Backdoor

Generic.Dacic.1.Backdoor.Hangup.A.4EB80C72 (file analysis)

Malware Removal

The Generic.Dacic.1.Backdoor.Hangup.A.4EB80C72 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Dacic.1.Backdoor.Hangup.A.4EB80C72 virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Generic.Dacic.1.Backdoor.Hangup.A.4EB80C72?


File Info:

name: 2E7114230290EF7919E9.mlw
path: /opt/CAPEv2/storage/binaries/196f31d67825dcc513ecd3e74d8ba2c5f3d8af2b7eb57dfc704296dccfe896ad
crc32: F220A8D8
md5: 2e7114230290ef7919e9a9212e302cb3
sha1: d29f6269d62e318c07c2367d74ed2c05da5a1f22
sha256: 196f31d67825dcc513ecd3e74d8ba2c5f3d8af2b7eb57dfc704296dccfe896ad
sha512: d8cd425776d9ddbb2960f02a4d9aabc863f0c17ed0df375ee0ba23a2da9bd9212f4da20840df3a341d321589d13ff49e19a9e10d3eb4785028106e979d8ca2c8
ssdeep: 1536:FI/W7Ewa0JJz9KPG5yI6HZ5OrN5xzJ3VXQUzRPvVtJ1vO9MgAPgnDNBrcN4i6tBH:YW7ESd9VFJ8MgAPgxed6BYudlNPMAZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T151A35CFB22152FB3C2750371915B29DFF7E990BA527A85806498C35C13B7E18C3B6AD2
sha3_384: f6746053729a3cdf526cd979e0eb4a91a1dc2af45a6d85f344ee497430f9c1a1bdfa2cc8b998c37c37e92a62fda124ef
ep_bytes: 90909090609090b80010400090bb6c8f
timestamp: 2018-07-09 22:06:51

Version Info:

0: [No Data]

Generic.Dacic.1.Backdoor.Hangup.A.4EB80C72 also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGeneric.Dacic.1.Backdoor.Hangup.A.4EB80C72
FireEyeGeneric.mg.2e7114230290ef79
CAT-QuickHealBackdoor.Berbew.A6.MUE
ALYacGeneric.Dacic.1.Backdoor.Hangup.A.4EB80C72
MalwarebytesCrypt.Trojan.Malicious.DDS
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.30290e
BitDefenderThetaAI:Packer.296DA1BE21
SymantecBackdoor.Berbew.F
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Padodor.NAX
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGeneric.Dacic.1.Backdoor.Hangup.A.4EB80C72
NANO-AntivirusTrojan.Win32.Qukart.fokxzm
F-SecureTrojan.TR/Crypt.XDR.Gen
VIPREGeneric.Dacic.1.Backdoor.Hangup.A.4EB80C72
Trapminemalicious.high.ml.score
SophosTroj/Padodo-Fam
IkarusTrojan-Spy.Win32.Qukart
JiangminTrojan.Generic.dzrgt
AviraTR/Crypt.XDR.Gen
MAXmalware (ai score=84)
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
ArcabitGeneric.Dacic.1.Backdoor.Hangup.A.4EB80C72
ZoneAlarmTrojan-Proxy.Win32.Qukart.gen
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
VBA32BScope.Backdoor.Berbew
TACHYONBackdoor/W32.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
TencentTrojan-Ransom.Win32.Pornoasset.a
SentinelOneStatic AI – Malicious PE
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Generic.Dacic.1.Backdoor.Hangup.A.4EB80C72?

Generic.Dacic.1.Backdoor.Hangup.A.4EB80C72 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment