Malware

Doina.16125 (file analysis)

Malware Removal

The Doina.16125 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.16125 virus can do?

  • Attempts to connect to a dead IP:Port (2 unique times)
  • Presents an Authenticode digital signature
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Queries information on disks, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Attempts to modify browser security settings
  • Creates a copy of itself
  • Attempts to create or modify system certificates
  • Anomalous binary characteristics

Related domains:

cdn-file-ssl-wan.ludashi.com
s.ludashi.com

How to determine Doina.16125?


File Info:

crc32: A674586E
md5: 3e1936560764da4e13811919dbd3a4f7
name: 3E1936560764DA4E13811919DBD3A4F7.mlw
sha1: f8928b566f1130749d2b67e9cea7c4ef479eeca6
sha256: 3061f16516474c0460c0f5148af1dc891f95b069788173bdc47698af0f1ea4a8
sha512: d3e310daa5e823045e348c43fb0d2969be498dcc1c396213689113085c16530537dabc640b8b6449ac51583d16301c96bbb5f48bc696f81b1336a473769dae30
ssdeep: 98304:y1wpL+wIIRn5P3NvdO9wgAIHM+gStdXeQzjumyCzEpqJ:Sw4O15P3NvZgAIs+lfeQuZQzJ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x5e94x7528x7a0bx5e8f
ProductVersion: 2.2021.06.09
ProductName: x4e09x7aefx4e92x901ax7cbex54c1x6e38x620f
FileVersion: 2.2021.06.09
FileDescription: x4e09x7aefx4e92x901ax7cbex54c1x6e38x620f
Translation: 0x0804 0x04b0

Doina.16125 also known as:

CynetMalicious (score: 100)
ALYacGen:Variant.Doina.16125
BitDefenderGen:Variant.Doina.16125
SymantecML.Attribute.HighConfidence
APEXMalicious
ClamAVWin.Malware.Fsysna-9760418-0
MicroWorld-eScanGen:Variant.Doina.16125
Ad-AwareGen:Variant.Doina.16125
SophosGeneric ML PUA (PUA)
McAfee-GW-EditionArtemis!Trojan
FireEyeGen:Variant.Doina.16125
EmsisoftGen:Variant.Doina.16125 (B)
WebrootW32.Malware.Gen
ArcabitTrojan.Doina.D3EFD
GDataWin32.Trojan.PSE.1K4L0HE
McAfeeArtemis!3E1936560764
MAXmalware (ai score=80)
PandaTrj/Genetic.gen
RisingAdware.Agent!1.CFEB (CLASSIC)
FortinetW32/Johnnie.3159!tr

How to remove Doina.16125?

Doina.16125 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment