Trojan

Trojan:Win32/Sabsik.FL (file analysis)

Malware Removal

The Trojan:Win32/Sabsik.FL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Sabsik.FL virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Trojan:Win32/Sabsik.FL?


File Info:

name: 294911E25F9B3072127E.mlw
path: /opt/CAPEv2/storage/binaries/382cdf4a05661e242d4221f5969ea7866bf1303b304053df7f6ee49ae57e19bb
crc32: 5C21BFE2
md5: 294911e25f9b3072127e099a56cecc40
sha1: bf7e9a18a1b81f0db41aa89510caedc371b53f04
sha256: 382cdf4a05661e242d4221f5969ea7866bf1303b304053df7f6ee49ae57e19bb
sha512: 1476bc23ccb6d95d799277be5702fcf98bca62aa3a1d3997792033359303b954eba277657a6f55b1d09c60524d90953b2f7480b4752afd3a4659b91809ecaf0f
ssdeep: 24576:0AOYgy5FNbLxbKtz6PIYTccJf2Ak0q+o82Ngdqr2Q7N1wo+AYOHu/Ek5:0UVHNJf2AU3NxjN1wo+QO/5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17E556C53B3C48163CBE655340617773B76797D34AA25B94B6BE03A3E29323011B3AB36
sha3_384: 6eaedb164772cbca229649aa759e9d6277d35fc076723f0c2beb43d9f98f4d8be34ed1a9374f919a3a6543cf8a08499d
ep_bytes: 5589e583ec08c7042402000000ff15d4
timestamp: 2008-04-19 11:49:11

Version Info:

0: [No Data]

Trojan:Win32/Sabsik.FL also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Click3.29339
MicroWorld-eScanGen:Heur.Minggy.1
FireEyeGeneric.mg.294911e25f9b3072
McAfeeGenericRXNT-WU!294911E25F9B
CylanceUnsafe
SangforTrojan.Win32.Agent.SPH
K7AntiVirusTrojan ( 005415ef1 )
AlibabaVirus:Win32/Lamer.fd686863
K7GWTrojan ( 005415ef1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.34638.urZ@augH7dl
CyrenW32/Kryptik.DIU.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDropper.Agent.SPH
TrendMicro-HouseCallTROJ_GEN.R002C0PDR22
Paloaltogeneric.ml
KasperskyVirus.Win32.Lamer.ks
BitDefenderGen:Heur.Minggy.1
NANO-AntivirusTrojan.Win32.Clicker.dapdse
AvastWin32:Malware-gen
TencentTrojan.Win32.Agent.xj
Ad-AwareGen:Heur.Minggy.1
EmsisoftGen:Heur.Minggy.1 (B)
ComodoPacked.Win32.MUPX.Gen@24tbus
TrendMicroTROJ_GEN.R002C0PDR22
McAfee-GW-EditionBehavesLike.Win32.RAHack.th
SophosML/PE-A + Troj/Agent-BGMW
IkarusTrojan.Win32.Genome
JiangminTrojan/Genome.cae
AviraTR/Crypt.ZPACK.Gen2
MAXmalware (ai score=83)
MicrosoftTrojan:Win32/Sabsik.FL
ViRobotTrojan.Win32.Z.Minggy.1384448
GDataGen:Heur.Minggy.1
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.RL_Reputation.R365985
Acronissuspicious
VBA32Trojan.Click
APEXMalicious
RisingTrojan.Kryptik!1.D30B (RDMK:cmRtazp8+wbnkH+dcxUDjlG+HSph)
YandexTrojan.GenKryptik!HqdwIMg4iPo
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/GenKryptik.CRKJ!tr
AVGWin32:Malware-gen
Cybereasonmalicious.25f9b3
PandaGeneric Suspicious

How to remove Trojan:Win32/Sabsik.FL?

Trojan:Win32/Sabsik.FL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment