Trojan

Trojan.Sunburst.B (file analysis)

Malware Removal

The Trojan.Sunburst.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Sunburst.B virus can do?

  • Presents an Authenticode digital signature
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Sunburst.B?


File Info:

crc32: EE829C13
md5: 3e329a4c9030b26ba152fb602a1d5893
name: 3E329A4C9030B26BA152FB602A1D5893.mlw
sha1: ebe711516d0f5cd8126f4d53e375c90b7b95e8f2
sha256: d3c6785e18fba3749fb785bc313cf8346182f532c59172b69adfb31b96a5d0af
sha512: 95f0308b8b9c1263c3318e4577446572190e508c9fbb87f3170dd1bfe104e01bfcb97537648eca4ef123e3f15d79b53ea702553a7433dbaf3d543b045d2ecb3e
ssdeep: 24576:ddBfeHcrhCECR1R/zoi8SHoN0W8vB8O3IcH:Re8nK/zopSHoN0W8vB8m
type: PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 1999-2019 SolarWinds Worldwide, LLC. All Rights Reserved.
Assembly Version: 2019.4.5200.8890
InternalName: SolarWinds.Orion.Core.BusinessLayer.dll
FileVersion: 2019.4.5200.8890
CompanyName: SolarWinds Worldwide, LLC.
LegalTrademarks:
Comments:
ProductName: SolarWinds.Orion.Core.BusinessLayer
ProductVersion: 2019.4.5200.8890
FileDescription: SolarWinds.Orion.Core.BusinessLayer
OriginalFilename: SolarWinds.Orion.Core.BusinessLayer.dll

Trojan.Sunburst.B also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Sunburst.B
McAfeeTrojan-sunburst
CylanceUnsafe
BitDefenderTrojan.Sunburst.B
CyrenW32/Trojan.CSFL-0204
Paloaltogeneric.ml
KasperskyBackdoor.MSIL.Sunburst.d
AlibabaBackdoor:MSIL/Sunburst.46226035
EmsisoftTrojan.Sunburst.B (B)
ComodoBackdoor@#aguwggb5iyn3
DrWebBackDoor.SiggenNET.14
TrendMicroTROJ_FRS.0NA103LM20
McAfee-GW-EditionTrojan-sunburst
IkarusTrojan.Sunburst
JiangminBackdoor.MSIL.ebbj
AviraTR/Redcap.exspb
MAXmalware (ai score=75)
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:MSIL/Solorigate.BR!dha
ViRobotBackdoor.Win32.S.sunburst.940304
ZoneAlarmBackdoor.MSIL.Sunburst.d
GDataTrojan.Sunburst.B
AhnLab-V3Backdoor/Win32.SunBurst.C4265836
Acronissuspicious
ALYacTrojan.MSIL.SunBurst
MalwarebytesBackdoor.Sunburst
PandaTrj/Solorigate.A
TrendMicro-HouseCallTROJ_FRS.0NA103LM20
FortinetW32/Trojan.SUNBURST!tr
WebrootW32.Trojan.Sunburst
Qihoo-360Generic/Trojan.c2d

How to remove Trojan.Sunburst.B?

Trojan.Sunburst.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment