Crack

HackTool.Win32.Sivuha.ciq removal guide

Malware Removal

The HackTool.Win32.Sivuha.ciq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware - Review 2020

GridinSoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend to use GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the TRIAL period.
6-day free trial available.

What HackTool.Win32.Sivuha.ciq virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • NtSetInformationThread: attempt to hide thread from debugger
  • Dynamic (imported) function loading detected
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Executable file is packed/obfuscated with ASPack
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Checks for the presence of known windows from debuggers and forensic tools
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • The following process appear to have been packed with Themida: 4FE5CD712B4531A16657.mlw
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects the presence of Wine emulator via registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Anomalous binary characteristics

How to determine HackTool.Win32.Sivuha.ciq?


File Info:

name: 4FE5CD712B4531A16657.mlw
path: /opt/CAPEv2/storage/binaries/1ade1edf3123c8474257441ead6aba832dd62b0d93cccc49ec41b3d9f2a55f68
crc32: 777ED06E
md5: 4fe5cd712b4531a16657f38bc176e2af
sha1: 503cdd8c5bf630529843fd295f6366a8facf775f
sha256: 1ade1edf3123c8474257441ead6aba832dd62b0d93cccc49ec41b3d9f2a55f68
sha512: aa03383837b506b7401bd309ac53414fcf7aa58582039dab43a757314f4146da30831e7d878121bfc48e18c1b90d8a43e91a986b3630a22c4a8d4da0225cbde1
ssdeep: 196608:Ra6CPLvOhuUlwSMUW0rINolDeuFyFV17b5l:RrCPTOhuUlbMUWOIN4Qn7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D56633C9B130DC98FDC0243B7A96D51E4716AF26C029D4CC18CEA9E7B076DF4729B6A4
sha3_384: dd1d8df9766422a69cf8d933d90640da8a83c0a42c5591faf6d195e271c9ab3f670b89476344e9c60491353fa8cb1b32
ep_bytes: 60e803000000e9eb045d4555c3e80100
timestamp: 2022-02-08 16:49:12

Version Info:

0: [No Data]

HackTool.Win32.Sivuha.ciq also known as:

LionicHacktool.Win32.Sivuha.3!c
tehtrisGeneric.Malware
FireEyeGeneric.mg.4fe5cd712b4531a1
CylanceUnsafe
SangforHacktool.Win32.Sivuha.ciq
K7AntiVirusRiskware ( 0040eff71 )
AlibabaHackTool:Win32/Sivuha.8e7aba85
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.c5bf63
CyrenW32/RLPacked.B.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
APEXMalicious
AvastWin32:Malware-gen
KasperskyHackTool.Win32.Sivuha.ciq
RisingTrojan.Tonmye!8.510 (CLOUD)
SophosGeneric PUA FA (PUA)
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
Paloaltogeneric.ml
GDataWin32.Application.PUPStudio.A
JiangminHackTool.Sivuha.xf
KingsoftWin32.HackTool.Sivuha.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
McAfeeArtemis!4FE5CD712B45
VBA32BScope.Trojan.Fuerboos
TrendMicro-HouseCallTROJ_GEN.R002H07C922
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.Sality.AA
FortinetMalicious_Behavior.SB
BitDefenderThetaGen:NN.ZexaE.34638.@l0bauVwNrhb
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_90% (D)

How to remove HackTool.Win32.Sivuha.ciq?

HackTool.Win32.Sivuha.ciq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment