Malware

Mal/Generic-S + Troj/Mocrt-A malicious file

Malware Removal

The Mal/Generic-S + Troj/Mocrt-A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-S + Troj/Mocrt-A virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Arabic (Qatar)
  • Authenticode signature is invalid
  • Attempts to remove evidence of file being downloaded from the Internet
  • CAPE detected the WarzoneRAT malware family
  • Accesses or creates Warzone RAT directories and/or files

How to determine Mal/Generic-S + Troj/Mocrt-A?


File Info:

name: 485AA72D1122385D41FD.mlw
path: /opt/CAPEv2/storage/binaries/dd39918720d7a30cce4d64ad039930bfbd9e5dc7c2293ead27fb1b56204625de
crc32: 64278DB5
md5: 485aa72d1122385d41fdefb74722a5e0
sha1: 437ac94b491a95767bf93a2a36383af02d0c1060
sha256: dd39918720d7a30cce4d64ad039930bfbd9e5dc7c2293ead27fb1b56204625de
sha512: 7f038274a76cc0f5c2d46830b73b73bf5a78a829e4e7fbda9e8db2d402f679b0240bbd4e3b301f53225c3d1e6dbe4b902d87e3bf61dd9e2c649e90ff9d7cd415
ssdeep: 1536:h0jP7/L1B5rVmN8sxHv2M28ix8EUaJxWZoB4u0OVE01g:K1VmhaH8EFvW+0OVE0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T106B39E13F7E54835F3B201B01ABD7E7ACBEDF9700628C49FA394858A2D31946E925397
sha3_384: 08594fe32dd90b2a03078dfc85f3c974b3e43fc06bb3a353ed51ecde689fa64b04a221815d95b1c0dbfbf2235c5cdabf
ep_bytes: 558bec83ec4456ff15e84141008bc88a
timestamp: 2020-08-29 06:54:20

Version Info:

0: [No Data]

Mal/Generic-S + Troj/Mocrt-A also known as:

BkavW32.AndrneLM.Trojan
LionicTrojan.Win32.Agentb.trG2
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Maria.3
MicroWorld-eScanTrojan.GenericKD.38202727
CAT-QuickHealTrojan.GenericRI.S22016029
ALYacTrojan.GenericKD.38202727
CylanceUnsafe
ZillyaTrojan.Agent.Win32.1391531
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0054d10e1 )
AlibabaMalware:Win32/km_2ec7e.None
K7GWTrojan ( 0054d10e1 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Generic.D246ED67
BitDefenderThetaGen:NN.ZexaF.34084.hyW@aC46ikhi
VirITTrojan.Win32.PSWStealer.CPI
CyrenW32/Antiav.INDT-0919
SymantecInfostealer
ESET-NOD32Win32/Agent.TJS
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.AveMaria-8799014-1
KasperskyTrojan.Win32.Agentb.jiad
BitDefenderTrojan.GenericKD.38202727
NANO-AntivirusTrojan.Win32.AntiAV.fljpfv
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10ce4ea1
Ad-AwareTrojan.GenericKD.38202727
EmsisoftTrojan.Agent (A)
ComodoTrojWare.Win32.AntiAV.VA@81mmki
TrendMicroTrojanSpy.Win32.MOCRT.SM
McAfee-GW-EditionBehavesLike.Win32.Ransomware.ch
FireEyeGeneric.mg.485aa72d1122385d
SophosMal/Generic-S + Troj/Mocrt-A
IkarusTrojan-Spy.AveMaria
JiangminTrojan.Agentb.eab
AviraTR/Redcap.ghjpt
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.2A11D98
KingsoftWin32.Heur.KVMH017.a.(kcloud)
GridinsoftTrojan.Win32.Agent.oa!s1
MicrosoftBackdoor:Win32/Remcos!MTB
ViRobotTrojan.Win32.Agent.1392640.E
GDataWin32.Backdoor.AveMaria.A
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.AveMaria.R263895
McAfeeGenericRXLJ-HT!485AA72D1122
TACHYONTrojan/W32.WarzoneRat.115712
VBA32TrojanPSW.Maria
MalwarebytesBackdoor.AveMaria
TrendMicro-HouseCallTrojanSpy.Win32.MOCRT.SM
RisingStealer.AveMaria!1.BA1C (CLASSIC)
YandexTrojan.GenAsa!++8lN4UW0KE
SentinelOneStatic AI – Malicious PE
eGambitTrojan.Generic
FortinetW32/Agent.TJS!tr
AVGWin32:Malware-gen
Cybereasonmalicious.d11223
PandaTrj/Genetic.gen

How to remove Mal/Generic-S + Troj/Mocrt-A?

Mal/Generic-S + Troj/Mocrt-A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment