Worm

Worm:Win32/Woreflint.A!cl information

Malware Removal

The Worm:Win32/Woreflint.A!cl is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Woreflint.A!cl virus can do?

  • Attempts to connect to a dead IP:Port (12 unique times)
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Starts servers listening on 0.0.0.0:40500
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to remove evidence of file being downloaded from the Internet
  • A process attempted to delay the analysis task by a long amount of time.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Attempts to modify or disable Security Center warnings

How to determine Worm:Win32/Woreflint.A!cl?


File Info:

name: 0A49900B4492F43B6833.mlw
path: /opt/CAPEv2/storage/binaries/4151d9af5a104eea9106b18d35102f3b11134d7ba598e1fd57580a932d4596fa
crc32: 3DF6D54A
md5: 0a49900b4492f43b68331af062731f33
sha1: 95adde1482efa92c0907917c8716cd337f008d7e
sha256: 4151d9af5a104eea9106b18d35102f3b11134d7ba598e1fd57580a932d4596fa
sha512: 5d7328a6e4e573c67dd829aafeccefbf84543b2c3fc7d3d9ace9bab026c66a6c78c913436ebd7ea315b5af636c40a6c7d6650b5bef5aabd694bc9c83eee8aa53
ssdeep: 768:K3MuYuJJXY865HeZY1eoxYIO9tF9U1boIQy5bEYSGIJUV9nAZzgEg62KQ2CnAa/A:K3Mz8i4u1u7LyB+GIx2csdgMGfF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AB633900F650C13BF0F740FFE2BB096E99299FE4434598DB22D0699F6B316C1AA32597
sha3_384: f37aea9824a25b602d154b133fdb919d972eca0e6ebfc8cefcedef9bf0b56bdc3237906b1e76f1ec5b394c993128d67a
ep_bytes: 558bec81ec040c000068d0070000ff15
timestamp: 2021-11-29 02:20:30

Version Info:

0: [No Data]

Worm:Win32/Woreflint.A!cl also known as:

BkavW32.FsnleamrM.Trojan
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.38236424
FireEyeGeneric.mg.0a49900b4492f43b
CAT-QuickHealTrojan.IgenericRI.S23757235
ALYacTrojan.Agent.Phorpiex
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005533551 )
AlibabaTrojan:Win32/Starter.ali2000005
K7GWTrojan ( 005533551 )
CrowdStrikewin/malicious_confidence_90% (W)
CyrenW32/Trojan.TOFS-7360
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Phorpiex.V
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKD.38236424
NANO-AntivirusTrojan.Win32.Phorpiex.jikqdt
AvastWin32:KadrBot [Trj]
TencentWin32.Trojan.Generic.Fif
Ad-AwareTrojan.GenericKD.38236424
EmsisoftTrojan.GenericKD.38236424 (B)
Comodofls.noname@0
DrWebTrojan.InjectNET.14
ZillyaWorm.Phorpiex.Win32.2233
TrendMicroTROJ_GEN.R04AC0GL321
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.lh
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKD.38236424
JiangminWorm.Generic.arrm
WebrootW32.Trojan.Phorpiex
AviraHEUR/AGEN.1135016
MAXmalware (ai score=87)
Antiy-AVLTrojan/Generic.ASMalwS.34CEFD9
KingsoftWin32.Heur.KVMH012.a.(kcloud)
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Generic.D2477108
MicrosoftWorm:Win32/Woreflint.A!cl
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4630408
Acronissuspicious
McAfeeGenericRXAA-FA!0A49900B4492
VBA32BScope.Trojan.Phorpiex
MalwarebytesTrojan.Downloader
TrendMicro-HouseCallTROJ_GEN.R04AC0GL321
RisingTrojan.Generic@ML.90 (RDML:au3XGGVEa3azlQ8PDqS7qw)
YandexTrojan.Agent!URNI0gKxB58
IkarusWorm.Win32.Phorpiex
eGambitUnsafe.AI_Score_99%
FortinetW32/Phorpiex.V!worm
BitDefenderThetaAI:Packer.E127E6491E
AVGWin32:KadrBot [Trj]
Cybereasonmalicious.b4492f
PandaAdware/SecurityProtection
MaxSecureTrojan.Malware.300983.susgen

How to remove Worm:Win32/Woreflint.A!cl?

Worm:Win32/Woreflint.A!cl removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment