Trojan

What is “Trojan:Win32/Brambul.A!dha”?

Malware Removal

The Trojan:Win32/Brambul.A!dha is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Brambul.A!dha virus can do?

  • Unconventionial language used in binary resources: Korean
  • Authenticode signature is invalid

How to determine Trojan:Win32/Brambul.A!dha?


File Info:

name: 8A35643C09065DEA3F6D.mlw
path: /opt/CAPEv2/storage/binaries/d5cda0118a216964858f554cd0df805585e2f2e1dd10a4204177d2fecd615e6a
crc32: 7C8C07B0
md5: 8a35643c09065dea3f6da607d2ee75c9
sha1: 13b853bf9a0f3a64231fc342dffb0b8b64f0570c
sha256: d5cda0118a216964858f554cd0df805585e2f2e1dd10a4204177d2fecd615e6a
sha512: ed1db7419c0df08ed14affb48978f70201b11bb96880fd6a6afcef6cece4977b04e3eabac878a6a1067e41f7ac707ec31a0401abd355687aaa82ce932666417b
ssdeep: 3072:0LoaELkp5l//JgId4ur3pc9SO9Uf/+ItPxWWn:T+rJfNZySaUf/+SPxWO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T182140113B9E394E6E867A071B5CB5B3AD137107182E754C3AF50CCED6A371A1AA2D0C7
sha3_384: ec512ddc1504b4ffb94c8b2835f741e6d9dbd2036c62123021028487945f4fec40a27aad847e9237a071cebc4bb79164
ep_bytes: 03ea0fb7c1f2430fafea69f3f0e2dab7
timestamp: 2009-10-14 12:45:54

Version Info:

0: [No Data]

Trojan:Win32/Brambul.A!dha also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.ClipBanker.Z!c
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKDZ.90234
FireEyeGeneric.mg.8a35643c09065dea
SkyhighBehavesLike.Win32.Virut.cm
ALYacTrojan.GenericKDZ.90234
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.GenericKDZ.90234
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 004ffce01 )
BitDefenderTrojan.GenericKDZ.90234
K7GWTrojan ( 004ffce01 )
Cybereasonmalicious.f9a0f3
BitDefenderThetaGen:NN.ZexaF.36792.mqW@au3lPOlG
VirITTrojan.Win32.Agent.AHCN
SymantecW32.Brambul
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Pepex.K
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Spyware.78857-1
KasperskyTrojan-Banker.Win32.ClipBanker.yyw
AlibabaTrojanBanker:Win32/ClipBanker.d5b9a5b3
NANO-AntivirusVirus.Win32.Gen.ccmw
RisingBackdoor.Win32.Mnless.diy (CLASSIC)
EmsisoftTrojan.GenericKDZ.90234 (B)
F-SecureTrojan.TR/Agent.grpm
DrWebWin32.HLLW.Brambul.1
ZillyaTrojan.Pepex.Win32.7
TrendMicroPE_SALITY.RL
Trapminemalicious.moderate.ml.score
SophosMal/Spy-Y
IkarusEmail-Worm.Win32.Atak
GDataWin32.Worm.Pepex.A
JiangminWin32/HLLP.Kuku.poly2
VaristW32/Sality.gen2
AviraTR/Agent.grpm
Kingsoftmalware.kb.a.1000
XcitiumWorm.Win32.Pepex.E0@1lqa8d
ArcabitTrojan.Generic.D1607A
ZoneAlarmTrojan-Banker.Win32.ClipBanker.yyw
MicrosoftTrojan:Win32/Brambul.A!dha
GoogleDetected
AhnLab-V3Trojan/Win32.Npkon.R136126
Acronissuspicious
VBA32suspected of Email-Worm.Mydoom.4
MAXmalware (ai score=100)
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/Chgt.AC
ZonerProbably Heur.ExeHeaderL
TrendMicro-HouseCallPE_SALITY.RL
TencentTrojan.Win32.Agent.spy
YandexWorm.Pepex!NAF4ascrlCU
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Pepex.A!tr
AVGWin32:TrojanX-gen [Trj]
AvastWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Brambul.A!dha?

Trojan:Win32/Brambul.A!dha removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment