Trojan

Trojan.SabsikRI.S22841427 (file analysis)

Malware Removal

The Trojan.SabsikRI.S22841427 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.SabsikRI.S22841427 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • NtSetInformationThread: attempt to hide thread from debugger
  • Dynamic (imported) function loading detected
  • Expresses interest in specific running processes
  • A process created a hidden window
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with Themida
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Checks for the presence of known windows from debuggers and forensic tools
  • The following process appear to have been packed with Themida: 99B6EE52D0DC5A07BFF0.mlw
  • CAPE detected the CryptBot malware family
  • Attempts to identify installed AV products by installation directory
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.SabsikRI.S22841427?


File Info:

name: 99B6EE52D0DC5A07BFF0.mlw
path: /opt/CAPEv2/storage/binaries/7b3296a5492a8b01ab3bb33164a1bb269630b396d6dd8234accce8e4c4d84067
crc32: 2624B912
md5: 99b6ee52d0dc5a07bff09373a8dda2fe
sha1: 616c52af96614c86623829b604b0eda3cf29af28
sha256: 7b3296a5492a8b01ab3bb33164a1bb269630b396d6dd8234accce8e4c4d84067
sha512: 338babef8e40c74ab6957b226e90457d9a0db9f4007235a2df699d4ba6797f571c957b743c1324acad579fd50fd128af47550e5680f92fa7ce276f5cc9d3c12e
ssdeep: 49152:DPPskqauipv1QRGYYHZRuhIR3AGb9UCJ0MaLQW2QWCQqc412Rx0dxgJ13:jfRpOUYuGVGJQPUjqcfRx1J
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D8D533E3B5821836CC52297DCD0ED569862E97E874B8928D2FDC7E50D740BCE0F76A24
sha3_384: 05e6fcd5916448f383fc3b467e79a7010cd6dd53f9b939837e6c386ef83f5402347c9bee3ed47ba5c7c428edb44ad760
ep_bytes: e84b0100005389e3538b73088b7b10fc
timestamp: 2021-12-28 19:56:39

Version Info:

0: [No Data]

Trojan.SabsikRI.S22841427 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Agent.7!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen16.21602
MicroWorld-eScanGen:Variant.Zusy.398819
FireEyeGeneric.mg.99b6ee52d0dc5a07
CAT-QuickHealTrojan.SabsikRI.S22841427
McAfeeArtemis!99B6EE52D0DC
CylanceUnsafe
SangforSuspicious.Win32.Save.a
AlibabaPacked:Win32/Themida.c89b82d4
Cybereasonmalicious.2d0dc5
ArcabitTrojan.Zusy.D615E3
BitDefenderThetaAI:Packer.7FC131D11F
CyrenW32/Zusy.IQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.Themida.HNR
TrendMicro-HouseCallTROJ_GEN.R067C0GA122
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Banker.Win32.Agent.pef
BitDefenderGen:Variant.Zusy.398819
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:CrypterX-gen [Trj]
TencentWin32.Trojan-banker.Agent.Hwcs
Ad-AwareGen:Variant.Zusy.398819
SophosMal/Generic-S
ComodoTrojWare.Win32.Agent.pduut@0
TrendMicroTROJ_GEN.R067C0GA122
McAfee-GW-EditionBehavesLike.Win32.Backdoor.vc
EmsisoftGen:Variant.Zusy.398819 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Banker.Agent.erb
AviraTR/Crypt.XPACK.Gen2
MAXmalware (ai score=81)
KingsoftWin32.Heur.KVMH008.a.(kcloud)
GridinsoftTrojan.Heur!.032100A1
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Variant.Zusy.398819
CynetMalicious (score: 100)
AhnLab-V3Infostealer/Win.CryptBot.R440484
Acronissuspicious
ALYacGen:Variant.Zusy.398819
VBA32BScope.Backdoor.Agent
MalwarebytesTrojan.Crypt
APEXMalicious
RisingTrojan.Generic@ML.96 (RDML:74MuwNYe5AKA2U34wk2rRg)
YandexTrojan.Themida!L1R35etw7Cw
IkarusTrojan.Win32.Themida
eGambitUnsafe.AI_Score_99%
FortinetW32/PackedThemida.HNR!tr
AVGWin32:CrypterX-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan.SabsikRI.S22841427?

Trojan.SabsikRI.S22841427 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment