Malware

Sobrab.8 malicious file

Malware Removal

The Sobrab.8 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Sobrab.8 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Creates known Njrat/Bladabindi RAT registry keys

How to determine Sobrab.8?


File Info:

name: 5402088123CB502CF8D9.mlw
path: /opt/CAPEv2/storage/binaries/c2665135f5b23e4e2ee38af9e514bd20f775f9cc94f15e3e2b3e20b7d535dd9b
crc32: B1124136
md5: 5402088123cb502cf8d9775949246679
sha1: 0165903934e5b792fee5f9a99b082dc2697b3037
sha256: c2665135f5b23e4e2ee38af9e514bd20f775f9cc94f15e3e2b3e20b7d535dd9b
sha512: b8ba7c015ae0564aca8a240e83c241cf460d719799e9c1acc23f2f1f23a6f8d91e2faf51c390d57057c4221ef9cef082bf566d91bacd6064417d64c96e00b482
ssdeep: 6144:jsTrfM66wXgscGff+Dbn5KUfhsM1QDnWK5LnYO2u/myo3I1kjBFOUj91tz0/MSxe:jsTrfM66wXgscGff+Dbn5KUfwl7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T158340859B3409A26C46D763FC3EB24941375A2CB4762D20B6F9963EC2D273E36C1F249
sha3_384: de5b8f5a5a848449dcb7bac530288ed3a8695305645aff9f4e7914a71152d8d45a0d3e5631dd3b8f37cbd89780a59d9e
ep_bytes: ff250020400000000000000000000000
timestamp: 2015-06-23 01:37:50

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: Server.exe
LegalCopyright:
OriginalFilename: Server.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Sobrab.8 also known as:

LionicTrojan.Win32.Generic.mzP4
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Sobrab.8
FireEyeGeneric.mg.5402088123cb502c
ALYacGen:Variant.Sobrab.8
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
AlibabaPacked:MSIL/CodeWall.e606be80
K7GWTrojan ( 700000121 )
Cybereasonmalicious.123cb5
BitDefenderThetaGen:NN.ZemsilF.34182.om2@aK43IFk
VirITTrojan.Win32.DownLoader14.IRO
CyrenW32/Trojan.FDV.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Packed.CodeWall.B suspicious
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Zapchast-6887881-0
KasperskyHEUR:Trojan-Ransom.Win32.Agent.gen
BitDefenderGen:Variant.Sobrab.8
AvastMSIL:GenMalicious-APD [Trj]
TencentMalware.Win32.Gencirc.114c99e4
EmsisoftGen:Variant.Sobrab.8 (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.DownLoader14.5864
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
SophosMal/Generic-S
IkarusPUA.MSIL.CodeWall
AviraTR/Dropper.Gen
MAXmalware (ai score=86)
Antiy-AVLTrojan/Win32.AGeneric
MicrosoftBackdoor:Win32/Bladabindi!ml
ZoneAlarmHEUR:Trojan-Ransom.Win32.Agent.gen
GDataMSIL.Backdoor.Bladabindi.WVGYDX
CynetMalicious (score: 99)
AhnLab-V3Malware/Win32.RL_Generic.C4085287
McAfeeArtemis!5402088123CB
MalwarebytesTrojan.Agent
TrendMicro-HouseCallTROJ_GEN.R002H0CB322
RisingMalware.Obfus/MSIL@AI.91 (RDM.MSIL:8qnoqhaeAvgenw+Q0c83nA)
YandexTrojan.Agent!5DMVktLIgNU
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/Application
AVGMSIL:GenMalicious-APD [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Sobrab.8?

Sobrab.8 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment