Malware

Generic.DataStealer.1.201CC928 (file analysis)

Malware Removal

The Generic.DataStealer.1.201CC928 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.DataStealer.1.201CC928 virus can do?

  • Authenticode signature is invalid
  • CAPE detected the Caliber malware family
  • Binary compilation timestomping detected

How to determine Generic.DataStealer.1.201CC928?


File Info:

name: DCABC2FF696E5D09503B.mlw
path: /opt/CAPEv2/storage/binaries/39611b454f032e08e595777f14e1c9d767fadfd1dcc77ae6e99e75805f331d2d
crc32: 95D1D822
md5: dcabc2ff696e5d09503beb0f64eb2f03
sha1: 647bd3dd0e19bf783f0fbf99675a5e0c7c643078
sha256: 39611b454f032e08e595777f14e1c9d767fadfd1dcc77ae6e99e75805f331d2d
sha512: a4465fd8f6c296699d6c23ebccae483d39a3291e43888a77a2c961997637c41078ac4c418f35cd1132159bd1a3c7b5b61668bc439149f3b1b90f9e312093981a
ssdeep: 6144:Z1oaT6MDdbICydeBij3yCUGh9Phbvur8mI1D0zC/:Z1FEyCUG7PSq1Dn/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15D64380427E88A15F5BE4BBED0B151548372B466B93FDB8F1E8060EE2D72350CE49B67
sha3_384: 32ea830e6ee24a0a29fa19eb36799708d71e57800dedce84724318d768e2d72c3e8c288eb022118e69f8a556f9a01b8a
ep_bytes: ff250020400010111200080709060a05
timestamp: 2068-04-20 12:24:18

Version Info:

Translation: 0x0000 0x04b0
Comments: 44 CALIBER
CompanyName: 44 CALIBER
FileDescription: 44 CALIBER
FileVersion: 1.6.2.0
InternalName: Insidious.exe
LegalCopyright: FuckTheSystem Copyright © 2021
LegalTrademarks:
OriginalFilename: Insidious.exe
ProductName: 44 CALIBER
ProductVersion: 1.6.2.0
Assembly Version: 1.6.2.0

Generic.DataStealer.1.201CC928 also known as:

LionicTrojan.Win32.Stealer.12!c
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.DataStealer.1.201CC928
FireEyeGeneric.mg.dcabc2ff696e5d09
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
ALYacGeneric.DataStealer.1.201CC928
MalwarebytesCoinStealer.Spyware.Stealer.DDS
ZillyaTrojan.CoinStealer.Win32.3839
SangforTrojan.Win32.Save.a
K7AntiVirusPassword-Stealer ( 005282e41 )
AlibabaTrojanPSW:MSIL/Stealgen.bfa40e38
K7GWPassword-Stealer ( 005282e41 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitGeneric.DataStealer.1.201CC928
BitDefenderThetaGen:NN.ZemsilF.36722.sm0@aWvIqio
VirITTrojan.Win32.GenusT.DJGV
CyrenW32/CoinMiner.FA.gen!Eldorado
SymantecInfostealer.Calibous
ESET-NOD32a variant of MSIL/PSW.CoinStealer.CC
APEXMalicious
ClamAVWin.Packed.Datastealer-9856291-0
KasperskyHEUR:Trojan-PSW.MSIL.Stealer.gen
BitDefenderGeneric.DataStealer.1.201CC928
NANO-AntivirusTrojan.Win32.Stealer.jxgesj
SUPERAntiSpywareTrojan.Agent/Gen-DataStealer
AvastWin32:MalwareX-gen [Trj]
RisingStealer.Agent!1.D483 (CLASSIC)
EmsisoftTrojan-PSW.Agent (A)
F-SecureHeuristic.HEUR/AGEN.1307083
DrWebTrojan.PWS.StealerNET.76
VIPREGeneric.DataStealer.1.201CC928
TrendMicroTROJ_GEN.R014C0DFR23
McAfee-GW-EditionGenericRXSG-XG!DCABC2FF696E
SophosTroj/Steal-CJF
IkarusTrojan.MSIL.PSW
GoogleDetected
AviraHEUR/AGEN.1307083
MAXmalware (ai score=88)
Antiy-AVLTrojan[PSW]/MSIL.CoinStealer
MicrosoftPWS:MSIL/Stealgen.GA!MTB
ZoneAlarmHEUR:Trojan-PSW.MSIL.Stealer.gen
GDataMSIL.Trojan-Stealer.CaliberStealer.B
CynetMalicious (score: 100)
AhnLab-V3Infostealer/Win.CALIBER.R513735
McAfeeGenericRXSG-XG!DCABC2FF696E
VBA32Trojan.MSIL.InfoStealer.gen.D
Cylanceunsafe
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R014C0DFR23
TencentTrojan-Spy.Win32.Stealer.16000599
YandexTrojan.PWS.CoinStealer!nKjQbL/JAZc
SentinelOneStatic AI – Malicious PE
FortinetMSIL/Agent.RML!tr
AVGWin32:MalwareX-gen [Trj]
Cybereasonmalicious.d0e19b
DeepInstinctMALICIOUS

How to remove Generic.DataStealer.1.201CC928?

Generic.DataStealer.1.201CC928 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment