Malware

About “Generic.Rebhip.8B8C60BB” infection

Malware Removal

The Generic.Rebhip.8B8C60BB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Rebhip.8B8C60BB virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Detects Sandboxie through the presence of a library
  • Deletes its original binary from disk
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Checks for the presence of known devices from debuggers and forensic tools
  • Creates a copy of itself
  • Creates known SpyNet mutexes and/or registry changes.
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generic.Rebhip.8B8C60BB?


File Info:

crc32: 39D27150
md5: 94902f3c09546999e30a4673d2137aaf
name: 94902F3C09546999E30A4673D2137AAF.mlw
sha1: 1be5dc72db527c08ed81b3ca53f6ff2ee2ecd9db
sha256: 20c87550f51e520247227703a0da0f88b017797c8b977b1cfec55662623bbe2d
sha512: 867d631598f0fed3e5823d3834cc65bd7966ff1a06ff79d8adedfc008c1dd075dd517a80556a632c9997b93ad7e95c27233b06b549a90302446d88bd9fdc6d0f
ssdeep: 6144:sk4qml/n9A2m/3Il2rPCqF366ARUGaeGB735oGo/Wrku:f96Ab3Il2Gp6ABfO
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Generic.Rebhip.8B8C60BB also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
ClamAVWin.Trojan.Agent-36136
CAT-QuickHealWorm.Rebhip.Z.mue
McAfeeGeneric PWS.ld
MalwarebytesTrojan.Downloader
VIPREWorm.Win32.Rebhip.A (v)
SangforMalware
K7AntiVirusTrojan ( 00193f571 )
K7GWTrojan ( 00193f571 )
Cybereasonmalicious.c09546
BaiduWin32.Trojan.Agent.co
CyrenW32/Rebhip.B.gen!Eldorado
SymantecW32.Spyrat
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Llac.lgnr
BitDefenderGeneric.Rebhip.8B8C60BB
NANO-AntivirusTrojan.Win32.Llac.crkzmz
ViRobotTrojan.Win32.Llac.297472[UPX]
MicroWorld-eScanGeneric.Rebhip.8B8C60BB
RisingWorm.Rebhip!1.A338 (CLASSIC)
Ad-AwareGeneric.Rebhip.8B8C60BB
SophosML/PE-A + W32/Rebhip-AR
ComodoTrojWare.Win32.Llac.C@1lpak6
F-SecureBackdoor:W32/Spyrat.A
DrWebBackDoor.Cybergate.1
ZillyaTrojan.Llac.Win32.3684
TrendMicroTSPY_LLAC.SML
McAfee-GW-EditionBehavesLike.Win32.PUPXDZ.dc
FireEyeGeneric.mg.94902f3c09546999
EmsisoftGeneric.Rebhip.8B8C60BB (B)
SentinelOneStatic AI – Malicious PE – Spyware
JiangminTrojan/Llac.kzj
WebrootW32.Rebhip
AviraWORM/Rebhip.V
MAXmalware (ai score=88)
Antiy-AVLTrojan/Win32.Llac.bdm
MicrosoftTrojanSpy:Win32/Rebhip
ArcabitGeneric.Rebhip.8B8C60BB
SUPERAntiSpywareTrojan.Agent/Gen-Rebhip
ZoneAlarmTrojan.Win32.Llac.lgnr
GDataGeneric.Rebhip.8B8C60BB
AhnLab-V3Trojan/Win32.Llac.R856
Acronissuspicious
VBA32Trojan.Llac
ALYacGeneric.Rebhip.8B8C60BB
TACHYONTrojan/W32.DP-Swisyn.297472
CylanceUnsafe
PandaTrj/Ransom.AB
ESET-NOD32Win32/Spatet.A
TrendMicro-HouseCallTSPY_LLAC.SML
TencentTrojan.Win32.Downloader.aat
YandexTrojan.GenAsa!1nY3u3qKVEI
IkarusTrojan.Win32.Llac
eGambitRAT.CyberGate
FortinetW32/Llac.GFU!tr
BitDefenderThetaAI:Packer.F8760CAF21
AVGWin32:Dropper-FJG [Trj]
AvastWin32:Dropper-FJG [Trj]
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360HEUR/QVM11.1.08A1.Malware.Gen

How to remove Generic.Rebhip.8B8C60BB?

Generic.Rebhip.8B8C60BB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment