Backdoor

Generic.Dacic.1.Backdoor.Hangup.A.FB69C95A (file analysis)

Malware Removal

The Generic.Dacic.1.Backdoor.Hangup.A.FB69C95A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Dacic.1.Backdoor.Hangup.A.FB69C95A virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Generic.Dacic.1.Backdoor.Hangup.A.FB69C95A?


File Info:

name: C89F9B5F7B18BA944351.mlw
path: /opt/CAPEv2/storage/binaries/f08e7dff839ad974f873cf35eb67f9ac9b117e965dd0aa434d0b276e648d88e5
crc32: FA12E849
md5: c89f9b5f7b18ba94435192a7661b0cb3
sha1: 2df6f1a73d8b94656f40c5022803088320ba1ee8
sha256: f08e7dff839ad974f873cf35eb67f9ac9b117e965dd0aa434d0b276e648d88e5
sha512: d10e77336e275ff128fafe136dcbc4d2a5d8bbd6d7c63fbefdfd5b5608f6728842c7cb158f276cab9c413d374e76e4a8c76879f6fa8d37046936f696bfd5528e
ssdeep: 1536:i7rsVi93jKAdD/0qMTV45YMkhohBE8VGh:iyPAN01TVEUAEQGh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T123834917725737B7CAC2027132CF85EABE3F6576936386B30045E11C129B967623A7E8
sha3_384: f463b790c02295ea290a5c500af99dd4a98d0abfc05771f209db14a03a9558dbe5b3e4c3445ccc06a84a99d61917984d
ep_bytes: 90609090909090b80010400090bbd08e
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Generic.Dacic.1.Backdoor.Hangup.A.FB69C95A also known as:

tehtrisGeneric.Malware
MicroWorld-eScanGeneric.Dacic.1.Backdoor.Hangup.A.FB69C95A
FireEyeGeneric.mg.c89f9b5f7b18ba94
CAT-QuickHealBackdoor.Berbew.A6.MUE
SkyhighBehavesLike.Win32.Generic.mh
ALYacGeneric.Dacic.1.Backdoor.Hangup.A.FB69C95A
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
BitDefenderGeneric.Dacic.1.Backdoor.Hangup.A.FB69C95A
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.73d8b9
BitDefenderThetaAI:Packer.61E432B221
VirITWorm.Win32.Berbew.G
SymantecBackdoor.Berbew.F
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Spy.Qukart
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Proxy.Win32.Qukart.gen
NANO-AntivirusTrojan.Win32.Qukart.fokxzm
TencentTrojan-Ransom.Win32.Pornoasset.a
TACHYONBackdoor/W32.Padodor
SophosTroj/Padodo-Gen
BaiduWin32.Trojan-Spy.Quart.a
F-SecureTrojan.TR/Crypt.ZPACK.Gen2
DrWebTrojan.Siggen13.42746
VIPREGeneric.Dacic.1.Backdoor.Hangup.A.FB69C95A
TrendMicroTROJ_GEN.R03BC0CJV23
Trapminemalicious.high.ml.score
EmsisoftGeneric.Dacic.1.Backdoor.Hangup.A.FB69C95A (B)
IkarusTrojan-Spy.Win32.Qukart
JiangminTrojan.Generic.dzrgt
VaristW32/S-705d01a1!Eldorado
AviraTR/Crypt.ZPACK.Gen2
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftBackdoor:Win32/Berbew
ArcabitGeneric.Dacic.1.Backdoor.Hangup.A.FB69C95A
ZoneAlarmTrojan-Proxy.Win32.Qukart.gen
GDataWin32.Trojan.PSE.1VR6SI3
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
McAfeeTrojan-FVOJ!C89F9B5F7B18
MAXmalware (ai score=88)
DeepInstinctMALICIOUS
VBA32BScope.Backdoor.Berbew
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03BC0CJV23
RisingBackdoor.Berbew!1.AE0A (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Qukart.A!tr
AVGWin32:TrojanX-gen [Trj]
AvastWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Generic.Dacic.1.Backdoor.Hangup.A.FB69C95A?

Generic.Dacic.1.Backdoor.Hangup.A.FB69C95A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment