Malware

About “Dropped:Generic.Dacic.304514EE.A.BA5E6990” infection

Malware Removal

The Dropped:Generic.Dacic.304514EE.A.BA5E6990 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dropped:Generic.Dacic.304514EE.A.BA5E6990 virus can do?

  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded win api malware family
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Dropped:Generic.Dacic.304514EE.A.BA5E6990?


File Info:

name: B92BFB61665CB25CC435.mlw
path: /opt/CAPEv2/storage/binaries/eb610168268886e3e7b1d18df94881b8979a9d2ca1c4a4ef741bc7d109b1db0a
crc32: FB63F7C6
md5: b92bfb61665cb25cc4357bdc1275a7ad
sha1: 56f239a873275cf04a98e91cd90d14839f5da31d
sha256: eb610168268886e3e7b1d18df94881b8979a9d2ca1c4a4ef741bc7d109b1db0a
sha512: dee57eb570b3d26c8b6ac592fc27fd310d4d83e89278c9fca2212bb06869c1618dde8de6bd10d96254fe43cf70e7253c617fccb0f0b442f5cb490429f9eb2416
ssdeep: 12288:tWsm+95nHfF2mgewFX5Qvhh9ZxEXpdNgj6UVZrOjNCRUVi:tWsz95ndbgfX52x4d2NVZrOjNCRUVi
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16FC4E115B696C232E1C202370E66CBB6992ABC351B2B65C763E0E36D6F317D1DB71306
sha3_384: d430be9bffe4654b2324ccbf8e645e881f69eebaf4fe47bb6589ed1b49833d96b47499696e9380f74085cdbe24380283
ep_bytes: e8d9650000e989feffff8bff558bec5d
timestamp: 2001-05-16 13:49:22

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft Office Word
FileVersion: 12.0.4518.1014
InternalName: WinWord
LegalCopyright: © 2006 Microsoft Corporation. All rights reserved.
LegalTrademarks1: Microsoft® is a registered trademark of Microsoft Corporation.
LegalTrademarks2: Windows® is a registered trademark of Microsoft Corporation.
OriginalFilename: WinWord.exe
ProductName: 2007 Microsoft Office system
ProductVersion: 12.0.4518.1014
Translation: 0x0000 0x04e4

Dropped:Generic.Dacic.304514EE.A.BA5E6990 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Salgorea.tpto
Elasticmalicious (high confidence)
DrWebTrojan.Siggen6.24701
MicroWorld-eScanDropped:Generic.Dacic.304514EE.A.BA5E6990
FireEyeGeneric.mg.b92bfb61665cb25c
CAT-QuickHealTrojan.GenericPMF.S31887376
SkyhighBehavesLike.Win32.Generic.hc
McAfeeGenericRXLH-OM!B92BFB61665C
Cylanceunsafe
ZillyaBackdoor.Salgorea.Win32.146
SangforTrojan.Win32.Save.a
AlibabaTrojan:Win32/Salgorea.379
K7GWTrojan ( 004e16831 )
K7AntiVirusTrojan ( 004e16831 )
BitDefenderThetaGen:NN.ZexaF.36804.IW2@aapc25hi
VirITTrojan.Win32.Salgorea.A
Paloaltogeneric.ml
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/TrojanDropper.Agent.RHG
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R002C0DD124
AvastWin32:Agent-AYZG [Cryp]
ClamAVWin.Malware.Bskd-9753126-0
KasperskyBackdoor.Win32.Salgorea.a
BitDefenderDropped:Generic.Dacic.304514EE.A.BA5E6990
NANO-AntivirusTrojan.Win32.Agent.djzunh
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
TencentBackdoor.Win32.Salgorea.hg
EmsisoftDropped:Generic.Dacic.304514EE.A.BA5E6990 (B)
GoogleDetected
F-SecureTrojan.TR/Crypt.ZPACK.Gen4
VIPREDropped:Generic.Dacic.304514EE.A.BA5E6990
TrendMicroTROJ_GEN.R002C0DD124
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
IkarusTrojan-Dropper.Win32.Agent
JiangminTrojanDropper.Agent.brds
VaristW32/Agent.IOO.gen!Eldorado
AviraTR/Crypt.ZPACK.Gen4
MAXmalware (ai score=82)
Antiy-AVLTrojan[Backdoor]/Win32.Salgorea.gen
KingsoftWin32.Hack.Salgorea.a
MicrosoftTrojan:Win32/Cerber.MPI!MTB
XcitiumTrojWare.Win32.Agent.QGO@57p1tw
ArcabitGeneric.Dacic.304514EE.A.BA5E6990
ZoneAlarmBackdoor.Win32.Salgorea.a
GDataWin32.Trojan.Salgorea.B
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.OM.C5537737
Acronissuspicious
VBA32Backdoor.Salgorea
ALYacDropped:Generic.Dacic.304514EE.A.BA5E6990
TACHYONTrojan/W32.Agent.559098.C
MalwarebytesWapomi.Virus.FileInfector.DDS
PandaTrj/Genetic.gen
RisingBackdoor.[OceanLotus]Salgorea!1.C3DC (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.12252991.susgen
FortinetW32/Agent.AYZG!tr
AVGWin32:Agent-AYZG [Cryp]
DeepInstinctMALICIOUS
alibabacloudBackdoor:Win/Salgorea.A(dyn)

How to remove Dropped:Generic.Dacic.304514EE.A.BA5E6990?

Dropped:Generic.Dacic.304514EE.A.BA5E6990 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment