Malware

What is “Dropper.214”?

Malware Removal

The Dropper.214 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dropper.214 virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Dropper.214?


File Info:

name: 37A4BBAC4C651F615745.mlw
path: /opt/CAPEv2/storage/binaries/0e594bf5f4a2ab716518b624b8581ea2f0e8b23e42158dcb96491fa7d1912da5
crc32: FB714F7B
md5: 37a4bbac4c651f615745e2c2513ce9f9
sha1: e904b40a014f4a4ee40a90a3fc01a9aaf1b4a473
sha256: 0e594bf5f4a2ab716518b624b8581ea2f0e8b23e42158dcb96491fa7d1912da5
sha512: 197a84f5e77620d22a2f70832dc070e2889c8c3117d3238dec5152d1f8e942ea614fbf893cce98448055d6fa3447b308f8f08eb1443b17ed4a824e42362018ed
ssdeep: 98304:up2sB9bORCzpLttINYtsJzjRojldMxWzctHHFLOAkGkzdnEVomFHKnP:2HhqSldMxWzctHHFLOyomFHKnP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EF06C0217E9D807AC46312314EEE7379A16FBDF02A35026731993A2E7B713C25A3D653
sha3_384: c63fb915db1f8e6ec1ec145bac6de229e00dbfd9aed29be52b478933b85148bd24c96659941506550e6cc9b3e400871a
ep_bytes: e8c8980000e97ffeffff3b0d30d46000
timestamp: 2019-05-07 08:48:08

Version Info:

0: [No Data]

Dropper.214 also known as:

LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanGen:Variant.Dropper.214
FireEyeGen:Variant.Dropper.214
SkyhighBehavesLike.Win32.BadFile.wc
McAfeeArtemis!37A4BBAC4C65
BitDefenderThetaGen:NN.ZexaF.36792.HxW@a0h0L7gi
APEXMalicious
BitDefenderGen:Variant.Dropper.214
EmsisoftGen:Variant.Dropper.214 (B)
VIPREGen:Variant.Dropper.214
MAXmalware (ai score=83)
ArcabitTrojan.Dropper.214
GDataGen:Variant.Dropper.214
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H09IU23
MaxSecureTrojan.Malware.201299402.susgen
DeepInstinctMALICIOUS

How to remove Dropper.214?

Dropper.214 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment