Malware

Cerbu.72214 (file analysis)

Malware Removal

The Cerbu.72214 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Cerbu.72214 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Oriya
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Cerbu.72214?


File Info:

name: 7792F7A25B09CF574ED8.mlw
path: /opt/CAPEv2/storage/binaries/92083162b7d8b7a4122d122438107fd053b8b32efa59d49ead33bececd5bb096
crc32: B0E5DEBC
md5: 7792f7a25b09cf574ed8d558432376ee
sha1: 01681a8fe1879e1bd56ac64b84d6d1ecd7fe53c6
sha256: 92083162b7d8b7a4122d122438107fd053b8b32efa59d49ead33bececd5bb096
sha512: 203b0ada7e4323379d605300b888832d007b6a969f58239dcdbfc236b99b1eb26481b3acbd830bf00aa3f13fc6b1247015a0170ed4136351d94363f529dd8615
ssdeep: 1536:86BkV+OXzzH4lUxCmC6ZWDT312igr+rjA92POaIMtKBrDBAc3q4yNrY9LHavUf:86BkVHr1xTQsBWwXetK/RH9+sf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12CB3F183F6BF4330D6F58934986A618A8FB4BC28DFA423D5AB071CD45EED0C646B5427
sha3_384: 9bd9d1b6504fbb6dbe6706212b0aad843808ab4766b40006dae9303b0309d98b98ae02df4a6f4cd660a2c09431c81c6f
ep_bytes: 535ab801000000e8000000005b83eb0c
timestamp: 2013-02-13 19:10:49

Version Info:

Coder: NEOx
Comments: Cool PE Editor !!!
CompanyName: Underground InformatioN Center
Credits: NiFi, Dr.Golova, SOLDIER, Corbio, Rook, SUnteXx, V.Vilman, JFX, dum0h, .Cryorb, Volodya, spEctoRius, cyberbob, FEUERRADER, .::D.e.M.o.N.i.X::., dyn!o, Bad_guy, Aster!x, lepton, ...
FileDescription: PE Tools v1.5 Xmas Edition
FileVersion: 1.5.400.2003
InternalName: PE Tools v1.5 Xmas Edition
LegalCopyright: Copyright © 2003 Underground InformatioN Center
LegalTrademarks: PE Tools v1.5 Xmas Edition
OriginalFilename: PETools.exe
PrivateBuild: Public version
ProductName: PE Tools v1.5 Xmas Edition
ProductVersion: 1.5.400.2003
SpecialBuild: Visit http://www.uinc.ru/ for updates.
Translation: 0x0409 0x04b0

Cerbu.72214 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Zbot.lJz0
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader8.10489
MicroWorld-eScanGen:Variant.Cerbu.72214
ALYacGen:Variant.Cerbu.72214
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.107062
SangforTrojan.Win32.Agent.atgen
K7AntiVirusTrojan ( 005325371 )
K7GWTrojan ( 005325371 )
Cybereasonmalicious.25b09c
BitDefenderThetaAI:Packer.7E4744021F
VirITTrojan.Win32.SHeur4.BBJA
CyrenW32/RuTroj.A.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Kryptik.BCJI
ClamAVWin.Trojan.Agent-576760
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Cerbu.72214
NANO-AntivirusTrojan.Win32.Zbot.brsvit
SUPERAntiSpywareTrojan.Agent/Gen-PWS
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10b533d6
SophosML/PE-A + Troj/Zbot-FHX
ComodoTrojWare.Win32.Spy.Zbot.JDBM@4ug0ls
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionPWS-Zbot-FAMR!7792F7A25B09
FireEyeGeneric.mg.7792f7a25b09cf57
EmsisoftGen:Variant.Cerbu.72214 (B)
IkarusTrojan-Spy.Win32.Zbot
JiangminTrojanSpy.Zbot.cvet
AviraTR/Crypt.ZPACK.Gen
MAXmalware (ai score=81)
Antiy-AVLTrojan/Generic.ASMalwS.1385A3
MicrosoftPWS:Win32/Zbot
GDataGen:Variant.Cerbu.72214
CynetMalicious (score: 100)
AhnLab-V3Spyware/Win32.Zbot.R52841
McAfeePWS-Zbot-FAMR!7792F7A25B09
TACHYONTrojan-Spy/W32.ZBot.114688.DV
VBA32Trojan.Downloader
MalwarebytesBackdoor.Agent.RND
APEXMalicious
RisingTrojan.Win32.Generic.141B5B8B (C64:YzY0OiRUBuwyHGqn)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_57%
FortinetPossibleThreat
WebrootW32.InfoStealer.Zeus
AVGWin32:Malware-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Cerbu.72214?

Cerbu.72214 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment