Malware

Mal/Generic-R + Mal/AuItInj-C (file analysis)

Malware Removal

The Mal/Generic-R + Mal/AuItInj-C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-R + Mal/AuItInj-C virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • A named pipe was used for inter-process communication
  • Starts servers listening on 127.0.0.1:0
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (inter-process)

How to determine Mal/Generic-R + Mal/AuItInj-C?


File Info:

name: 8B101F2E44DD299982E7.mlw
path: /opt/CAPEv2/storage/binaries/20f231ab56dcc75eef9106cc90355e47de68d0a170038d322932115f60c4b214
crc32: C8168A7F
md5: 8b101f2e44dd299982e7ca8f82a725d6
sha1: c95fa458c6e00e153622a6fa513672f4540a07bc
sha256: 20f231ab56dcc75eef9106cc90355e47de68d0a170038d322932115f60c4b214
sha512: f3a2ba357a7742c8685d32cc3880c7edbb9cdaba25e720b95bdf1e30a0e04b0e058044a05a27d45d3ac6e2a249b78039ef56664a62dbc4c1ce82fa76db7bc2f8
ssdeep: 49152:jd9mOsfJlbDNda3b+8T2Da5inFDb1hT9I:jupfJXIV55wN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12F95CF12338DC264CBE261F3BA12B7205E677C950626F6761E863BE8EEF1121D11F653
sha3_384: 36cece445be0aa7875d018ffaa07b07d65c4208c3404ab43ffacf5b4180f189f0969ac72787060197f2e2be91dc6c006
ep_bytes: e877ce0000e97ffeffffcccccccccccc
timestamp: 2021-03-31 02:29:08

Version Info:

FileVersion: 0.0.1.1
ProductVersion: 1.0.1.1
OriginalFilename: upbase_FINAL.exe
InternalName: upbase_FINAL.exe
FileDescription: MUAHACK.COM
CompanyName: MUAHACK.COM
LegalCopyright: MUAHACK.COM
ProductName: FIX-VER-MUAHACK.VN
Translation: 0x0809 0x04b0

Mal/Generic-R + Mal/AuItInj-C also known as:

BkavW32.AIDetect.malware1
LionicRiskware.Win32.Generic.1!c
MicroWorld-eScanTrojan.GenericKD.36655541
FireEyeTrojan.GenericKD.36655541
McAfeeArtemis!8B101F2E44DD
CylanceUnsafe
SangforTrojan.Win32.Wacatac.A
K7AntiVirusTrojan ( 0052617c1 )
AlibabaPacked:Win32/AuItInj.3f44aa37
K7GWTrojan ( 0052617c1 )
Cybereasonmalicious.8c6e00
BitDefenderThetaGen:NN.ZexaF.34182.4v0@aawasWfi
CyrenW32/AutoIt.UA.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.Autoit.Z suspicious
Paloaltogeneric.ml
BitDefenderTrojan.GenericKD.36655541
AvastWin32:Malware-gen
SophosMal/Generic-R + Mal/AuItInj-C
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.tc
EmsisoftTrojan.GenericKD.36655541 (B)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_72%
AviraTR/Crypt.ZPACK.Gen4
MAXmalware (ai score=87)
Antiy-AVLTrojan/Generic.ASMalwS.7CCFA0
MicrosoftBackdoor:Win32/Bladabindi!ml
GDataTrojan.GenericKD.36655541
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R469296
VBA32Backdoor.PoisonIvy
ALYacTrojan.GenericKD.36655541
MalwarebytesTrojan.Agent.AutoIt
APEXMalicious
RisingTrojan.Crypto!8.364 (CLOUD)
IkarusAdWare.LiveKeys
MaxSecureTrojan.Malware.117735605.susgen
FortinetRiskware/AuItInj
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Mal/Generic-R + Mal/AuItInj-C?

Mal/Generic-R + Mal/AuItInj-C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment