Worm

About “Worm.Rebhip” infection

Malware Removal

The Worm.Rebhip is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Rebhip virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Creates a copy of itself
  • Creates known SpyNet mutexes and/or registry changes.
  • Anomalous binary characteristics

How to determine Worm.Rebhip?


File Info:

crc32: 3F88D023
md5: 875f2eebac385c8d09d9863e39dcb52f
name: 875F2EEBAC385C8D09D9863E39DCB52F.mlw
sha1: 3d8d021660d21339f4f2ad2b5f3a477a03b7625e
sha256: 35fd77f4b27cbb37c4cab6d90a56d7ad2f906298d1f225990a34a1446047e6d8
sha512: 52045323059a231f4b255f27890063092e1663037ac83ef541cfcb21b7d3965d05ecc47639493da98458713c27402ef78c6b502ee1b87285f3d86267a034cb47
ssdeep: 6144:0MIF7KMVHPnAtb7HTHrebyQvJu7h+ncV:0bF7lH/AprGyQBu7h+ncV
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Worm.Rebhip also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 001987931 )
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Autoruner.25074
CynetMalicious (score: 100)
CAT-QuickHealWorm.Rebhip.Z.mue
ALYacTrojan.Agent.AROC
CylanceUnsafe
ZillyaTrojan.Llac.Win32.29703
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanSpy:Win32/Bublik.e4304570
K7GWTrojan ( 001987931 )
Cybereasonmalicious.bac385
BaiduWin32.Trojan.Agent.co
CyrenW32/Rebhip.B.gen!Eldorado
SymantecW32.Spyrat
ESET-NOD32Win32/Spatet.I
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Ag-1
KasperskyTrojan.Win32.Bublik.elhu
BitDefenderTrojan.Agent.AROC
NANO-AntivirusTrojan.Win32.Llac.dsnuug
ViRobotTrojan.Win32.A.Llac.296448[UPX]
SUPERAntiSpywareTrojan.Agent/Gen-FraudLoad
MicroWorld-eScanTrojan.Agent.AROC
Ad-AwareTrojan.Agent.AROC
SophosML/PE-A + Mal/Behav-328
ComodoWorm.Win32.AutoRun.BDZ@4obei9
F-SecureTrojan.TR/Crypt.CFI.Gen
BitDefenderThetaAI:Packer.06262E031B
VIPRETrojan.Win32.Llac.bdm (v)
TrendMicroTSPY_LLAC.SM
McAfee-GW-EditionBehavesLike.Win32.Ransomware.dc
FireEyeGeneric.mg.875f2eebac385c8d
EmsisoftTrojan.Agent.AROC (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Llac.kyz
WebrootW32.Trojan.Gen
AviraTR/Crypt.CFI.Gen
eGambitRAT.CyberGate
Antiy-AVLTrojan/Generic.ASBOL.2C2D
MicrosoftTrojanSpy:Win32/Rebhip.C
GridinsoftTrojan.Win32.Agent.dg
ArcabitTrojan.Agent.AROC
AegisLabTrojan.Win32.Llac.mzjh
ZoneAlarmTrojan.Win32.Bublik.elhu
GDataTrojan.Agent.AROC
TACHYONTrojan/W32.DP-Hijack.303616
AhnLab-V3Trojan/Win32.Llac.R856
Acronissuspicious
McAfeeGenericRXAA-AA!875F2EEBAC38
MAXmalware (ai score=100)
VBA32Trojan.Bublik
MalwarebytesWorm.Rebhip
PandaTrj/Inject.JQ
TrendMicro-HouseCallTSPY_LLAC.SM
RisingWorm.Rebhip!1.A338 (CLASSIC)
IkarusTrojan.Win32.Llac
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Spatet.TRR!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Worm.Rebhip?

Worm.Rebhip removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment