Trojan

Win32/TrojanDownloader.Delf.DCE (file analysis)

Malware Removal

The Win32/TrojanDownloader.Delf.DCE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDownloader.Delf.DCE virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Attempts to create or modify system certificates
  • Anomalous binary characteristics

Related domains:

discord.com
cdn.discordapp.com

How to determine Win32/TrojanDownloader.Delf.DCE?


File Info:

crc32: 697EF81E
md5: 45e2bbc7c5df2378a2bd2217d6afddf2
name: 45E2BBC7C5DF2378A2BD2217D6AFDDF2.mlw
sha1: 161bf22fae724e741642bde5b73c458c45a2b0de
sha256: d54847c7831d92a014c603f004d75828da72ed8f9d270a18023706f1bb375415
sha512: 583a115bcc60d492b5288580124c3ff11f68aeefbe59e713aa770334eebaa98eae81ab4fc29ac996eddbcd1d67c61d6a0e2865f7aa00f765ebcbb7c9709c2399
ssdeep: 49152:LR/ovVcOM1pJTYBzQ0DZVhlZfyiSCyiSV/CznFw9:LRmi/YBzZDZVLpi
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 1998-2017 Mark Russinovich
InternalName: Process Explorer
FileVersion: 16.21
CompanyName: Sysinternals - www.sysinternals.com
LegalTrademarks: Copyright (C) 1998-2017 Mark Russinovich
ProductName: Process Explorer
ProductVersion: 16.21
FileDescription: Sysinternals Process Explorer
OriginalFilename: Procexp.exe
Translation: 0x0409 0x04e4

Win32/TrojanDownloader.Delf.DCE also known as:

MicroWorld-eScanGen:Variant.Bulz.49339
FireEyeGeneric.mg.45e2bbc7c5df2378
ALYacGen:Variant.Bulz.49339
CylanceUnsafe
K7AntiVirusTrojan ( 7000000f1 )
BitDefenderGen:Variant.Bulz.49339
K7GWTrojan ( 7000000f1 )
BitDefenderThetaGen:NN.ZelphiCO.34658.jI3@aGLArXfi
SymantecML.Attribute.HighConfidence
APEXMalicious
Ad-AwareGen:Variant.Bulz.49339
McAfee-GW-EditionFareit-FZO!45E2BBC7C5DF
EmsisoftGen:Variant.Bulz.49339 (B)
SentinelOneStatic AI – Suspicious PE
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Bulz.DC0BB
GDataGen:Variant.Bulz.49339
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R347077
McAfeeFareit-FZO!45E2BBC7C5DF
MAXmalware (ai score=89)
VBA32Malware-Cryptor.Limpopo
MalwarebytesTrojan.MalPack.SMY.Generic
ESET-NOD32Win32/TrojanDownloader.Delf.DCE
IkarusTrojan.Inject
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Win32/TrojanDownloader.Delf.DCE?

Win32/TrojanDownloader.Delf.DCE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment