Malware

What is “Win32/Injector.DFED”?

Malware Removal

The Win32/Injector.DFED is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.DFED virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the shellcode patterns malware family
  • Attempts to access Bitcoin/ALTCoin wallets
  • Harvests credentials from local FTP client softwares
  • Installs WinPCAP
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Injector.DFED?


File Info:

name: 2CB9FA3B936CAC6DBCF9.mlw
path: /opt/CAPEv2/storage/binaries/8ae5037ce6e8b32da21acd1fce880749a922af15564b1f073cfa63c464e905cd
crc32: 6EDB2EEB
md5: 2cb9fa3b936cac6dbcf9e167385af81f
sha1: 34d1b9bf819aaae1fbf822f315fe5fee3ef58819
sha256: 8ae5037ce6e8b32da21acd1fce880749a922af15564b1f073cfa63c464e905cd
sha512: 4ca835dd2d6b97918138b48001ce1bfaac301f687c28335ce3e67ce3468975409ad5d61f7561d15dabc26d1cac6074f522e0fd63c2c060ad3510d7670d901a49
ssdeep: 24576:0R011EpJuN6qz0/oRCtOCQjpKS9Fm9lNMeMAmUqu+:0RWEpJuZz2RpQlklX6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F835233071B97F66D092817426A7ED2BED5B2AB42B0F25C3AB661E6B03217875720F41
sha3_384: b4ab785b7a3b66ffa94dc95550e1976edf5da94ce042a41f814b9b7f686e544567f46e717ed7c7629c4c2910dc08fc29
ep_bytes: 558bec6aff6808992000680089200064
timestamp: 2016-08-30 06:47:37

Version Info:

Comments:
CompanyName:
FileDescription: record
FileVersion: 1, 0, 0, 1
InternalName: record
LegalCopyright: Copyright ? 2016
LegalTrademarks:
OriginalFilename: record.exe
PrivateBuild:
Pro邐uctName: record
ProductVersion: 1, 0, 0, 1
SpecialBuild:
Translation: 0x040a 0x04e5

Win32/Injector.DFED also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
AVGWin32:Evo-gen [Trj]
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Ransom.Seven.18
FireEyeGeneric.mg.2cb9fa3b936cac6d
CAT-QuickHealTrojanDropper.Bunitu.S11426
SkyhighPWSZbot-FAVD!2CB9FA3B936C
McAfeePWSZbot-FAVD!2CB9FA3B936C
Cylanceunsafe
ZillyaTrojan.Inject.Win32.198930
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 004f74791 )
AlibabaVirTool:Win32/CeeInject.a4df9ba6
K7GWTrojan ( 004f74791 )
Cybereasonmalicious.b936ca
BaiduWin32.Trojan.Injector.jj
SymantecDownloader.Upatre
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.DFED
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Bunitu-7394346-1
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ransom.Seven.18
NANO-AntivirusTrojan.Win32.Dwn.egytxt
AvastWin32:Evo-gen [Trj]
TencentMalware.Win32.Gencirc.10b11fb2
EmsisoftGen:Variant.Ransom.Seven.18 (B)
F-SecureHeuristic.HEUR/AGEN.1339454
DrWebTrojan.DownLoader22.57121
VIPREGen:Variant.Ransom.Seven.18
Trapminemalicious.high.ml.score
SophosMal/Zbot-UM
SentinelOneStatic AI – Suspicious PE
JiangminBackdoor.Hlux.bol
VaristW32/S-abfd3645!Eldorado
AviraHEUR/AGEN.1339454
Antiy-AVLTrojan/Win32.AGeneric
Kingsoftmalware.kb.a.1000
MicrosoftTrojan:Win32/Dynamer!ac
XcitiumTrojWare.Win32.Matsnu.C@6lh75k
ArcabitTrojan.Ransom.Seven.18
ViRobotTrojan.Win32.Agent.1090007
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Ransom.Seven.18
GoogleDetected
AhnLab-V3Trojan/Win32.MDA.R188247
VBA32SScope.Malware-Cryptor.Hlux
ALYacGen:Variant.Ransom.Seven.18
MAXmalware (ai score=80)
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/CI.A
RisingDropper.Bunitu!8.A59 (TFE:3:mTLRGqOuilU)
YandexTrojan.GenAsa!hwDAooVt5QQ
IkarusTrojan.Win32.Injector
FortinetW32/Injector.DFPC!tr
BitDefenderThetaGen:NN.ZexaF.36802.cz3@a8EtbCkj
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Injector.DFED?

Win32/Injector.DFED removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment