Trojan

Trojan:Win32/Phorpiex.DHE!MTB (file analysis)

Malware Removal

The Trojan:Win32/Phorpiex.DHE!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Phorpiex.DHE!MTB virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Hungarian
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Queries information on disks, possibly for anti-virtualization
  • Attempts to remove evidence of file being downloaded from the Internet
  • Deletes its original binary from disk
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Operates on local firewall’s policies and settings
  • Creates a copy of itself
  • Attempts to disable Windows Defender
  • Connects to an IRC server, possibly part of a botnet
  • Anomalous binary characteristics

Related domains:

rohgoruhgsorhugih.ru

How to determine Trojan:Win32/Phorpiex.DHE!MTB?


File Info:

crc32: 410522A1
md5: c8396cc91fd874ba18e306a764b8b9a8
name: C8396CC91FD874BA18E306A764B8B9A8.mlw
sha1: 3bd1507634c68b454653f2317c6a856a318cf70c
sha256: 0811fcb5ce210fb089f1f1cff67074ec183085b9837e2a55a02dae23e80b5fcb
sha512: 521ba317c0619547822115c445ea832d9a94d0cd0efb33c4fc85caa3d67739c2e57dfcdb950ec915e15afd3711031fd9746e231708c413731ab8d656f5523de2
ssdeep: 3072:yr1cWI8i05JurTwXU/ulPgc9qz+bgR0+l+E:g1RJxur8XMQPgyPgq+l+E
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Phorpiex.DHE!MTB also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005198121 )
LionicTrojan.Win32.Androm.m!c
Elasticmalicious (high confidence)
DrWebTrojan.Inject2.61397
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Mauvaise.S1639727
ALYacTrojan.Ransom.MyRansom
CylanceUnsafe
ZillyaTrojan.IRCbot.Win32.5
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/Phorpiex.d7f126a3
K7GWTrojan ( 005198121 )
Cybereasonmalicious.91fd87
CyrenW32/S-ced9a09c!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Injector.DSOK
APEXMalicious
AvastWin32:Dropper-gen [Drp]
ClamAVWin.Trojan.Ircbot-7576460-0
KasperskyHEUR:Trojan.Win32.IRCbot.pef
BitDefenderTrojan.BRMon.Gen.3
NANO-AntivirusTrojan.Win32.IRCbot.etsstv
ViRobotTrojan.Win32.MyRansom.150528
MicroWorld-eScanTrojan.BRMon.Gen.3
TencentMalware.Win32.Gencirc.10b0d4b3
Ad-AwareTrojan.BRMon.Gen.3
SophosMal/Generic-R + Troj/Agent-BCUG
ComodoTrojWare.Win32.Neutrinopos.A@7ntsgu
BitDefenderThetaAI:Packer.FC42522E1F
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_HPWORTRIK.SM
McAfee-GW-EditionBehavesLike.Win32.Emotet.dm
FireEyeGeneric.mg.c8396cc91fd874ba
EmsisoftTrojan.BRMon.Gen.3 (B)
SentinelOneStatic AI – Malicious PE
JiangminRiskTool.BitCoinMiner.fio
AviraTR/Injector.hlxrw
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.224FB28
MicrosoftTrojan:Win32/Phorpiex.DHE!MTB
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
GDataTrojan.BRMon.Gen.3
AhnLab-V3Trojan/Win32.RL_Magniber.R266314
McAfeeTrojan-FMGH!C8396CC91FD8
MAXmalware (ai score=82)
VBA32Trojan-Banker.Jimmy
MalwarebytesTrojan.Injector
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_HPWORTRIK.SM
RisingMalware.Obscure/Heur!1.9E03 (CLASSIC)
YandexTrojan.GenAsa!nOJGZbHYoKY
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HCUD!tr
AVGWin32:Dropper-gen [Drp]
Paloaltogeneric.ml

How to remove Trojan:Win32/Phorpiex.DHE!MTB?

Trojan:Win32/Phorpiex.DHE!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment