Trojan

Woool.Trojan.Downloader.DDS malicious file

Malware Removal

The Woool.Trojan.Downloader.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Woool.Trojan.Downloader.DDS virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • The sample wrote data to the system hosts file.

How to determine Woool.Trojan.Downloader.DDS?


File Info:

name: 1DD5E52BCC2AA506EDD7.mlw
path: /opt/CAPEv2/storage/binaries/04b56ea8fac0607cbce3c249ec5cf390175fb311dd3089c21836a85cefecd79e
crc32: 65E0A829
md5: 1dd5e52bcc2aa506edd7364adccc5074
sha1: be865af3a9562a3808f49c0da6035d7776d63201
sha256: 04b56ea8fac0607cbce3c249ec5cf390175fb311dd3089c21836a85cefecd79e
sha512: 7ff12263ca61f12d935da140fd300534bf1384074fc661d7db8afa25c4a9bdd3e83088ae607955e4101484a59bd2a525110f30aeab0ece9d2b2e6b8d972eaf34
ssdeep: 196608:S24EwwFAYm5Ch1QLw/Jxtdg/XY3AqBESYwuZhWxRWOgrJ2JayEHVleu+hzdMzG65:Z46FbV12wBx/g/RqBCZZMfGJsEHVleuf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T150C633270A538377D8484D7E6FCE3B0448DFEE839571656A58800CEAD6A358A7DCE363
sha3_384: bb0ee2e6ea6fbbad659d94b19dc6f733f1efd47ae8fa48de5cd6a60dc000b6f31ab4896e29f3c0d7a5d91cb1fb1cbd56
ep_bytes: 6820cfc36fe8c59860ffb1bba4644716
timestamp: 2022-01-05 08:41:59

Version Info:

CompanyName: 蓝天工作室
FileDescription: 蓝天登录器
FileVersion: 1.0.0.0
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName: 蓝天登陆器
ProductVersion: Phoenixer
Comments: 蓝天工作室荣誉出品
Translation: 0x0804 0x03a8

Woool.Trojan.Downloader.DDS also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Fragtor.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Fragtor.70166
FireEyeGeneric.mg.1dd5e52bcc2aa506
ALYacGen:Variant.Fragtor.70166
MalwarebytesWoool.Trojan.Downloader.DDS
VIPREGen:Variant.Fragtor.70166
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00585f6e1 )
AlibabaTrojan:Win32/GenKryptik.9a26e46e
K7GWTrojan ( 00585f6e1 )
BitDefenderThetaGen:NN.ZexaF.34796.@V3@a4Y6t2jb
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/GenKryptik.FIPW
TrendMicro-HouseCallTROJ_GEN.R002H0CKH22
BitDefenderGen:Variant.Fragtor.70166
CynetMalicious (score: 100)
AvastWin32:DropperX-gen [Drp]
TencentWin32.Trojan.Crypt.Ozfl
Ad-AwareGen:Variant.Fragtor.70166
EmsisoftGen:Variant.Fragtor.70166 (B)
ZillyaTrojan.OnLineGames.Win32.246417
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
APEXMalicious
JiangminTrojan.PSW.OnLineGames.bvd
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.GenKryptik
ArcabitTrojan.Fragtor.D11216
GDataGen:Variant.Fragtor.70166
GoogleDetected
AhnLab-V3Trojan/Win.Trojan-gen.C4884839
MAXmalware (ai score=84)
IkarusTrojan.Win32.Woool
RisingTrojan.Kryptik!8.8 (TFE:5:GO6J4CzD0G)
YandexTrojan.PWS.OnLineGames!txcF+y2+1II
SentinelOneStatic AI – Malicious PE
FortinetW32/PossibleThreat
AVGWin32:DropperX-gen [Drp]

How to remove Woool.Trojan.Downloader.DDS?

Woool.Trojan.Downloader.DDS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment