Malware

Generic.Dacic.DED21A61.A.76A1585A (file analysis)

Malware Removal

The Generic.Dacic.DED21A61.A.76A1585A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Dacic.DED21A61.A.76A1585A virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Generic.Dacic.DED21A61.A.76A1585A?


File Info:

name: 62C4F8202270DB3A6DEA.mlw
path: /opt/CAPEv2/storage/binaries/00d62fd14c8961077aec82e7bca053ed479f1f45a5754641f5374cd5d6b21477
crc32: F0F80979
md5: 62c4f8202270db3a6deaf7bd34a0cd24
sha1: 2ed866ed265c9b77cd668417a84241575cbd8688
sha256: 00d62fd14c8961077aec82e7bca053ed479f1f45a5754641f5374cd5d6b21477
sha512: a643613facd1806883aec5713455a67301ed5b02c7acf270356769cf0efc9807470820ad75b5dfc6eca7fc8d5e3e44ca49d63c3d3f6151d8b6e1ce6f4b0969e6
ssdeep: 3072:Bv5Ls27BIJlElLyXuuoXXXD+XXXiIII/xXXX4vnXXXD+XXXBWI9fXXXDVXXXDjX3:BBs27cULyXloXXXD+XXXiIII/xXXXune
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D3147D6F27890771D591023D24AA338BA72E7C78531EE640ECD1F18F067A92DDB39789
sha3_384: 77655476bec84decbf84ebe736d38dcace1cd2543c3f9150e7eea4c4170796f39ea99c9cb098a3ec165093b2a321ea15
ep_bytes: 558bec6aff6870614000684039400064
timestamp: 2018-10-11 16:42:28

Version Info:

Comments:
CompanyName: Yagu Music
FileDescription: Clien RunProcess Local
FileVersion: 10.0.14393.0 (rs1_release.160715-1616)
InternalName: hello.exe
LegalCopyright: All rights reserved.
LegalTrademarks:
OriginalFilename: Yagu Music
PrivateBuild:
ProductName: Yagu Music® Operating System
ProductVersion: 17.000.14393.08
SpecialBuild:
Translation: 0x0409 0x04b0

Generic.Dacic.DED21A61.A.76A1585A also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGeneric.Dacic.DED21A61.A.76A1585A
SkyhighBehavesLike.Win32.Generic.ct
McAfeeGenericRXHB-SG!62C4F8202270
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 0054d1101 )
BitDefenderGeneric.Dacic.DED21A61.A.76A1585A
K7GWTrojan ( 0054d1101 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.36792.l83@a0RKXApj
VirITTrojan.Win32.Dnldr24.CYLH
SymantecSMG.Heur!gen
Elasticmalicious (high confidence)
ESET-NOD32Win32/ServStart.M
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Barys-10002063-0
KasperskyHEUR:Trojan-DDoS.Win32.Nitol.gen
NANO-AntivirusTrojan.Win32.GenKryptik.fnpygk
ViRobotDropper.Agent.54110
RisingBackdoor.Overie!1.C6A2 (CLASSIC)
SophosTroj/Nitol-BF
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.DownLoader24.51669
VIPREGeneric.Dacic.DED21A61.A.76A1585A
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.62c4f8202270db3a
EmsisoftGeneric.Dacic.DED21A61.A.76A1585A (B)
IkarusWorm.Win32.ServStart
JiangminTrojanDDoS.Nitol.cm
WebrootW32.Trojan.Gen
VaristW32/Agent.QSZH-5909
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.AGeneric
Kingsoftmalware.kb.a.1000
MicrosoftDDoS:Win32/Nitol!atmnm
XcitiumTrojWare.Win32.GameThief.Magania.~NWABI@1775fs
ArcabitGeneric.Dacic.DED21A61.A.76A1585A
ZoneAlarmHEUR:Trojan-DDoS.Win32.Nitol.gen
GDataWin32.Trojan.ServStart.F
GoogleDetected
AhnLab-V3Worm/Win32.Nitol.C3549303
Acronissuspicious
ALYacGeneric.Dacic.DED21A61.A.76A1585A
MAXmalware (ai score=81)
DeepInstinctMALICIOUS
VBA32BScope.Trojan.Downloader
Cylanceunsafe
PandaTrj/Genetic.gen
ZonerTrojan.Win32.82643
TencentTrojan-DDoS.Win32.Nitol.ka
SentinelOneStatic AI – Malicious PE
MaxSecureDDoS.W32.Nitol.gen
FortinetMalwThreat!E1E6IV
AVGWin32:Nitol-B [Trj]
Cybereasonmalicious.d265c9
AvastWin32:Nitol-B [Trj]

How to remove Generic.Dacic.DED21A61.A.76A1585A?

Generic.Dacic.DED21A61.A.76A1585A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment