Trojan

Trojan.SabsikPMF.S24637975 removal tips

Malware Removal

The Trojan.SabsikPMF.S24637975 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.SabsikPMF.S24637975 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Latvian
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Enumerates services, possibly for anti-virtualization
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • CAPE detected the Tofsee malware family
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.SabsikPMF.S24637975?


File Info:

name: D2869F77632D612F8869.mlw
path: /opt/CAPEv2/storage/binaries/394959854ca6029feb2390f0f4853a62cf891b6328217c784b63c4d41673ae8f
crc32: 6F393283
md5: d2869f77632d612f8869613cdcc81461
sha1: b163efe4f33c9cf92bb4d9b868925c900f9504c7
sha256: 394959854ca6029feb2390f0f4853a62cf891b6328217c784b63c4d41673ae8f
sha512: 747c3d7f039f8aeef8394fb9380fc7606fc052d47c04be808a85aba12e2576a0f213ff40c04235f7d0b17eee3ecfab1a0abcc4a4c8a548ae51ee935090fbba36
ssdeep: 24576:Uw/bjWjWjWjWjWjWjWjWjWjWjWjWjWjWjWjWjWjWjWjWjWjWjWjWjWjWjWjWjWj/:b/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E7F66B71A6EC9D15D6A34E30853196E81537FCD26B20A19AE250BBCF2C31F5D46E232F
sha3_384: b3a4bfe53f4701565c2645efb4cd652bb49fa22efeff7a866dde29192d749ddb1c79a343822d3441314fb80269ab8791
ep_bytes: e854420000e989feffff6a0868700042
timestamp: 2020-11-12 06:01:45

Version Info:

InternalName: bomgpiaruci.iwa
Copyright: Copyrighz (C) 2021, fudkagat
ProductVersion: 15.54.12.11
Translation: 0x0014 0x046a

Trojan.SabsikPMF.S24637975 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Siggen15.36515
MicroWorld-eScanTrojan.GenericKDZ.80247
FireEyeGeneric.mg.d2869f77632d612f
CAT-QuickHealTrojan.SabsikPMF.S24637975
McAfeeLockbit-FSWW!D2869F77632D
MalwarebytesTrojan.MalPack.GS
K7AntiVirusTrojan ( 0058a0e91 )
AlibabaRansom:Win32/StopCrypt.982d32ca
K7GWTrojan ( 0058a0e91 )
Cybereasonmalicious.4f33c9
ArcabitTrojan.Generic.D13977
BitDefenderThetaGen:NN.ZexaF.34062.@t0@aK6OnxhI
CyrenW32/Kryptik.FOQ.gen!Eldorado
SymantecPacked.Generic.528
ESET-NOD32a variant of Win32/Kryptik.HNFO
TrendMicro-HouseCallMal_Tofsee
ClamAVWin.Trojan.Generic-9906674-0
KasperskyHEUR:Backdoor.Win32.Tofsee.gen
BitDefenderTrojan.GenericKDZ.80247
AvastWin32:MalwareX-gen [Trj]
Ad-AwareTrojan.GenericKDZ.80247
SophosML/PE-A + Troj/Krypt-BO
ZillyaTrojan.Kryptik.Win32.3629346
TrendMicroMal_Tofsee
McAfee-GW-EditionBehavesLike.Win32.Generic.vh
EmsisoftTrojan.Crypt (A)
IkarusTrojan-Ransom.StopCrypt
JiangminBackdoor.Tofsee.fdo
AviraHEUR/AGEN.1136028
Antiy-AVLTrojan/Generic.ASMalwS.34CBFA5
MicrosoftRansom:Win32/StopCrypt.PS!MTB
GDataTrojan.GenericKDZ.80247
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.OC.R449108
Acronissuspicious
VBA32Malware-Cryptor.2LA.gen
ALYacTrojan.GenericKDZ.80247
MAXmalware (ai score=83)
APEXMalicious
RisingTrojan.Generic@ML.92 (RDML:Ohytj/5QCb2Oj970I0/Wew)
YandexTrojan.Kryptik!sj4Qhx5PYgo
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.FQN!tr
AVGWin32:MalwareX-gen [Trj]
PandaTrj/GdSda.A
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan.SabsikPMF.S24637975?

Trojan.SabsikPMF.S24637975 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment