Malware

Heur.Munp.1 malicious file

Malware Removal

The Heur.Munp.1 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Heur.Munp.1 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Behavioural detection: Transacted Hollowing
  • CAPE detected the embedded win api malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Heur.Munp.1?


File Info:

name: E760D591F64590C9AE2B.mlw
path: /opt/CAPEv2/storage/binaries/61b8eda172e39d10f1f6312efa4467e971e5636694ac87396b2fa706c016bbb7
crc32: 2D3062F2
md5: e760d591f64590c9ae2b172bba49f2c4
sha1: 2de4e008ae8751283bb3113d5373c0daac802a6c
sha256: 61b8eda172e39d10f1f6312efa4467e971e5636694ac87396b2fa706c016bbb7
sha512: 7788a06dc8ab3158702b4a766fd40396e11613da89395ca14bbcbc77ba4ecd38bccc9242c6030c3535a91ec1fd8f001c33f76c8ad0fba9a7b9d27c0a8158832d
ssdeep: 98304:3iOqvRkL4mT1qCSYV3ltaXo6oQfZqEfG/XGIq36r6lkG:SX+L4m5qCS+3ltaXzfZqAZjKr6lr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18416331772E58CF2F4B29F393F1A185A83B7F6261471B6881CF8D9431EB9E449B0485B
sha3_384: c8306fd939fa9edd71c4311148c29dab7a5ec09c31c09e6307faa75188596304e5555804ca5ec7fb940a4e9037268e5c
ep_bytes: 558bec83c4d453565733c08945f08945
timestamp: 2024-01-07 03:31:59

Version Info:

Comments: This installation was built with Inno Setup: http://www.innosetup.com
CompanyName:
FileDescription: JS pop mail module Setup
FileVersion:
InternalName:
OriginalFilename:
ProductName:
ProductVersion:
Translation: 0x0409 0x04e4

Heur.Munp.1 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Ekstak.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Munp.1
FireEyeGen:Heur.Munp.1
SkyhighBehavesLike.Win32.ObfuscatedPoly.rc
McAfeeArtemis!E760D591F645
MalwarebytesFloxif.Virus.FileInfector.DDS
SangforDropper.Win32.Ekstak.V8dv
K7AntiVirusTrojan ( 005722f11 )
AlibabaTrojanDropper:Win32/Ekstak.d9b3a547
K7GWTrojan ( 005722f11 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
APEXMalicious
KasperskyTrojan.Win32.Ekstak.auvnf
BitDefenderGen:Heur.Munp.1
TencentWin32.Trojan.Ekstak.Ngil
EmsisoftGen:Heur.Munp.1 (B)
F-SecureTrojan.TR/AD.Nekark.rwsny
VIPREGen:Heur.Munp.1
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusTrojan.Win32.Crypt
GDataWin32.Trojan.PSE.SRMNXW
JiangminTrojan.Ekstak.cimi
AviraTR/AD.Nekark.rwsny
VaristW32/Agent.VUEJ-6357
ArcabitTrojan.Munp.1
ZoneAlarmTrojan.Win32.Ekstak.auvnf
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R630982
MAXmalware (ai score=80)
DeepInstinctMALICIOUS
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H0DA724
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.222751246.susgen
FortinetW32/Agent.SLC!tr
PandaTrj/Chgt.AC

How to remove Heur.Munp.1?

Heur.Munp.1 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment