Trojan

TrojanDownloader:Win32/Berbew!pz (file analysis)

Malware Removal

The TrojanDownloader:Win32/Berbew!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Berbew!pz virus can do?

  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine TrojanDownloader:Win32/Berbew!pz?


File Info:

name: F71DB0F333021AAAAE8B.mlw
path: /opt/CAPEv2/storage/binaries/6217fd19653aaa0edab60481c45dc675d756207bb080134fc045edda222f5879
crc32: 808253DC
md5: f71db0f333021aaaae8bc0cd43e5520f
sha1: c944f3257008e59513db63a1743067c04b259276
sha256: 6217fd19653aaa0edab60481c45dc675d756207bb080134fc045edda222f5879
sha512: 93768665726e98312efecea869dc0db5c4bf282275860c6689524603defbac9625b3f6a3446beecc0a2337174523e5fd92efafaaf8e62b243249ce88f616a4ca
ssdeep: 1536:NXlw7iXclOt3bY/tNBEK7FkmsJifTduD4oTxw:FGiMW3gBEK7ymsJibdMTxw
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T169635C9F32CA0FEAC0C332B6597A99D5376D5C381316E7F008BE803E1396E2A57B5650
sha3_384: 7f4191bf4609088c0bddb61c6e5dcc4f89cb8c4640c1418e54b9171c36de5b102e4826eed09c86a5b7b3c2d42e35c775
ep_bytes: 90909090906067e80000000090589090
timestamp: 2022-03-16 18:29:59

Version Info:

0: [No Data]

TrojanDownloader:Win32/Berbew!pz also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
DrWebBackDoor.HangUp.43832
MicroWorld-eScanGenPack:Backdoor.Hangup.B
FireEyeGeneric.mg.f71db0f333021aaa
CAT-QuickHealTrojanDownloader.Berbew
SkyhighBehavesLike.Win32.Generic.kh
McAfeeGenericRXVP-YB!F71DB0F33302
MalwarebytesGeneric.Malware.AI.DDS
VIPREGenPack:Backdoor.Hangup.B
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.57008e
BitDefenderThetaAI:Packer.CC3D5BBB21
VirITWorm.Win32.Berbew.G
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Spy.Qukart
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Spy.Win32.Qukart.af
BitDefenderGenPack:Backdoor.Hangup.B
NANO-AntivirusTrojan.Win32.Qukart.jwfegu
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.Pornoasset.a
EmsisoftGenPack:Backdoor.Hangup.B (B)
F-SecureTrojan.TR/Spy.Qukart.NB
BaiduWin32.Trojan-Spy.Quart.a
ZillyaTrojan.QukartGen.Win32.2
TrendMicroTROJ_GEN.R03BC0DAQ24
SophosMal/Padodor-A
SentinelOneStatic AI – Malicious PE
GDataGenPack:Backdoor.Hangup.B
JiangminTrojanSpy.Qukart.ahel
VaristW32/Qukart.K.gen!Eldorado
AviraTR/Spy.Qukart.NB
MAXmalware (ai score=89)
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
ArcabitGenPack:Backdoor.Hangup.B
ZoneAlarmTrojan-Spy.Win32.Qukart.af
MicrosoftTrojanDownloader:Win32/Berbew!pz
GoogleDetected
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32BScope.Backdoor.Berbew
ALYacGenPack:Backdoor.Hangup.B
TACHYONBackdoor/W32.Padodor
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03BC0DAQ24
RisingBackdoor.Berbew!1.AE0A (CLASSIC)
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Qukart.A!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove TrojanDownloader:Win32/Berbew!pz?

TrojanDownloader:Win32/Berbew!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment