Worm

Phorpiex.Worm.Downloader.DDS (file analysis)

Malware Removal

The Phorpiex.Worm.Downloader.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Phorpiex.Worm.Downloader.DDS virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • A process created a hidden window
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Queries information on disks, possibly for anti-virtualization
  • Attempts to remove evidence of file being downloaded from the Internet
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Operates on local firewall’s policies and settings
  • Creates a copy of itself
  • Attempts to disable Windows Defender
  • Connects to an IRC server, possibly part of a botnet

Related domains:

rohgoruhgsorhugih.ru

How to determine Phorpiex.Worm.Downloader.DDS?


File Info:

crc32: C3AF4F3E
md5: ac97717bb003a98b757138f050a20a45
name: AC97717BB003A98B757138F050A20A45.mlw
sha1: 13fb826abc07f1f7d4189b020d3493498620c313
sha256: f7953b8cd1347d271fc42b605bdda22beece3e02c98930a6d36fb8b235e2d65d
sha512: 93c96059ea8c089bc71fcebc932e867372f452a6a03655f1ba135c6b905799de54c16d037941092d5c6205cdcc0c58dd86cedf81435c7b81624dcdc7a2089ba2
ssdeep: 1536:PCUBSz6rMnsDVX3ItptptptptgtptX3ItptptptptgtptptmtgtptptptptptptC:PNS+7DVXT9qR+0
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Phorpiex.Worm.Downloader.DDS also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanDropped:Generic.Malware.SYBd.432DE27A
FireEyeGeneric.mg.ac97717bb003a98b
CAT-QuickHealTrojan.FuerboosPMF.S17834671
McAfeeGenericRXNI-ON!AC97717BB003
CylanceUnsafe
VIPREBehavesLike.Win32.Malware.eah (mx-v)
AegisLabTrojan.Script.Generic.4!c
SangforMalware
K7AntiVirusTrojan ( 004e13371 )
BitDefenderDropped:Generic.Malware.SYBd.432DE27A
K7GWTrojan ( 004e13371 )
Cybereasonmalicious.bb003a
CyrenW32/IRCBot-based6_DET!Eldorado
APEXMalicious
AvastWin32:Crypt-PQQ [Trj]
ClamAVWin.Malware.Sybddld-6753293-0
AlibabaWorm:Win32/Phorpiex.60814269
NANO-AntivirusTrojan.Win32.Autoruner2.fghchh
ViRobotTrojan.Win32.Z.Phorpiex.100392.A
RisingWorm.Phorpiex!1.BCEC (CLASSIC)
Ad-AwareDropped:Generic.Malware.SYBd.432DE27A
EmsisoftDropped:Generic.Malware.SYBd.432DE27A (B)
ComodoTrojWare.Win32.Phorpiex.CT@803ooe
F-SecureTrojan.TR/Downloader.Gen
DrWebWin32.HLLW.Autoruner2.39914
ZillyaWorm.Phorpiex.Win32.472
SophosMal/Generic-R + W32/Phorpiex-AF
SentinelOneStatic AI – Malicious PE
JiangminWorm.Generic.eiz
AviraTR/Downloader.Gen
MAXmalware (ai score=100)
Antiy-AVLWorm/Win32.Phorpiex.c
ArcabitGeneric.Malware.SYBd.432DE27A
ZoneAlarmHEUR:Trojan.Script.Generic
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.IRCBot.R246976
Acronissuspicious
VBA32BScope.Trojan.IRCbot
ALYacDropped:Generic.Malware.SYBd.432DE27A
MalwarebytesPhorpiex.Worm.Downloader.DDS
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Phorpiex.C
TrendMicro-HouseCallMal_DLDER
TencentMalware.Win32.Gencirc.10b07829
YandexTrojan.Agent!vJHZ6FEsjQQ
IkarusWorm.Win32.Phorpiex
FortinetW32/Phorpiex.F!worm
AVGWin32:Crypt-PQQ [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.Script.ed4

How to remove Phorpiex.Worm.Downloader.DDS?

Phorpiex.Worm.Downloader.DDS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment