Trojan

TrojanDownloader:Win32/Berbew!pz (file analysis)

Malware Removal

The TrojanDownloader:Win32/Berbew!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Berbew!pz virus can do?

  • Sample contains Overlay data
  • Creates an indicator observed in Territorial Disputes report SIG40
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine TrojanDownloader:Win32/Berbew!pz?


File Info:

name: DE5CEFD6D9915D448D43.mlw
path: /opt/CAPEv2/storage/binaries/4580b24cbf846f74eaff1bac6980da7de239c77ed8a02414494b744ffe3acaa1
crc32: 14BF42A7
md5: de5cefd6d9915d448d43d77e3f4f10df
sha1: c84dcbff1f13c7a016f488d77e7794643d74f54b
sha256: 4580b24cbf846f74eaff1bac6980da7de239c77ed8a02414494b744ffe3acaa1
sha512: 36bf05b7684870be1e0f28fa0bafb3b13c3e0ca2b86c30c1a3c83ba6d67e5710a2c2b6f55f594250df62085921254ee6b36d2000b77e81f39f5076fc10e132c6
ssdeep: 6144:uVfb/l3/fc/UmKyIxLDXXoq9FJZCUmKyIxLq:uy32XXf9Do3R
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B7646A06E1EC9E03CA65C67747C22DF2AB534E8986F5ADBD364C84B4ADC69323C3146C
sha3_384: 08ad6387bece38ac82ad8b2cbd97c47887854bd005dfc97649c911e50333cb1783f9b057bba9df4801556fd83628c166
ep_bytes: 90609090909067e80000000090909090
timestamp: 1977-12-31 05:39:38

Version Info:

0: [No Data]

TrojanDownloader:Win32/Berbew!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.ShellObject.u4Z@ay8bj9g
ClamAVWin.Trojan.Crypted-30
FireEyeGeneric.mg.de5cefd6d9915d44
CAT-QuickHealTrojan.GenericIH.S13286062
SkyhighBehavesLike.Win32.Generic.fc
McAfeeTrojan-FVOK!DE5CEFD6D991
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Padodor.Win32.1425886
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005780dd1 )
K7GWTrojan ( 005780dd1 )
Cybereasonmalicious.f1f13c
ArcabitTrojan.ShellObject.E7C732
BitDefenderThetaAI:Packer.5F173D0121
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Padodor.AB
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Padodor.gen
BitDefenderGen:Trojan.ShellObject.u4Z@ay8bj9g
NANO-AntivirusTrojan.Win32.Padodor.jzfekv
AvastWin32:Padodor-V [Trj]
TencentBackdoor.Win32.Padodor.kp
TACHYONBackdoor/W32.Padodor
SophosMal/Padodor-A
F-SecureTrojan.TR/Crypt.XDR.Gen
DrWebBackDoor.Wdozer
VIPREGen:Trojan.ShellObject.u4Z@ay8bj9g
Trapminemalicious.high.ml.score
EmsisoftGen:Trojan.ShellObject.u4Z@ay8bj9g (B)
IkarusTrojan.Win32.Padodor
JiangminBackdoor.Padodor.erlj
GoogleDetected
AviraTR/Crypt.XDR.Gen
Antiy-AVLTrojan[Proxy]/Win32.Qukart.gen
Kingsoftmalware.kb.a.1000
MicrosoftTrojanDownloader:Win32/Berbew!pz
ZoneAlarmBackdoor.Win32.Padodor.gen
GDataGen:Trojan.ShellObject.u4Z@ay8bj9g
VaristW32/Backdoor.DKIC-2994
AhnLab-V3Win-Trojan/Berbew.51712
Acronissuspicious
VBA32Backdoor.Padodor
ALYacGen:Trojan.ShellObject.u4Z@ay8bj9g
MAXmalware (ai score=89)
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Berbew!8.115 (TFE:2:OZNHsQD3f1G)
YandexBackdoor.Padodor!A5nRMmhQe3Q
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Qukart.A!tr
AVGWin32:Padodor-V [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove TrojanDownloader:Win32/Berbew!pz?

TrojanDownloader:Win32/Berbew!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment