Malware

Win32/Woool.F (file analysis)

Malware Removal

The Win32/Woool.F is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Woool.F virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Checks for the presence of known windows from debuggers and forensic tools
  • Crashed cuckoomon during analysis. Report this error to the Github repo.

Related domains:

www.68cs.com
a.75cs.com
b.75cs.com
c.75cs.com
AB1.75cs.com

How to determine Win32/Woool.F?


File Info:

crc32: CA46AFD1
md5: 27f19630de9ecc0b20cce1ff7a9d029e
name: 27F19630DE9ECC0B20CCE1FF7A9D029E.mlw
sha1: f038f791779566ada1902f868bd1f4d0a49fbe3c
sha256: df80ecfbaafec749618096cb619cacedcbf084706b94d79da82ec1c044d487d8
sha512: 3eba5ba4cac759f9efd344efdcdb5b2da2ae6540c79776284046d30451af64878a60017dd573d09528b615bbdcefd9b8e8972821313fb8f61933f86f185539a1
ssdeep: 49152:lVJv0NSm3hJFNRWiUeyO4JrgRn9T6+BpsYbsbHwGHV8Y4+YPQrQifMzVhQF:Xl0hhDNRWHJrcnJ6+RYHVnQi0zVhQF
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName: x3000
FileVersion: 1.1.0.0
CompanyName:
LegalTrademarks:
Comments: x51e4x51f0x5de5x4f5cx5ba4x8363x8a89x51fax54c1
ProductName: x51e4x51f0x767bx9646x5668
ProductVersion: Pnoenixerx3000
FileDescription: x3000
OriginalFilename:
Translation: 0x0804 0x03a8

Win32/Woool.F also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Rootkit.22035
MicroWorld-eScanTrojan.GenericKD.45659352
CAT-QuickHealTrojan.Generic
Qihoo-360Generic/HEUR/QVM16.0.D6C1.Malware.Gen
ALYacTrojan.GenericKD.45659352
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
SangforMalware
K7AntiVirusTrojan ( 004f01851 )
BitDefenderTrojan.GenericKD.45659352
K7GWTrojan ( 004f01851 )
Cybereasonmalicious.177956
BitDefenderThetaGen:NN.ZexaF.34804.5U3@aCohgcib
CyrenW32/Banload.B.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Woool.cb2fb7be
RisingTrojan.Generic@ML.100 (RDMK:LCOmFmPMiYYWvVDywbKH6w)
Ad-AwareTrojan.GenericKD.45659352
EmsisoftTrojan.GenericKD.45659352 (B)
ComodoMalware@#2x96alrkfz2tt
F-SecureTrojan.TR/Spy.Banker.Gen7
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
FireEyeGeneric.mg.27f19630de9ecc0b
SophosMal/Generic-S
IkarusTrojan.Win32.Woool
AviraTR/Spy.Banker.Gen7
MAXmalware (ai score=86)
MicrosoftVirTool:MSIL/CryptInject
ArcabitTrojan.Generic.D2B8B4D8
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan.PSE.1EKLUME
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R358237
Acronissuspicious
McAfeeArtemis!27F19630DE9E
VBA32TScope.Trojan.Delf
MalwarebytesAutoKMS.HackTool.Patcher.DDS
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Woool.F
TrendMicro-HouseCallTROJ_GEN.R035H0CAS21
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_95%
FortinetW32/Woool.C!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Malware.121218.susgen

How to remove Win32/Woool.F?

Win32/Woool.F removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment