Malware

What is “Generic.ShellCode.Marte.3.4327FB46”?

Malware Removal

The Generic.ShellCode.Marte.3.4327FB46 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.ShellCode.Marte.3.4327FB46 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Generic.ShellCode.Marte.3.4327FB46?


File Info:

name: 950F7F473B864AA3263F.mlw
path: /opt/CAPEv2/storage/binaries/d23c9f6b3273c7f018767f9e722a37a417d461008d307ce0867acfd6cb48961d
crc32: 253AB06E
md5: 950f7f473b864aa3263fd789abe72996
sha1: 52ca18810c3f20a00d46470c7adc5870b002a0a3
sha256: d23c9f6b3273c7f018767f9e722a37a417d461008d307ce0867acfd6cb48961d
sha512: a822c636169e8c6e24d3621ce799b97f07ec71cd26d36700274cad0bfb9d5c26677fcdd77aa3e5e74c6b5b540da7fb527df2aaa85ea26f2fb2399986098ac3c6
ssdeep: 768:IH15Ee6MXVsGYRLVLOoqtJfEf8OyvPzUsVNf54IE427jebN7DFYDVxn3MFrQG6ik:IV5EMsGuLSJxBNVNfuFUJ2D736EG7Tq3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B113D08092C84496FA76BB3027F18372CF78BD61E87D8B5C2194945B2F725F4A8127ED
sha3_384: 294636953f4f6010c9d580f9429f32fd39e508355c9faafb3d6fff3df36e68ee4d6cdc96ea5bb6fbad041e3ef3d52481
ep_bytes: 60be00e040008dbe0030ffff5783cdff
timestamp: 2009-05-07 11:55:20

Version Info:

Comments: Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0 Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.
CompanyName: Apache Software Foundation
FileDescription: ApacheBench command line utility
FileVersion: 2.2.14
InternalName: ab.exe
LegalCopyright: Copyright 2009 The Apache Software Foundation.
OriginalFilename: ab.exe
ProductName: Apache HTTP Server
ProductVersion: 2.2.14
Translation: 0x0409 0x04b0

Generic.ShellCode.Marte.3.4327FB46 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Jorik.lrUS
MicroWorld-eScanDeepScan:Generic.ShellCode.Marte.3.4327FB46
ClamAVWin.Exploit.Alpha_Upper-1
FireEyeGeneric.mg.950f7f473b864aa3
CAT-QuickHealTrojan.Swrort.A
ALYacDeepScan:Generic.ShellCode.Marte.3.4327FB46
MalwarebytesRozena.Trojan.Shell.DDS
VIPREDeepScan:Generic.ShellCode.Marte.3.4327FB46
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 001172b51 )
AlibabaTrojan:Win32/CobaltStrike.5c89
K7GWTrojan ( 001172b51 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitDeepScan:Generic.ShellCode.Marte.3.4327FB46
BitDefenderThetaGen:NN.ZexaF.36250.cmKfaC8@dqdi
CyrenW32/Swrort.B
SymantecPacked.Generic.347
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Rozena.BJG
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderDeepScan:Generic.ShellCode.Marte.3.4327FB46
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Evo-gen [Trj]
TencentMalware.Win32.Gencirc.13bf3858
EmsisoftDeepScan:Generic.ShellCode.Marte.3.4327FB46 (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen
ZillyaTrojan.Rozena.Win32.193388
TrendMicroBKDR_SWRORT.SM
McAfee-GW-EditionSwrort.d
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLTrojan/Win32.Rozena
XcitiumTrojWare.Win32.Rozena.A@4jwdqr
MicrosoftTrojan:Win32/Meterpreter.O
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataDeepScan:Generic.ShellCode.Marte.3.4327FB46
GoogleDetected
AhnLab-V3Backdoor/Win32.RL_Bifrose.R272107
McAfeeSwrort.d
MAXmalware (ai score=80)
VBA32Trojan.Meterpreter
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallBKDR_SWRORT.SM
RisingTrojan.Crypto!8.364 (TFE:5:qRUE1u5wYD)
IkarusExploit.PDF
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Rozena.ABV!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.73b864
DeepInstinctMALICIOUS

How to remove Generic.ShellCode.Marte.3.4327FB46?

Generic.ShellCode.Marte.3.4327FB46 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment