Trojan

What is “TrojanDownloader:Win32/Gippers.A”?

Malware Removal

The TrojanDownloader:Win32/Gippers.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Gippers.A virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Possible date expiration check, exits too soon after checking local time
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Checks for the presence of known windows from debuggers and forensic tools
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Detects VirtualBox through the presence of a registry key
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
newcard.dyndns.biz
newletter.dyndns.info
a.tomx.xyz

How to determine TrojanDownloader:Win32/Gippers.A?


File Info:

crc32: 0DB5B5A7
md5: 73ed8474d0d89aef199224f9a75a1fee
name: 73ED8474D0D89AEF199224F9A75A1FEE.mlw
sha1: bbbeaa36eb2ae69448b05ad101233201f76f9278
sha256: f22e25062fe933fee5f0c206f4fbd61cf556522f67ba83349f57212a2b385311
sha512: 6c670d316696ea681b59d64e39d6bcff13bc0a4eb722606cd866e348f96945e061de40691ec910d7e5026b002d07dc5f7141b28f209000392e2148b9de9b7604
ssdeep: 1536:OGQrSDoYNxR/GHcpk8oJGai7tgD3NJG5FExjZ2sf:pp1/GHcS9H+yD3N44xjUsf
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

TrojanDownloader:Win32/Gippers.A also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanDropped:Generic.Malware.SB.6C0309C2
FireEyeGeneric.mg.73ed8474d0d89aef
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacDropped:Generic.Malware.SB.6C0309C2
MalwarebytesTrojan.Agent.KRN
VIPRETrojan-Downloader.Win32.Gippers.a (v)
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004d677e1 )
BitDefenderDropped:Generic.Malware.SB.6C0309C2
K7GWTrojan ( 004d677e1 )
Cybereasonmalicious.4d0d89
BitDefenderThetaGen:NN.ZexaF.34590.dqZ@ay!VQnab
SymantecTrojan.Dropper
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Agent-1302681
KasperskyTrojan-Ransom.Win32.Blocker.azqp
AlibabaRansom:Win32/Blocker.ec19b336
NANO-AntivirusTrojan.Win32.Blocker.bxpndh
TencentTrojan-ransom.Win32.Blocker.cgth
Ad-AwareDropped:Generic.Malware.SB.6C0309C2
SophosML/PE-A + Mal/Behav-112
ComodoTrojWare.Win32.Ransom.Blocker.UOY@4w6mes
F-SecureTrojan.TR/Downloader.Gen7
DrWebTrojan.Inject1.11547
ZillyaTrojan.Blocker.Win32.9993
McAfee-GW-EditionBehavesLike.Win32.Dropper.qc
EmsisoftDropped:Generic.Malware.SB.6C0309C2 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Genome.clsz
AviraTR/Downloader.Gen7
Antiy-AVLTrojan[Ransom]/Win32.Blocker
MicrosoftTrojanDownloader:Win32/Gippers.A
ArcabitGeneric.Malware.SB.6C0309C2
ZoneAlarmTrojan-Ransom.Win32.Blocker.azqp
GDataDropped:Generic.Malware.SB.6C0309C2
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Blocker.R78431
McAfeeGenericRXAA-AA!73ED8474D0D8
MAXmalware (ai score=84)
VBA32Hoax.Blocker
CylanceUnsafe
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Mirage.L
RisingRansom.Blocker!8.12A (CLOUD)
YandexTrojan.GenAsa!srCRe0lIJ4I
IkarusTrojan-Downloader.Win32.Gippers
eGambitUnsafe.AI_Score_99%
FortinetW32/Blocker.AZQP!tr
MaxSecureTrojan.Malware.121218.susgen
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_90% (D)
Qihoo-360Win32/Trojan.Ransom.fd8

How to remove TrojanDownloader:Win32/Gippers.A?

TrojanDownloader:Win32/Gippers.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment