Malware

Win32/Death.27.C.UPX (file analysis)

Malware Removal

The Win32/Death.27.C.UPX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Death.27.C.UPX virus can do?

  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Creates an autorun.inf file
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz

How to determine Win32/Death.27.C.UPX?


File Info:

crc32: 3DBCB190
md5: 904b572db5db2b9402250984984bc686
name: 904B572DB5DB2B9402250984984BC686.mlw
sha1: d4cf1b64ee8bf1d96bf22ae0881c90aa77a5f5bc
sha256: 318d1785cd466fcf231c2d2d9c88f12901e79fdb0d786a4a1e107ee6abe5ef73
sha512: 5d4ba42b3696b5413b60e9c1e67fdee5a96ae0793ddb2bdfdefb1bed2a6610483ff5c46844e33d4fe564b1aad0802192f66d6829dd83045f378e5d44f9752c4c
ssdeep: 6144:B0UZ7RSZP7xxtV1Z0FaVLn3nu50Ut+tsu5cTzu+:6uwPV51Z0FaVD3u50U05iu+
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Win32/Death.27.C.UPX also known as:

K7AntiVirusTrojan ( 7000000f1 )
LionicTrojan.Win32.Death.m!c
Elasticmalicious (high confidence)
DrWebBackDoor.Death.27
CynetMalicious (score: 100)
ALYacTrojan.Generic.7553379
CylanceUnsafe
ZillyaBackdoor.Death.Win32.167
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.db5db2
CyrenW32/Death.EMTP-6902
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Death.27.C.UPX
ZonerProbably Heur.ExeHeaderH
APEXMalicious
AvastFileRepMalware
ClamAVWin.Trojan.Death-6
KasperskyBackdoor.Win32.Death.25.k
BitDefenderTrojan.Generic.7553379
NANO-AntivirusTrojan.Win32.Death-25.gzyu
MicroWorld-eScanTrojan.Generic.7553379
TencentWin32.Backdoor.Death.Hqbj
Ad-AwareTrojan.Generic.7553379
SophosTroj/Death-27
ComodoBackdoor.Win32.Death.27.C@1tqi
BitDefenderThetaAI:Packer.4028503321
TrendMicroBKDR_DEATH.A
McAfee-GW-EditionBackDoor-FP.svr
FireEyeGeneric.mg.904b572db5db2b94
EmsisoftTrojan.Generic.7553379 (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor/Death.e
AviraTR/Dldr.Delphi.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.3723D
MicrosoftBackdoor:Win32/Death
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Generic.7553379
AhnLab-V3Trojan/Win32.Xema.C22019
McAfeeBackDoor-FP.svr
MAXmalware (ai score=87)
VBA32Backdoor.Death
PandaBck/Death.27.D
TrendMicro-HouseCallBKDR_DEATH.A
RisingBackdoor.Death.mkn (CLASSIC)
YandexTrojan.GenAsa!cB6obvBAu0Q
IkarusBackdoor.Win32.Death
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Death_27.A!tr.bdr
AVGFileRepMalware

How to remove Win32/Death.27.C.UPX?

Win32/Death.27.C.UPX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment