Spy

What is “Weecnaw.Spyware.Stealer.DDS”?

Malware Removal

The Weecnaw.Spyware.Stealer.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Weecnaw.Spyware.Stealer.DDS virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities to create a scheduled task
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Injection with CreateRemoteThread in a remote process
  • CAPE detected the WarzoneRAT malware family
  • Deletes executed files from disk
  • Accesses or creates Warzone RAT directories and/or files
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Weecnaw.Spyware.Stealer.DDS?


File Info:

name: 2D33695D79ADF6D4E756.mlw
path: /opt/CAPEv2/storage/binaries/9830d55cbca13f6b4f15652d3a379eb9b877ec29e1be5ae81af128e4315f969e
crc32: 985385EE
md5: 2d33695d79adf6d4e7565f3d7aaf883e
sha1: 9c92b7f30e34bb3d52219e536664f0181e11d22b
sha256: 9830d55cbca13f6b4f15652d3a379eb9b877ec29e1be5ae81af128e4315f969e
sha512: 25212d787160404acd43cc6da65da9da6c245e9007be9a8b3a51a7890070c27fc125691e1466ffe27cb06b1b4d7de4adee73933ebebf14c33916566880ccae66
ssdeep: 24576:Ku6J33O0c+JY5UZ+XC0kGso6Fa720W4njUprvVcC1f2o5RRfgUWYt:8u0c++OCvkGs9Fa+rd1f26RaYt
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BE55BF52E39EC2F0DE165172BA7DF71A2F3F3C254530B956AFC52D3AAD21021112DAA3
sha3_384: 8bdff773ce903a8ceb9d7ea57e5d5793b8f48b37b54236bb8e6b76563bbcad63bcd644fa871cf3a333d22131b527a384
ep_bytes: e8b5d00000e97ffeffffcccccccccccc
timestamp: 2019-03-06 09:50:08

Version Info:

Translation: 0x0809 0x04b0

Weecnaw.Spyware.Stealer.DDS also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.NetWire.4!c
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKD.48560802
FireEyeGeneric.mg.2d33695d79adf6d4
ALYacTrojan.GenericKD.48560802
Cylanceunsafe
VIPRETrojan.GenericKD.48560802
SangforVirus.Win32.Save.a
K7AntiVirusTrojan ( 700000111 )
AlibabaTrojanSpy:Win32/NetWire.98da6848
K7GWTrojan ( 700000111 )
CrowdStrikewin/malicious_confidence_100% (W)
VirITBackdoor.Win32.Wirenet.CCS
CyrenW32/FakeDoc.G.gen!Eldorado
SymantecAUT.Heuristic!gen6
ElasticWindows.Trojan.Netwire
ESET-NOD32Win32/Spy.Weecnaw.O
APEXMalicious
ClamAVWin.Trojan.Ulise-7135679-1
KasperskyTrojan.Win32.NetWire.bh
BitDefenderTrojan.GenericKD.48560802
NANO-AntivirusTrojan.Win32.Dapato.fbcjkw
AvastWin32:RATX-gen [Trj]
TencentTrojan.Win32.Netwire.wa
EmsisoftTrojan.GenericKD.48560802 (B)
F-SecureTrojan.TR/Spy.Weecnaw.vfmhg
DrWebBackDoor.Wirenet.543
TrendMicroTSPY_WEECNAW.SMC
McAfee-GW-EditionBehavesLike.Win32.Generic.th
SophosMal/AuItInj-A
IkarusTrojan.Win32.Autoit
GDataTrojan.GenericKD.48560802
AviraTR/Spy.Weecnaw.vfmhg
Antiy-AVLGrayWare/Autoit.ShellCode.a
XcitiumTrojWare.Win32.TrojanSpy.Loyeetro.A@8lofxp
ArcabitTrojan.Generic.D2E4FAA2
ViRobotTrojan.Win.Z.Weecnaw.1391008
ZoneAlarmTrojan.Win32.NetWire.bh
MicrosoftVirTool:Win32/AutInject!rfn
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/AutoInj.Exp
Acronissuspicious
McAfeeArtemis!2D33695D79AD
MAXmalware (ai score=81)
VBA32Trojan.NetWire
MalwarebytesWeecnaw.Spyware.Stealer.DDS
PandaTrj/Chgt.AC
ZonerTrojan.Win32.124944
TrendMicro-HouseCallTSPY_WEECNAW.SMC
RisingBackdoor.NetWire!1.B84F (CLASSIC)
YandexTrojan.GenAsa!wuPhUbOs0XU
MaxSecureTrojan.Malware.300983.susgen
FortinetAutoIt/Injector.DWD!tr
BitDefenderThetaGen:NN.ZexaF.36196.iyW@aqHZL8
AVGWin32:RATX-gen [Trj]
Cybereasonmalicious.d79adf
DeepInstinctMALICIOUS

How to remove Weecnaw.Spyware.Stealer.DDS?

Weecnaw.Spyware.Stealer.DDS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment