Trojan

Trojan.Win32.Eb.bli (file analysis)

Malware Removal

The Trojan.Win32.Eb.bli is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Eb.bli virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Expresses interest in specific running processes
  • Unconventionial language used in binary resources: Serbian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Trojan.Win32.Eb.bli?


File Info:

crc32: F5D1995C
md5: d7b5c0dfacada838878509c0e797e38c
name: D7B5C0DFACADA838878509C0E797E38C.mlw
sha1: c03590cbfeba3f9820457e4ac083144896c7b4c6
sha256: 5a821f9282f6d079eeb89fda84f5cc1b6baa5e87e5bf04a9c5721863e6e23d00
sha512: 0af0b8fb10b7c9362b6dc47526cea53c5dcb1745d8eb10b8b89585c09a492c5860000b38ceb7807034b776bc6923302bc7f6167d8ee4f138e66c7ed097b62548
ssdeep: 98304:J9MBIc/tTe9nL1AjYxqILKB7NaeUYcpSP3M4V2tV4UDxSze5uvcTvr35m2IL+qy:nMSYSvAdsCEtt7Ts+hkoUb
type: PE32 executable (GUI) Intel 80386 system file, for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifor.occ
FileVersion: 6.26.361
Copyright: Copyrighz (C) 2020, wodkafull
ProductVersion: 1.0.16
TranslationUsa: 0x0273 0x0080

Trojan.Win32.Eb.bli also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.36047309
FireEyeGeneric.mg.d7b5c0dfacada838
McAfeeGenericRXAA-AA!D7B5C0DFACAD
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Malicious.4!c
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.36047309
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.bfeba3
BitDefenderThetaGen:NN.ZexaF.34760.@pKfay@tTMpG
CyrenW32/Trojan.JOPN-3993
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyTrojan.Win32.Eb.bli
AlibabaTrojan:Win32/Azorult.9cfc4cef
TencentWin32.Trojan.Eb.Wtdl
Ad-AwareTrojan.GenericKD.36047309
EmsisoftTrojan.GenericKD.36047309 (B)
F-SecureHeuristic.HEUR/AGEN.1140248
DrWebTrojan.Siggen11.58114
ZillyaTrojan.Eb.Win32.290
TrendMicroTROJ_GEN.R067C0DAB21
McAfee-GW-EditionBehavesLike.Win32.Generic.rc
SophosMal/Generic-S
IkarusTrojan.WinGo.Ranumbot
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1140248
MicrosoftTrojan:Win32/Azorult.MR!MTB
GridinsoftTrojan.Win32.Packed.oa
ArcabitTrojan.Generic.D22609CD
ZoneAlarmTrojan.Win32.Eb.bli
GDataTrojan.GenericKD.36047309
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R362567
Acronissuspicious
ALYacTrojan.GenericKD.36047309
MAXmalware (ai score=82)
VBA32Trojan.Eb
MalwarebytesTrojan.MalPack.GS
PandaTrj/RnkBend.A
ESET-NOD32WinGo/RanumBot.J
TrendMicro-HouseCallTROJ_GEN.R067C0DAB21
RisingTrojan.Kryptik!1.CFEE (CLASSIC)
YandexTrojan.Igent.bU7Z9x.5
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.HIRY!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Generic/HEUR/QVM11.1.729B.Malware.Gen

How to remove Trojan.Win32.Eb.bli?

Trojan.Win32.Eb.bli removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment