Backdoor

Sock.Backdoor.Bot.DDS (file analysis)

Malware Removal

The Sock.Backdoor.Bot.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Sock.Backdoor.Bot.DDS virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Sock.Backdoor.Bot.DDS?


File Info:

name: 7F15ADC186C76601D684.mlw
path: /opt/CAPEv2/storage/binaries/cffc9c97b8d6a4f0d83ceb32a6548b335da55a3017c68a2dedfaa410ffceff3f
crc32: B8E6E6C4
md5: 7f15adc186c76601d684102a17cdce84
sha1: 416169a9ff259ec3983ad85536b3b2a95bfc1ef4
sha256: cffc9c97b8d6a4f0d83ceb32a6548b335da55a3017c68a2dedfaa410ffceff3f
sha512: abfc13f49e79847ce541bd8045df19f6a04e065597cedddf307177864f93856b7e8b0e0327e657658392060b0790146bd535425a3558815d9b2bcc46a083d2f8
ssdeep: 768:uYAjI/52wGAyUtxJYfYuFFkghPjYeIeeqk:9Ac/52wGAyUcYulPUeIeeqk
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13E532B5AAB46EC77C4ED05F66B64480A7FBFFE3116A85707CB00224D6CF65C7E824289
sha3_384: b118c11365c7287144ace8796e65a6915ab83c3df4749c9a0dbfab5c6edc309825e9d9095f563b7747d17bc0e7a086ce
ep_bytes: 00000000000000000000000000000000
timestamp: 2008-04-19 08:02:16

Version Info:

0: [No Data]

Sock.Backdoor.Bot.DDS also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanTrojan.GenericKDZ.70943
FireEyeGeneric.mg.7f15adc186c76601
ALYacTrojan.GenericKDZ.70943
Cylanceunsafe
VIPRETrojan.GenericKDZ.70943
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 004bcce41 )
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.186c76
BaiduWin32.Backdoor.IRCBot.a
CyrenW32/Backdoor.J.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
APEXMalicious
BitDefenderTrojan.GenericKDZ.70943
AvastWin32:Socks-AC [Wrm]
EmsisoftTrojan.GenericKDZ.70943 (B)
F-SecureWorm.WORM/Socks.ex
TrendMicroTROJ_GEN.R03BC0DEL23
McAfee-GW-EditionBehavesLike.Win32.Generic.kz
Trapminemalicious.high.ml.score
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKDZ.70943
AviraWORM/Socks.ex
Antiy-AVLTrojan[Backdoor]/Win32.Koceg
ArcabitTrojan.Generic.D1151F
MicrosoftBackdoor:Win32/Koceg.gen!A
CynetMalicious (score: 100)
McAfeeArtemis!7F15ADC186C7
MAXmalware (ai score=83)
MalwarebytesSock.Backdoor.Bot.DDS
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R03BC0DEL23
RisingWorm.Socks!1.A966 (CLASSIC)
IkarusBackdoor.Win32.Koceg
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/GenericKDZ.70943!dam
AVGWin32:Socks-AC [Wrm]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Sock.Backdoor.Bot.DDS?

Sock.Backdoor.Bot.DDS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment