Malware

About “Generic.Bash.MiraiA.94041CF3” infection

Malware Removal

The Generic.Bash.MiraiA.94041CF3 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Bash.MiraiA.94041CF3 virus can do?

  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • A potential decoy document was displayed to the user
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz
redirector.gvt1.com
r4—sn-4g5ednsy.gvt1.com

How to determine Generic.Bash.MiraiA.94041CF3?


File Info:

crc32: 6BFBE30C
md5: 672de7bd35719776255cadd4875f917d
name: upload_file
sha1: 7391d704b636e50f7673dd6a77e3e970e7845017
sha256: 3ad82f600715ade75ccd11a09dcf3c3baf50a39da435479a3581caa2da8ad94c
sha512: ff37c21c235dfc2499fe68eaa8835ce21a068e4ac5c89b1cd85ab6f0b9fc0504925e06b3b186c236bce07b1b8de78c48768fe52d8dcd205215c7d3f37afd8b3c
ssdeep: 24:vLnsIzRyYsk8iQvkSEhQ41LLQhTg8WbksQSvKs6Xs8rn:v4ktsziQvkrhQ41LLQBg7JQSvv68q
type: Bourne-Again shell script, ASCII text executable

Version Info:

0: [No Data]

Generic.Bash.MiraiA.94041CF3 also known as:

DrWebLinux.DownLoader.664
MicroWorld-eScanGeneric.Bash.MiraiA.94041CF3
FireEyeGeneric.Bash.MiraiA.94041CF3
McAfeeLinux/Downloader.k
TrendMicro-HouseCallELF_MIRAILOD.SM
AvastBV:Downloader-AAN [Drp]
GDataGeneric.Bash.MiraiA.94041CF3
KasperskyHEUR:Trojan-Downloader.Shell.Agent.p
BitDefenderGeneric.Bash.MiraiA.94041CF3
NANO-AntivirusTrojan.Script.Downloader.fjajjs
RisingMalware.Shell!1.C8A3 (CLASSIC)
Ad-AwareGeneric.Bash.MiraiA.94041CF3
SophosMal/ShellDl-A
ComodoTrojWare.Script.TrojanDownloader.Agent.D@7qvmcx
F-SecureMalware.HTML/ExpKit.Gen2
TrendMicroELF_MIRAILOD.SM
EmsisoftGeneric.Bash.MiraiA.94041CF3 (B)
CyrenSH/Mirai.A.gen!Camelot
AviraHTML/ExpKit.Gen2
MicrosoftTrojanDownloader:Linux/Morila!MTB
ArcabitGeneric.Bash.MiraiA.94041CF3
ZoneAlarmHEUR:Trojan-Downloader.Shell.Agent.p
CynetMalicious (score: 85)
AhnLab-V3Shell/ElfDownloader.S1
ALYacGeneric.Bash.MiraiA.94041CF3
ESET-NOD32Linux/TrojanDownloader.SH.S
TencentHeur:Trojan.Linux.Downloader.e
MAXmalware (ai score=83)
FortinetBASH/MiraiA.SHELL!tr.dldr
AVGBV:Downloader-AAN [Drp]

How to remove Generic.Bash.MiraiA.94041CF3?

Generic.Bash.MiraiA.94041CF3 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment