Trojan

About “Trojan:Win32/Sabsik!rfn” infection

Malware Removal

The Trojan:Win32/Sabsik!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Sabsik!rfn virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Harvests cookies for information gathering

How to determine Trojan:Win32/Sabsik!rfn?


File Info:

name: 3790EFD4BBC72413CFD1.mlw
path: /opt/CAPEv2/storage/binaries/bd2133d580405f6886a2859b466a3519725cf46857e7237cdaa30a8fac3008c7
crc32: 33F26AD1
md5: 3790efd4bbc72413cfd17e78193a2f94
sha1: 49d9ad1d7532eec2b02de3854cb87ff5c9a0c9d0
sha256: bd2133d580405f6886a2859b466a3519725cf46857e7237cdaa30a8fac3008c7
sha512: ecc1c29ffb439d0ecc016bd5a06fdfbc6fb465f58f6c0985d7a374b7d5c322bc0364707e15add11e584b95adf4d3fd0654845195b687a06b2ee6fabf93172862
ssdeep: 49152:MmrMIbKDye9jYOJPU+SyDKbsJuIJBhIY99kBfTgqynHm2IkLPZ/l8z2XhXOc2g3P:5XIKQkOqyp3PoClOc53u5KkQ8TDImvTg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FBF52301FBC2D0F1CA5252306E9AFF2A90EDB66547664AC3FBD80E8C5D715E03236796
sha3_384: 60c7a8e6435508f8301f9937f2870bad1a7fd568f9e61db900ce9c43a3009990da0f70abca648a1d02718310593d9d42
ep_bytes: e8443a0000e97ffeffff538bdc515183
timestamp: 2019-02-22 03:23:18

Version Info:

FileVersion: 5.9.8.10920
ProductVersion: 5.9
Translation: 0x0804 0x04b0

Trojan:Win32/Sabsik!rfn also known as:

LionicTrojan.Win32.SchoolBoy.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Midie.88217
FireEyeGeneric.mg.3790efd4bbc72413
ALYacGen:Variant.Midie.88217
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojan:Win32/SchoolBoy.ad748d96
K7AntiVirusRiskware ( 00584baa1 )
VirITTrojan.Win32.Muldrop8.CQAV
CyrenW32/SchoolBoy.A.gen!Eldorado
tehtrisGeneric.Malware
TrendMicro-HouseCallTROJ_GEN.R002C0WDO22
Paloaltogeneric.ml
ClamAVWin.Malware.Mikey-6986881-0
KasperskyHEUR:Trojan.Win32.SchoolBoy.gen
BitDefenderGen:Variant.Midie.88217
NANO-AntivirusRiskware.Win32.HackTool.gggyda
AvastWin32:Malware-gen
Ad-AwareGen:Variant.Midie.88217
SophosMal/Generic-S
ComodoTrojWare.Win32.Eqtonex.B@83htfq
ZillyaTrojan.Miner.Win32.5421
TrendMicroTROJ_GEN.R002C0WDO22
McAfee-GW-EditionBehavesLike.Win32.BrowseFox.wc
EmsisoftGen:Variant.Midie.88217 (B)
Ikaruspossible-Threat.Untrusted.Certificate
AviraHEUR/AGEN.1223912
MicrosoftTrojan:Win32/Sabsik!rfn
ZoneAlarmHEUR:Trojan.Win32.SchoolBoy.gen
GDataGen:Variant.Midie.88217
CynetMalicious (score: 100)
Acronissuspicious
McAfeeArtemis!3790EFD4BBC7
MAXmalware (ai score=88)
VBA32BScope.Trojan.Runner
MalwarebytesPUP.Optional.ChinAd
APEXMalicious
YandexPUP.Crack!9ZqoJCZNjeQ
MaxSecureTrojan.Malware.10640424.susgen
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
Cybereasonmalicious.d7532e
PandaTrj/Genetic.gen

How to remove Trojan:Win32/Sabsik!rfn?

Trojan:Win32/Sabsik!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment