Backdoor

Generic.Dacic.1.Backdoor.Hangup.A.1D122B25 (file analysis)

Malware Removal

The Generic.Dacic.1.Backdoor.Hangup.A.1D122B25 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Dacic.1.Backdoor.Hangup.A.1D122B25 virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Generic.Dacic.1.Backdoor.Hangup.A.1D122B25?


File Info:

name: 02C862A0881B8EACDED2.mlw
path: /opt/CAPEv2/storage/binaries/aab9d5fb667c12fb762ce485e1c567aafd857b510a4592dca5bc1357e0bcc190
crc32: DDD5937D
md5: 02c862a0881b8eacded2d05ebfd6d99a
sha1: 6941a06deefe9316656bed12b15f493a6a6cba6b
sha256: aab9d5fb667c12fb762ce485e1c567aafd857b510a4592dca5bc1357e0bcc190
sha512: a31e121bdb0e3613598b48428caee7cb777c39f1693f56a854610ef0d02b39212440bfe85bcc1ae167ac1e20e7840ab125224036850f215fc17a71d129454702
ssdeep: 6144:g9Ju8fdmUTYaT15f7o+STYaT15fOkHs+yoO:IdmUTYapJoTYapXHZtO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T181646A0BA224EEE3FA74837415E7068BE155676D02B6984D7CD8C8BCBF735B5806E270
sha3_384: 1d42b42e02600b7ccd7b0dbe5c76e3dc83aa2e1f8fe24e9e0357e17db6928aefdc75d75d8468adc6f627439d69b5a86d
ep_bytes: 90609090909090b800104000bb6c8f40
timestamp: 2018-07-09 22:06:51

Version Info:

0: [No Data]

Generic.Dacic.1.Backdoor.Hangup.A.1D122B25 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Qukart.4!c
DrWebBackDoor.HangUp.43791
MicroWorld-eScanGeneric.Dacic.1.Backdoor.Hangup.A.1D122B25
ClamAVWin.Trojan.Crypted-30
FireEyeGeneric.mg.02c862a0881b8eac
CAT-QuickHealBackdoor.Berbew.A6.MUE
McAfeeGenericRXVP-YB!02C862A0881B
MalwarebytesMalware.AI.1520611931
ZillyaTrojan.Padodor.Win32.641693
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
AlibabaBackdoor:Win32/Berbew.36d
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.0881b8
BitDefenderThetaAI:Packer.9DF4A2E821
VirITWorm.Win32.Berbew.G
CyrenW32/Padodor.F.gen!Eldorado
SymantecBackdoor.Berbew.F
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Padodor.NAX
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Proxy.Win32.Qukart.gen
BitDefenderGeneric.Dacic.1.Backdoor.Hangup.A.1D122B25
NANO-AntivirusTrojan.Win32.Qukart.fokxzm
AvastWin32:TrojanX-gen [Trj]
TencentTrojan-Ransom.Win32.Pornoasset.a
TACHYONBackdoor/W32.Padodor
SophosTroj/Padodo-Fam
F-SecureTrojan.TR/Crypt.XDR.Gen
BaiduWin32.Trojan-Spy.Quart.a
VIPREGeneric.Dacic.1.Backdoor.Hangup.A.1D122B25
TrendMicroTROJ_GEN.R002C0CDL23
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
Trapminemalicious.high.ml.score
EmsisoftGeneric.Dacic.1.Backdoor.Hangup.A.1D122B25 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.11RRK8R
JiangminTrojan.Generic.dzrgt
AviraTR/Crypt.XDR.Gen
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
ArcabitGeneric.Dacic.1.Backdoor.Hangup.A.1D122B25
ZoneAlarmTrojan-Proxy.Win32.Qukart.gen
MicrosoftBackdoor:Win32/Berbew.BU
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32BScope.Backdoor.Berbew
ALYacGeneric.Dacic.1.Backdoor.Hangup.A.1D122B25
MAXmalware (ai score=86)
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0CDL23
RisingBackdoor.Berbew!1.AE0A (CLASSIC)
YandexTrojan.PR.Qukart!niMNmBPy9Os
IkarusTrojan-Spy.Win32.Qukart
MaxSecureProxy.Qukart.gen
FortinetW32/Qukart.A!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Generic.Dacic.1.Backdoor.Hangup.A.1D122B25?

Generic.Dacic.1.Backdoor.Hangup.A.1D122B25 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment