Malware

Generic.PY.ReverseShell.B.AFC75CD9 removal

Malware Removal

The Generic.PY.ReverseShell.B.AFC75CD9 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.PY.ReverseShell.B.AFC75CD9 virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the PyInstaller malware family

How to determine Generic.PY.ReverseShell.B.AFC75CD9?


File Info:

name: 9C8BE11899C125A462E0.mlw
path: /opt/CAPEv2/storage/binaries/908f09ae0495ee95715cb23e606426a1da3a7fbd91a4035d741a18c00b2db7ea
crc32: 6B796F61
md5: 9c8be11899c125a462e03d020ff89f59
sha1: 6042abb280132e0843c10dfe051ff66bc9a9d2f3
sha256: 908f09ae0495ee95715cb23e606426a1da3a7fbd91a4035d741a18c00b2db7ea
sha512: 8f26b925bcefaec5e049071b90631a5ab2305cc801cd8fad699c354b0f6a7e535169ea1741b5b8304c42148be8e9fc5af62fe59de1355c91eb1d50825d8855f3
ssdeep: 98304:wqJ0mrHQktlw2Kce26t+JhVWn2xxjsAIzsN+puy3Pd3ygyRNNENx:wqh3tlKXqXWnA3IzO+puaZvqN
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T15B3633A4A2544EF8F933913AC452C529D2B3B41057B1DB4F57A482A25F3BAE0BD7F321
sha3_384: e8286de714c57de6b8ad8b161b18918042a5fadd6d8c6a56ea53bc2d3696cc5d94911af7cb6d8d34ed410b74d0a0b21f
ep_bytes: 4883ec28e8070500004883c428e97afe
timestamp: 2022-05-06 09:08:23

Version Info:

0: [No Data]

Generic.PY.ReverseShell.B.AFC75CD9 also known as:

LionicTrojan.Win32.Tedy.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.PY.ReverseShell.B.AFC75CD9
FireEyeGeneric.PY.ReverseShell.B.AFC75CD9
McAfeeArtemis!9C8BE11899C1
CylanceUnsafe
SangforTrojan.Win32.Save.a
AlibabaTrojan:Win32/Almi_Agent.f
CrowdStrikewin/malicious_confidence_100% (W)
SymantecML.Attribute.HighConfidence
ESET-NOD32Python/Rozena.CV
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Cobalt.jvy
BitDefenderGeneric.PY.ReverseShell.B.AFC75CD9
AvastWin64:Trojan-gen
TencentWin32.Trojan.Cobalt.Akjl
Ad-AwareGeneric.PY.ReverseShell.B.AFC75CD9
SophosGeneric ML PUA (PUA)
VIPREGeneric.PY.ReverseShell.B.AFC75CD9
TrendMicroBackdoor.Win64.COBEACON.YXCEFZ
McAfee-GW-EditionBehavesLike.Win64.Ransom.tc
EmsisoftGeneric.PY.ReverseShell.B.AFC75CD9 (B)
GDataGeneric.PY.ReverseShell.B.AFC75CD9
WebrootW32.Trojan.Gen
AviraTR/Rozena.urvpj
ArcabitGeneric.PY.ReverseShell.B.AFC75CD9
MicrosoftTrojan:Win32/Wacatac.B!ml
Acronissuspicious
ALYacGeneric.PY.ReverseShell.B.AFC75CD9
MAXmalware (ai score=83)
MalwarebytesTrojan.ShellCode.Python
TrendMicro-HouseCallBackdoor.Win64.COBEACON.YXCEFZ
FortinetPython/Rozena.CV!tr
AVGWin64:Trojan-gen

How to remove Generic.PY.ReverseShell.B.AFC75CD9?

Generic.PY.ReverseShell.B.AFC75CD9 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment