Malware

Doina.9452 (file analysis)

Malware Removal

The Doina.9452 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Doina.9452 virus can do?

  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

wpad.local-net
s3.us-east-2.amazonaws.com

How to determine Doina.9452?


File Info:

name: 2074AB7EF64028C55F65.mlw
path: /opt/CAPEv2/storage/binaries/cc6cee5ceec576418e1f6f699ed30ad9a2a73a0a91457ac83faad622b1f8274d
crc32: D95FAAAE
md5: 2074ab7ef64028c55f657e4320064755
sha1: 87aeb6c3e6d6b67aeb36f4f87fae2ed9ba5d6bf3
sha256: cc6cee5ceec576418e1f6f699ed30ad9a2a73a0a91457ac83faad622b1f8274d
sha512: 5d35cb2cf6eca08fd993d03bfa3c3620771ab49a8ccfbfb872b7386b7b300f4cfe474100a91a6fa93899c31931a5da072929edccdd60d85ce8864be2bf7e4638
ssdeep: 12288:CoosZWekyiW5A3/fhqRQ2Xt1Oy9Ks+TYujnvmMs/TUqnj7UP9:bDyyiW5A3/f+Qs7is+Pnvmh/TU+/q9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19B057D23F5A05437D1333BB98C5B57656C36BE106E38784A2BE83D4C5F3A6827D2528B
sha3_384: 5f1f27f6568f93d5d495f43a64e80affab31a5b8d9921cb0bc09d9db9a595edba35adfd0927842cc753c8d5f14097812
ep_bytes: 558bec83c4f053b81c5e4900e81304f7
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Doina.9452 also known as:

LionicTrojan.Win32.Banload.a!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Doina.9452
FireEyeGeneric.mg.2074ab7ef64028c5
McAfeeArtemis!2074AB7EF640
CylanceUnsafe
ZillyaDownloader.Banload.Win32.82859
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 00512ad51 )
AlibabaTrojanDownloader:Win32/Banload.f5c71a7a
K7GWTrojan-Downloader ( 00512ad51 )
Cybereasonmalicious.ef6402
BitDefenderThetaAI:Packer.EB7CDD9A21
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDownloader.Banload.YAP
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Downloader.Win32.Banload.aashv
BitDefenderGen:Variant.Doina.9452
NANO-AntivirusTrojan.Win32.Banload.esjetr
AvastWin32:Malware-gen
TencentWin32.Trojan-downloader.Banload.Hooi
Ad-AwareGen:Variant.Doina.9452
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.ch
EmsisoftGen:Variant.Doina.9452 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Doina.9452
JiangminTrojanDownloader.Banload.bnbg
eGambitUnsafe.AI_Score_100%
AviraTR/Dldr.Delphi.Gen7
Antiy-AVLTrojan/Generic.ASMalwS.21A0C1F
MicrosoftTrojan:Win32/Skeeyah.A!bit
CynetMalicious (score: 100)
AhnLab-V3Downloader/Win32.Banload.C2116028
VBA32BScope.Trojan.Agent
ALYacGen:Variant.Doina.9452
MAXmalware (ai score=100)
RisingTrojan.Generic@ML.100 (RDML:XiWTHcrKhYEDZmY9bpoYlQ)
YandexTrojan.GenAsa!oU/E5xoho3U
IkarusTrojan-Downloader.Win32.Banload
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Banload.YAV!tr.dldr
AVGWin32:Malware-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Doina.9452?

Doina.9452 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment