Malware

Doina.15465 (file analysis)

Malware Removal

The Doina.15465 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.15465 virus can do?

  • Attempts to connect to a dead IP:Port (2 unique times)
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Tries to unhook or modify Windows functions monitored by Cuckoo

Related domains:

www.ababbb.com
www.baidu.com

How to determine Doina.15465?


File Info:

crc32: A5DB67FE
md5: 314d06028e3ea30c18e027bf1e4014a1
name: 314D06028E3EA30C18E027BF1E4014A1.mlw
sha1: 834b12a57990ee16e9aa9296a6a1c3eb0fc9cf61
sha256: b2c15d4954fa7c62a73c69c3e1621e930b926555293710d1587c096835a19087
sha512: 9f9618890f6d085e0dd77a02d891ed1b744f7ac05802f929bc101c3b09b2fcd5e61b4616ccea5ab2a2a0f6384064b648b77813c0bfb0f90fc14fb3d70b194b4b
ssdeep: 12288:8XDwgP35rn5ahSxKYUQMleKTCfjxedWZYfg9HKZxZCDGfXuJaHzxYV8cDXM+APo:eDweN5oCMlI7xswYINdD+HzxYV8cvvU
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: UI - x57fax4e8ex672ax95fbx82b1x540dx4feex6539 x4ee3x7801 - x7d2bx82cfi x81eax5199
FileVersion: 2.0.0.1
CompanyName: x7d2bx82cfi@x7eddx5bf9x9886x57df
Comments: x7d2bx82cfi@x7eddx5bf9x9886x57df
ProductName: x65b0x7eddx5bf9x9886x57df
ProductVersion: 2.0.0.1
FileDescription: x7d2bx82cfi@x7eddx5bf9x9886x57df
Translation: 0x0804 0x04b0

Doina.15465 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005246d51 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Doina.15465
CrowdStrikewin/malicious_confidence_80% (W)
K7GWTrojan ( 00013a151 )
Cybereasonmalicious.57990e
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.CZOJ
APEXMalicious
AvastWin32:Trojan-gen
BitDefenderGen:Variant.Doina.15465
MicroWorld-eScanGen:Variant.Doina.15465
Ad-AwareGen:Variant.Doina.15465
SophosMal/Generic-S
ComodoPacked.Win32.MUPX.Gen@24tbus
BitDefenderThetaGen:NN.ZexaF.34738.TmKfaqazYyeH
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.bc
FireEyeGeneric.mg.314d06028e3ea30c
EmsisoftGen:Variant.Doina.15465 (B)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASCommon.FA
MicrosoftTrojan:Script/Phonzy.A!ml
GDataGen:Variant.Doina.15465
AhnLab-V3Malware/Gen.Generic.C2166372
McAfeeArtemis!314D06028E3E
MAXmalware (ai score=88)
VBA32BScope.TrojanDDoS.Macri
TrendMicro-HouseCallTROJ_GEN.R005H09FB21
RisingMalware.Heuristic!ET#94% (RDMK:cmRtazogFhv71sBg6ihMQuUfwXb6)
IkarusTrojan.Win32.Krypt
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/CoinMiner.65CA!tr
AVGWin32:Trojan-gen

How to remove Doina.15465?

Doina.15465 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment