cc25fa3f
ALYacGen:Variant.Cerbu.156416
MalwarebytesMalware.Heuristic.1003
K7AntiVirusRiskware ( 00584baa1 )
K7GWRiskware ( 00584baa1 )
Cybereasonmalicious.2751a0
ArcabitTrojan.Cerbu.D26300
BitDefenderThetaGen:NN.ZexaF.36196.@NW@aCw6zuc
CyrenW32/Cerbu.BT.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
APEXMalicious
CynetMalicious (score: 100)
KasperskyVHO:Trojan.Win32.Sdum.gen
BitDefenderGen:Variant.Cerbu.156416
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Evo-gen [Trj]
EmsisoftGen:Variant.Cerbu.156416 (B)
VIPREGen:Variant.Cerbu.156416
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
Trapminemalicious.high.ml.score
SophosGeneric Reputation PUA (PUA)
Antiy-AVLTrojan/Win32.Sdum
MicrosoftProgram:Win32/Wacapew.C!ml
ZoneAlarmVHO:Trojan.Win32.Sdum.gen
GDataGen:Variant.Cerbu.156416
GoogleDetected
AhnLab-V3Malware/Win.Generic.R535424
McAfeeArtemis!4490B140CC25
MAXmalware (ai score=83)
VBA32BScope.Trojan.DelShad
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002H0CEL23
RisingTrojan.Generic@AI.100 (RDML:laoqHtJ/uSCXCLDzQ/CU7w)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Cerbu.156416!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Cerbu.156416?

Cerbu.156416 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment