Malware

Win32/Socks.NAL malicious file

Malware Removal

The Win32/Socks.NAL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Socks.NAL virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • A process attempted to delay the analysis task by a long amount of time.
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings

How to determine Win32/Socks.NAL?


File Info:

name: 1C320C3AD5B380901046.mlw
path: /opt/CAPEv2/storage/binaries/89d4cd03a63a3090bfde0528be664892c135f58145e9ddfb06a21ab65f3ebb79
crc32: 9296A21C
md5: 1c320c3ad5b380901046f9428a8ae706
sha1: 755e1531536e1cdfab7e0924b8536e161dba1c31
sha256: 89d4cd03a63a3090bfde0528be664892c135f58145e9ddfb06a21ab65f3ebb79
sha512: ee276d3baabce5a5e0e916bce9d9e63125413c3f4fa7e97969e4cc70738b13b81213a2ac3825cdec940bef37d820d486322275585ba41767ff68ffd608f53f12
ssdeep: 196608:47effIPEsy58doQaTxLhQyZbIly38doQalArdfehQM9rdQyZbnE993V7nWBKnybv:47effIPEsy58doQaTxLhQyZbIly38doP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F27623B9E31E6CA0FF3D4A76937CBA25D918FC425EB8F8AF784D5BD521C1A54C892040
sha3_384: 99c5348063cabd64da3b143eabc89975530380dea32276b499b0f8b44d106ca0d749c863c53a5340ff2e96c74a6b49f9
ep_bytes: 60be002042008dbe00f0fdff5783cdff
timestamp: 2008-03-14 10:18:02

Version Info:

0: [No Data]

Win32/Socks.NAL also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Crypt.AI
FireEyeGeneric.mg.1c320c3ad5b38090
CAT-QuickHealTrojan.MauvaiseRI.S5244566
ALYacTrojan.Crypt.AI
CylanceUnsafe
VIPREWorm.Win32.Socks.bt (fs)
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004ac0a31 )
BitDefenderTrojan.Crypt.AI
K7GWTrojan ( 004ac0a31 )
CrowdStrikewin/malicious_confidence_70% (D)
BaiduWin32.Trojan-Downloader.Agent.au
VirITTrojan.Win32.Agent.BME
CyrenW32/Socks.A.gen!Eldorado
SymantecDownloader
ESET-NOD32a variant of Win32/Socks.NAL
APEXMalicious
ClamAVWin.Worm.Socks-9892592-0
KasperskyWorm.Win32.Socks.anm
NANO-AntivirusTrojan.Win32.Pace.ihwkc
ViRobotWorm.Win32.Socks.12800.I
RisingTrojan.Agent!1.6618 (RDMK:cmRtazqCpICCr9nUFTlytZHysf//)
Ad-AwareTrojan.Crypt.AI
EmsisoftTrojan.Crypt.AI (B)
ComodoWorm.Win32.Agent.~CY@2v635
DrWebTrojan.PWS.Pace
ZillyaWorm.Socks.Win32.691
TrendMicroWORM_SOCKS.BL
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
SophosML/PE-A + Troj/Agent-THB
IkarusTrojan-Downloader.Win32.Small
GDataTrojan.Crypt.AI
JiangminWorm/Socks.aa
AviraTR/PSW.Agent.nhg
MAXmalware (ai score=84)
Antiy-AVLTrojan/Generic.ASMalwS.743D8
KingsoftHeur.SSC.2725271.0010.(kcloud)
ArcabitTrojan.Crypt.AI
ZoneAlarmWorm.Win32.Socks.anm
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/FakeAV52.Gen
Acronissuspicious
McAfeegeneric!bg.f
VBA32BScope.TrojanDownloader.Small
MalwarebytesMalware.AI.4106911760
PandaTrj/Downloader.TCG
TrendMicro-HouseCallWORM_SOCKS.BL
TencentMalware.Win32.Gencirc.10b0e699
YandexTrojan.GenAsa!Yuu3lqrxeJg
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Socks.NAL!tr
BitDefenderThetaAI:Packer.97B3962E1C
AVGWin32:Trojan-gen
Cybereasonmalicious.ad5b38
AvastWin32:Trojan-gen
MaxSecureWorm.W32.Socks.S

How to remove Win32/Socks.NAL?

Win32/Socks.NAL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment