Malware

Generic.LoadaRat.A.C1C20E29 (file analysis)

Malware Removal

The Generic.LoadaRat.A.C1C20E29 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.LoadaRat.A.C1C20E29 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Generic.LoadaRat.A.C1C20E29?


File Info:

name: 4F60C312C12541087ECA.mlw
path: /opt/CAPEv2/storage/binaries/280845ac7da4a0bb64adfeec17d873e020ff8d12e616bb7a70159318000c4dc0
crc32: 33A8760B
md5: 4f60c312c12541087eca27759bed5707
sha1: 983d41faa32c7b8c1e67d7d2574173e2dba56b9d
sha256: 280845ac7da4a0bb64adfeec17d873e020ff8d12e616bb7a70159318000c4dc0
sha512: 4f285f17061b21008af8fc4a90cb53799378c6295b20736d2f32e0b52e1de6d6766514328913fe729bcf9f1b03b27d9666fab20c530ec4515ac57b6a4fac8270
ssdeep: 24576:CRmJkcoQricOIQxiZY1iaeCE08ZUU21RO0mfbCPv7/t8DTt:XJZoQrbTFZY1iaeT08ZX21U0iCu9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T170557C31DCC66821C2F132F4C977A6259226DC2352338B57A6F87E117AB064BFE3661D
sha3_384: 1d7e9053262a405d8f23f39a98b1d00db2547f024a23b6ac90d5b42c55cc52417c9ac2559d839d91fd402df63fd38697
ep_bytes: e816900000e989feffffcccccccccc55
timestamp: 2012-01-29 21:32:28

Version Info:

FileDescription:
FileVersion: 3, 3, 8, 1
CompiledScript: AutoIt v3 Script: 3, 3, 8, 1
Translation: 0x0809 0x04b0

Generic.LoadaRat.A.C1C20E29 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Script.LodaRat.m!c
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.LoadaRat.A.C1C20E29
FireEyeGeneric.mg.4f60c312c1254108
McAfeeArtemis!4F60C312C125
K7AntiVirusTrojan ( 00479c481 )
AlibabaBackdoor:AutoIt/LodaRat.528e30a5
K7GWTrojan ( 00479c481 )
Cybereasonmalicious.2c1254
BitDefenderThetaAI:Packer.7492DFF116
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Autoit.DB
APEXMalicious
Paloaltogeneric.ml
ClamAVTxt.Malware.LodaRAT-9769386-0
KasperskyHEUR:Backdoor.Script.LodaRat.a
BitDefenderGeneric.LoadaRat.A.C1C20E29
SUPERAntiSpywareTrojan.Agent/Gen-Ransom
AvastAutoIt:KeyLogger-R [Trj]
Ad-AwareGeneric.LoadaRat.A.C1C20E29
SophosMal/Generic-S
TrendMicroTROJ_GEN.R002C0DB622
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
EmsisoftGeneric.LoadaRat.A.C1C20E29 (B)
IkarusTrojan.Autoit
GDataGeneric.LoadaRat.A.C1C20E29 (2x)
AviraHEUR/AGEN.1229437
MAXmalware (ai score=89)
GridinsoftRansom.Win32.Sabsik.sa
ZoneAlarmHEUR:Backdoor.Script.LodaRat.a
MicrosoftSpyware:PowerShell/Keylogger.G!MTB
CynetMalicious (score: 100)
VBA32Trojan.Autoit.F
ALYacGeneric.LoadaRat.A.C1C20E29
CylanceUnsafe
TrendMicro-HouseCallTROJ_GEN.R002C0DB622
RisingBackdoor.888Rat/Autoit!1.C8E3 (CLASSIC)
MaxSecureTrojan.Autoit.AZA
FortinetAutoIt/Agent.DB!tr
AVGAutoIt:KeyLogger-R [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Generic.LoadaRat.A.C1C20E29?

Generic.LoadaRat.A.C1C20E29 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment