Malware

Win32/Packed.Obsidium.KJ (file analysis)

Malware Removal

The Win32/Packed.Obsidium.KJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Packed.Obsidium.KJ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Checks for the presence of known windows from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects VirtualBox through the presence of a device
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering
  • Collects information to fingerprint the system

How to determine Win32/Packed.Obsidium.KJ?


File Info:

name: BF7620822808E50E138D.mlw
path: /opt/CAPEv2/storage/binaries/9ac631abb51ef59914b5b32b4e70dacf76b45eea3cbaddd85f4a8bdb4db6f79a
crc32: 7F4541B1
md5: bf7620822808e50e138d31a695791f4c
sha1: 5da02e4063cb4a3233028f7ee6d7b10c101c30c0
sha256: 9ac631abb51ef59914b5b32b4e70dacf76b45eea3cbaddd85f4a8bdb4db6f79a
sha512: 4a4031463cedab0bbcfdcb7dc2180b673f28c319b31c8a4181bb112bae6b3e75ab738d5ba301dbdc10bb7110cf34f8c17fd289c07158988b423c329bc9636b02
ssdeep: 12288:CQIaSN7jIuubkpYYWm8tB86lcwg4KVKBHNub3iM+4lE8qbB/tmYT1q1:CQs7jI5lg8tBnlcL3VKBHr4S8qhtmYw1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1ADB42320F5705A77C2EF72BF5A3BB815626C4A61CDF9008CAB20F45A05E666CC87DD2C
sha3_384: 4b08efce7332c8aff30b8f4aa635945cffec78ba63cf7fb80768be8f1cd0e672d05efb14bd8427dd5240354adb76bf1b
ep_bytes: eb0539b61cf8e650eb04f6a248c2e811
timestamp: 2022-08-24 17:13:14

Version Info:

FileDescription: Description of my application
InternalName: myfile.exe
OriginalFilename: myfile.exe
CompanyName: My Company
LegalCopyright: © My Company. All rights reserved.
ProductName: My App
FileVersion: 1.0.0.0
ProductVersion: 1.0.0.0
Translation: 0x0409 0x04b0

Win32/Packed.Obsidium.KJ also known as:

BkavW32.AIDetect.malware1
MicroWorld-eScanGen:Variant.Midie.113896
FireEyeGeneric.mg.bf7620822808e50e
ALYacGen:Variant.Midie.113896
MalwarebytesRiskWare.FlyStudio
K7AntiVirusTrojan ( 005944981 )
K7GWTrojan ( 005944981 )
Cybereasonmalicious.063cb4
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.Obsidium.KJ
ZonerProbably Heur.ExeHeaderL
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Banker.Win32.Bandra.gen
BitDefenderGen:Variant.Midie.113896
RisingTrojan.Bandra!8.13457 (TFE:5:FvCYJFKTGUR)
Ad-AwareGen:Variant.Midie.113896
EmsisoftGen:Variant.Midie.113896 (B)
F-SecureHeuristic.HEUR/AGEN.1216961
VIPREGen:Variant.Midie.113896
Trapminemalicious.high.ml.score
SophosML/PE-A
IkarusTrojan.Win32.Obsidium
AviraHEUR/AGEN.1216961
MAXmalware (ai score=84)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ArcabitTrojan.Midie.D1BCE8
ZoneAlarmHEUR:Trojan-Banker.Win32.Bandra.gen
GDataGen:Variant.Midie.113896
GoogleDetected
AhnLab-V3Malware/Win.Generic.C5171211
Acronissuspicious
VBA32BScope.Trojan.Tiggre
CylanceUnsafe
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
BitDefenderThetaGen:NN.ZexaF.34606.Hq1@aud7Grii
AVGWin32:Evo-gen [Trj]
AvastWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Win32/Packed.Obsidium.KJ?

Win32/Packed.Obsidium.KJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment