Trojan

Trojan:Win32/Dinwod.A!MTB malicious file

Malware Removal

The Trojan:Win32/Dinwod.A!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Dinwod.A!MTB virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Possible date expiration check, exits too soon after checking local time
  • Starts servers listening on 0.0.0.0:32219
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Looks up the external IP address
  • Sniffs keystrokes
  • Attempts to stop active services
  • A process attempted to delay the analysis task by a long amount of time.
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Creates a copy of itself
  • Attempts to disable UAC
  • Attempts to modify UAC prompt behavior

Related domains:

whatismyip.everdot.org
whatismyipaddress.com
www.showmyipaddress.com
www.whatismyip.ca
www.whatismyip.com
www.adobe.com
syogeocaac.org
dmpczsdoj.info
vcvdrbqg.net
ynwquyizxwta.info
ngdcpykte.org
jcyjriqe.net
tilgtmodf.org
pjpdnznikx.info
mkrlisz.net
xmrkuvvupsd.com
xnwnfugt.info
xojwsovwi.net
lhvmhpyf.info
jibdhv.net
fzdsbgodlh.info
ylrblcyhakdr.info
cuaigi.org
lgfcvtxjvazj.net
adnsfqt.net
msawccaugiyg.org
khlztmjjps.info
kahzysr.net
nbzorucp.net
npangy.info
icfobolypfx.info
lgdczmyqx.info
kqgqcgzzc.net
caeomqykgckm.com
rhffhbbrpyot.info
zyeaqhsuicf.org
xthrvjek.info
syfkuyx.info
qcmkuw.com
gzwumhfj.net
mglupgbxbbp.net
cgwhyrocrsp.info
iisjjzzk.info
akftoai.info
favckollduxp.net
gjfsguqye.net
wwzajzptqucm.info
sshrdwyj.info
xcowqyvzlk.net
oumkuigiyk.com
cgqagmaeqg.org
wodkjkp.net
auamgaf.info
uktwdmhubwb.info
geiiyg.org
svgfawgkgera.info
vgltokm.com
tgtjesmjle.net
dsflqdxexp.info
imhqsxnveqs.net
edgedl.me.gvt1.com

How to determine Trojan:Win32/Dinwod.A!MTB?


File Info:

crc32: EB4B8F9E
md5: f895451b282cbc4295de57124a121ca4
name: F895451B282CBC4295DE57124A121CA4.mlw
sha1: eb2afa70b81114c2038cf3eb43eb593bdc817de7
sha256: 000cbb570079b804f4abe8a9e7f0437a6765c4ceab099300b25c4010dcf5478f
sha512: 7759c8058dc9bb29bbe10072f298db9f5b4d81f7dd5c8fd9fa6aad58ab340526ebfd7e59bdd2d2b24a0efc43be324db576221dc61c032428ad06af68ae766e7d
ssdeep: 6144:S3Te8ySm8hQAAIfFrRXuEE+0l97mKwKROHVMOU86JQPDHDdx/Qtqa:1/zkFF+EExZmKbRiVjUPJQPDHvd
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Dinwod.A!MTB also known as:

BkavW32.FxcaxMMUqhATTc.Worm
K7AntiVirusTrojan ( 003da8d71 )
Elasticmalicious (high confidence)
DrWebTrojan.Siggen.36621
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacGen:Variant.Pykspa.1
CylanceUnsafe
ZillyaTrojan.Vilsel.Win32.2601
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 003da8d71 )
Cybereasonmalicious.b282cb
BaiduWin32.Worm.Autorun.o
CyrenW32/Pykspa.A.gen!Eldorado
SymantecW32.Pykspa.D
ESET-NOD32Win32/AutoRun.Agent.TG
ZonerTrojan.Win32.24407
APEXMalicious
AvastWin32:Renos-KY [Trj]
ClamAVWin.Worm.Pykspa-1
KasperskyTrojan-Ransom.Win32.Blocker.jcen
BitDefenderGen:Variant.Pykspa.1
NANO-AntivirusTrojan.Win32.Agent.ctkmgw
ViRobotTrojan.Win32.Blocker.Gen.B
SUPERAntiSpywareWorm.SkypeBot
MicroWorld-eScanGen:Variant.Pykspa.1
TencentWorm.Win32.Pykspa.a
Ad-AwareGen:Variant.Pykspa.1
SophosML/PE-A + W32/Pykse-F
ComodoWorm.Win32.Autorun.Agent_TG0@1isiwy
BitDefenderThetaGen:NN.ZexaF.34758.tnW@aK0GwZl
VIPREWorm.Win32.Skyper.b (v)
TrendMicroWORM_VILSEL.SMC
McAfee-GW-EditionBehavesLike.Win32.Pykse.tz
FireEyeGeneric.mg.f895451b282cbc42
EmsisoftGen:Variant.Pykspa.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Blocker.lhz
WebrootW32.Trojan.Gen
AviraTR/Agent.327680.A
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.C6BB
KingsoftHeur.SSC.2452.1216.(kcloud)
MicrosoftTrojan:Win32/Dinwod.A!MTB
ZoneAlarmTrojan-Ransom.Win32.Blocker.jcen
GDataWin32.Trojan.PSE.17CFWL2
TACHYONTrojan/W32.Blocker.1363968.E
AhnLab-V3Trojan/Win32.Zepfod.R4378
Acronissuspicious
McAfeeW32/Pykse.worm.gen.a
MAXmalware (ai score=100)
VBA32Trojan.ChidikSun.28205
MalwarebytesGeneric.Worm.Agent.DDS
PandaTrj/Vilsel.B
TrendMicro-HouseCallWORM_VILSEL.SMC
RisingWorm.Autorun!1.BC87 (CLASSIC)
YandexTrojan.GenAsa!R41E4MI3PTc
IkarusTrojan.Win32.AntiAV
MaxSecureTrojan.Ransom.Blocker.iprw
FortinetW32/Agent.XEK!tr
AVGWin32:Renos-KY [Trj]
Paloaltogeneric.ml

How to remove Trojan:Win32/Dinwod.A!MTB?

Trojan:Win32/Dinwod.A!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment