Malware

Win32/VB.SOR (file analysis)

Malware Removal

The Win32/VB.SOR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/VB.SOR virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Detected script timer window indicative of sleep style evasion
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • A scripting utility was executed
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
dngj.upzxt.com

How to determine Win32/VB.SOR?


File Info:

crc32: EBDEDD51
md5: dfc3cb1b60e1ecec5e1501c943e5c961
name: DFC3CB1B60E1ECEC5E1501C943E5C961.mlw
sha1: e06b91e2a733495c3cf6d6b819322103c9162f0d
sha256: 3f58fe1e73cb85e74736479f5303a6d93e82880a3ec8232122fcdfca76c0358b
sha512: 088635e5b695e0180e4865681a26c363d75ec44875e00c0e87766489c3b8f617033cc2d96bf794fc420dccf666e57ffbddf9c68ba307f7b5eaa74b17fbc3ef7b
ssdeep: 384:eC3qmKyl+qzM6xvge+FOZUaWAO4VsL+9u8bzza3D3W4FP:eIpQqz1vgaGaWJ4VsLT7F
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0804 0x04b0
InternalName: jk
FileVersion: 9.00.0009
CompanyName: aaaa
ProductName: x5de5x7a0b1
ProductVersion: 9.00.0009
FileDescription: update
OriginalFilename: jk.exe

Win32/VB.SOR also known as:

K7AntiVirusP2PWorm ( 0055abdc1 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader25.35648
CynetMalicious (score: 85)
ALYacGen:Variant.Zusy.255797
CylanceUnsafe
SangforRiskware.Win32.Agent.ky
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Masson.ffb78dbb
K7GWP2PWorm ( 0055abdc1 )
Cybereasonmalicious.b60e1e
CyrenW32/Trojan.BCKP-0959
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/VB.SOR
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan-Downloader.Win32.Generic
BitDefenderGen:Variant.Zusy.255797
NANO-AntivirusTrojan.Win32.VB.ibnceu
ViRobotTrojan.Win32.Z.Zusy.40960.AFK
MicroWorld-eScanGen:Variant.Zusy.255797
TencentMalware.Win32.Gencirc.10ce0fcd
Ad-AwareGen:Variant.Zusy.255797
SophosMal/Generic-R + Mal/Emogen-F
ComodoTrojWare.Win32.TrojanDownloader.VB.PMEA@4rev5s
F-SecureTrojan.TR/Dropper.VB.Gen7
BitDefenderThetaAI:Packer.B38D5E311F
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R01FC0PK120
McAfee-GW-EditionBehavesLike.Win32.Trojan.pt
FireEyeGeneric.mg.dfc3cb1b60e1ecec
EmsisoftGen:Variant.Zusy.255797 (B)
JiangminTrojanDownloader.Generic.biad
AviraTR/Dropper.VB.Gen7
Antiy-AVLTrojan/Win32.VB
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Masson.A!rfn
ArcabitTrojan.Zusy.D3E735
ZoneAlarmHEUR:Trojan-Downloader.Win32.Generic
GDataGen:Variant.Zusy.255797
AhnLab-V3Downloader/Win32.Agent.R210836
McAfeeDownloader-FBYH!DFC3CB1B60E1
MAXmalware (ai score=80)
VBA32TScope.Trojan.VB
MalwarebytesTrojan.Downloader
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R01FC0PK120
RisingDownloader.Generic!8.141 (CLOUD)
YandexTrojan.VB!bzef65b9mjA
IkarusTrojan.Win32.VB
MaxSecureTrojan.Malware.7175239.susgen
FortinetW32/VB.SOR!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Generic/Trojan.Dropper.890

How to remove Win32/VB.SOR?

Win32/VB.SOR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment