Worm

Worm.Win32.Vobfus.eepy (file analysis)

Malware Removal

The Worm.Win32.Vobfus.eepy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.Vobfus.eepy virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Worm.Win32.Vobfus.eepy?


File Info:

name: EF85F36E0E8E3691732F.mlw
path: /opt/CAPEv2/storage/binaries/650c5c5cfaba65f7c4b43d2363896ac5dfa2bca3b8743565fd3a2ece4fff2396
crc32: 6D40281D
md5: ef85f36e0e8e3691732f5f7d445c1d81
sha1: ee2f35e80a47219ebf77185bbcdb33850debe66b
sha256: 650c5c5cfaba65f7c4b43d2363896ac5dfa2bca3b8743565fd3a2ece4fff2396
sha512: 70a06fc366d20dc50cb2b11bb50233e524116d74e7d268bb10f13af9b6f78df8cc10bcc52d1ece745fe84e4a1b1c2f26899fdef67fe54cceb12e5a3e6d248b87
ssdeep: 3072:Qa4/w3vu3XuIcN6/xbccM3hEL8fyUha5fJiIWIJ:Qaj/uuIcNmLX8dhaRJiIWi
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16AE3A22A3A91F23EC514CAF47D5A43E0907DAC3625D2AC17F7C22B16B2B1D6BD260753
sha3_384: 6744eba07998aeba2fea419277677b3c83f0c3169c91b0886bc45dfeda228cdf0d39745e5e434cdc3dfebd7a079e51f8
ep_bytes: 68b8354000e8f0ffffff000000000000
timestamp: 2011-08-26 14:33:47

Version Info:

Translation: 0x0409 0x04b0
ProductName: YYhThSIQIXSeI
FileVersion: 1.00
ProductVersion: 1.00
InternalName: zMPqoXLpiCnhLibIlYtU
OriginalFilename: zMPqoXLpiCnhLibIlYtU.exe

Worm.Win32.Vobfus.eepy also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.83208
FireEyeGeneric.mg.ef85f36e0e8e3691
CAT-QuickHealTrojan.Vobfus.gen
McAfeeDownloader-CJX.gen.ad
Cylanceunsafe
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.e0e8e3
BitDefenderThetaAI:Packer.01657CE620
VirITTrojan.Win32.SHeur4.ZG
CyrenW32/Vobfus.V.gen!Eldorado
SymantecW32.Changeup!gen35
ESET-NOD32Win32/AutoRun.VB.AKM
APEXMalicious
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.Vobfus.eepy
BitDefenderTrojan.GenericKDZ.83208
NANO-AntivirusTrojan.Win32.WBNA.jsxpfi
SUPERAntiSpywareTrojan.Agent/Gen-FakeAlert[Dropper]
AvastWin32:AutoRun-CHF [Trj]
TencentWorm.Win32.Vobfus.n
TACHYONTrojan/W32.VB-Agent.143360.AB
SophosMal/VB-XV
BaiduWin32.Worm.VB.od
F-SecureTrojan.TR/ATRAPS.Gen2
DrWebTrojan.VbCrypt.60
VIPRETrojan.GenericKDZ.83208
TrendMicroWORM_VOBFUS.SMHE
McAfee-GW-EditionBehavesLike.Win32.VBObfus.cm
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.GenericKDZ.83208 (B)
IkarusTrojan.Win32.Diple
GDataWin32.Trojan.PSE.10I69CR
GoogleDetected
AviraTR/ATRAPS.Gen2
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumTrojWare.Win32.VB.AVA@4paxk7
ArcabitTrojan.Generic.D14508
ZoneAlarmWorm.Win32.Vobfus.eepy
MicrosoftWorm:Win32/Vobfus.SE
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Diple.R23097
VBA32TScope.Trojan.VB
ALYacTrojan.GenericKDZ.83208
MAXmalware (ai score=100)
MalwarebytesGeneric.Malware.AI.DDS
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallWORM_VOBFUS.SMHE
RisingWorm.Vobfus!1.99C8 (CLASSIC)
YandexTrojan.GenAsa!hnsWsW5eEPo
SentinelOneStatic AI – Malicious PE
MaxSecureWorm.VB.ceo
FortinetW32/VBKrypt.C!tr
AVGWin32:AutoRun-CHF [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Worm.Win32.Vobfus.eepy?

Worm.Win32.Vobfus.eepy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment