Malware

Win32/Ipamor.G (file analysis)

Malware Removal

The Win32/Ipamor.G is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Ipamor.G virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • Authenticode signature is invalid
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/Ipamor.G?


File Info:

name: 4FC8C55476020FBF6F66.mlw
path: /opt/CAPEv2/storage/binaries/2a5a8974e9f9acfb16fe6f0ea11eb5a7f28677975bad2518f94db36dbeddb52e
crc32: FAB12D2A
md5: 4fc8c55476020fbf6f664beb0cce815e
sha1: 9031d9815355bc4db1a4139bcb5c6f2f6e2296f9
sha256: 2a5a8974e9f9acfb16fe6f0ea11eb5a7f28677975bad2518f94db36dbeddb52e
sha512: a1c807a428aa163f65ae656e3787c136152770ffc4b4cd5b01d496b623204fe111177d2dc744a2309038b73cce11e71006502405647c8b763453a84048e10bcb
ssdeep: 3072:wQVG4urzuVGp8rojCJ37yMWslb5r8P+0kizv6ODHt/OE9sP/:woezrKMU5WslyPlxPDHt/OEO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T139E35A133BE1C177C28602745D60FBA66BBBFE320A60D617B7503B4E6EB1596CD1860B
sha3_384: 2be08d828c4fbb568ee8e756704a08deb8fcd056f6275a2c526fa617a454b093ff4066e1f523919f33f164467136e615
ep_bytes: 558bec6aff6820b2400068c470400064
timestamp: 2002-08-01 06:57:54

Version Info:

0: [No Data]

Win32/Ipamor.G also known as:

BkavW32.FamVT.LpamorA.Trojan
LionicTrojan.Win32.Daws.mzM4
MicroWorld-eScanGen:Trojan.Backdoor2.jyZ@aK0BAidb
ClamAVWin.Trojan.Iparm-1
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacGen:Trojan.Backdoor2.jyZ@aK0BAidb
Cylanceunsafe
VIPREGen:Trojan.Backdoor2.jyZ@aK0BAidb
SangforSuspicious.Win32.Save.ins
K7AntiVirusVirus ( 0040f5921 )
AlibabaVirus:Win32/Ipamor.19c5
K7GWVirus ( 0040f5921 )
Cybereasonmalicious.476020
BaiduWin32.Virus.Ipamor.b
VirITTrojan.Win32.SHeur4.BZZF
CyrenW32/Ipamor.CVBC-7790
SymantecW32.HLLP.Ipamor
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Ipamor.G
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Scar.okbl
BitDefenderGen:Trojan.Backdoor2.jyZ@aK0BAidb
NANO-AntivirusVirus.Win32.Ipamor.cmck
AvastWin32:Parmo [Inf]
TencentVirus.Win32.Viking.aak
EmsisoftGen:Trojan.Backdoor2.jyZ@aK0BAidb (B)
F-SecureTrojan.TR/Agent.arue
DrWebWin32.HLLP.Iparmor.35858
ZillyaVirus.Ipamor.Win32.6
TrendMicroTROJ_GEN.R002C0CEG23
McAfee-GW-EditionBehavesLike.Win32.Ipamor.cm
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.4fc8c55476020fbf
SophosW32/Ipamor-B
SentinelOneStatic AI – Malicious PE
GDataWin32.Virus.Ipamor-Main.A
JiangminTrojan.Generic.ghobc
AviraTR/Agent.arue
Antiy-AVLVirus/Win32.Ipamor.g
XcitiumVirus.Win32.Ipamor.G@8j5juk
ArcabitTrojan.Backdoor2.E7683F
ViRobotWin32.Ipamor.A
ZoneAlarmTrojan.Win32.Scar.okbl
MicrosoftVirus:Win32/Ipamor.C
GoogleDetected
AhnLab-V3Win32/Ipamor.B.X932
Acronissuspicious
McAfeeW32/Ipamor
MAXmalware (ai score=87)
VBA32Virus.Facepalm.21207
MalwarebytesIpamor.Trojan.RAT.DDS
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0CEG23
RisingWin32.MSWDM.b (CLASSIC)
YandexTrojan.GenAsa!qp+sKG55Fu8
IkarusVirus.Win32.Ipamor.b
MaxSecureVirus.Ipamor.Gen
FortinetW32/Ipamor.D
BitDefenderThetaAI:Packer.963408E81F
AVGWin32:Parmo [Inf]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Ipamor.G?

Win32/Ipamor.G removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment