Trojan

Trojan.Generic.5238568 (file analysis)

Malware Removal

The Trojan.Generic.5238568 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.5238568 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Possible date expiration check, exits too soon after checking local time
  • Anomalous file deletion behavior detected (10+)
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs HTTP requests potentially not found in PCAP.
  • Enumerates running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Code injection with CreateRemoteThread in a remote process
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Injection with CreateRemoteThread in a remote process
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Steals private information from local Internet browsers
  • Collects and encrypts information about the computer likely to send to C2 server
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Attempts to modify browser security settings
  • Harvests credentials from local FTP client softwares
  • Collects information to fingerprint the system
  • Clears web history

How to determine Trojan.Generic.5238568?


File Info:

name: ED8418AF4CFB3225761D.mlw
path: /opt/CAPEv2/storage/binaries/1c0b99f2404ddba295be1d8f9e5a4a35d15f7341cb6899d5e1f5c080deec4da8
crc32: D2FEF340
md5: ed8418af4cfb3225761ddff589a04d38
sha1: 4f8c704e31fd55165e31d977ec88b940d401d338
sha256: 1c0b99f2404ddba295be1d8f9e5a4a35d15f7341cb6899d5e1f5c080deec4da8
sha512: 31e999e98102aba43065d93a47f3c577963e04b20bdea1bf531c349b0157e758e4b63d2e7e549c3164e564a07a17941169f17689d4586bd67f95b1d2479f5778
ssdeep: 3072:xjL6X+uTIzOyBi4Mm9uDrd1XehnQbnnALHhjFHLC2N5WHj:xSXd6Bi4Mm0DrrOMnWFHLC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A4E312A886CEE8EEF84AFD3546477D058CDFE042BB1BA09C96D5567E4C6FED4C020059
sha3_384: d24768cda7a32a29770831a6b699f1542c16638a75dc2799c48b983252129342a709e1c906c0854da96e16e0721195f8
ep_bytes: 60be008042008dbe0090fdff57eb0b90
timestamp: 2007-02-27 20:08:46

Version Info:

0: [No Data]

Trojan.Generic.5238568 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Zbot.lijp
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.ed8418af4cfb3225
McAfeeArtemis!ED8418AF4CFB
CylanceUnsafe
VIPREVirTool.Win32.Obfuscator.da!j (v)
SangforTrojan.Win32.Zbot.blfv
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanSpy:Win32/Kryptik.7bd849b0
K7GWRiskware ( 0015e4f01 )
K7AntiVirusRiskware ( 0015e4f01 )
BitDefenderThetaAI:Packer.68EA927C1F
VirITTrojan.Win32.Panda.GAB
CyrenW32/Risk.EFIV-2260
SymantecTrojan.Zbot!gen14
ESET-NOD32a variant of Win32/Kryptik.IRX
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Zbot-51086
KasperskyTrojan-Spy.Win32.Zbot.blfv
BitDefenderTrojan.Generic.5238568
NANO-AntivirusTrojan.Win32.Zbot.ikgbo
MicroWorld-eScanTrojan.Generic.5238568
AvastWin32:Evo-gen [Susp]
TencentWin32.Trojan-spy.Zbot.Anfo
Ad-AwareTrojan.Generic.5238568
SophosMal/Generic-R + Mal/Agent-IE
ComodoTrojWare.Win32.TrojanSpy.Zbot.G@2tckk5
DrWebTrojan.PWS.Panda.4057
ZillyaTrojan.FakeAV.Win32.36879
TrendMicroTROJ_SPYEYE.SMEP
McAfee-GW-EditionBehavesLike.Win32.Spyeye.cc
EmsisoftTrojan.Generic.5238568 (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.Generic.5238568
JiangminTrojan/Generic.cdsa
WebrootW32.Malware.Gen
AviraTR/Crypt.ULPM.Gen
MAXmalware (ai score=99)
Antiy-AVLTrojan[Spy]/Win32.Zbot
ArcabitTrojan.Generic.D4FEF28
ZoneAlarmTrojan-Spy.Win32.Zbot.blfv
MicrosoftPWS:Win32/Zbot!ZA
Acronissuspicious
VBA32Trojan.Zeus.EA.0999
ALYacTrojan.Generic.5238568
TrendMicro-HouseCallTROJ_SPYEYE.SMEP
RisingSpyware.Zbot!8.16B (CLOUD)
YandexTrojan.GenAsa!EWy2MbrxvQg
IkarusTrojan-Spy.Win32.Zbot
AVGWin32:Evo-gen [Susp]
Cybereasonmalicious.f4cfb3
PandaGeneric Malware

How to remove Trojan.Generic.5238568?

Trojan.Generic.5238568 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment