Malware

Mal/Sohana-A removal tips

Malware Removal

The Mal/Sohana-A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Sohana-A virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Attempts to masquerade or mimic a legitimate process or file name
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Mal/Sohana-A?


File Info:

name: 1133200F1BB3089C8026.mlw
path: /opt/CAPEv2/storage/binaries/7c07470d750f8fa9393a92227c1a4cd8eb4e53801a67651da458df5225b1c03e
crc32: E921F61C
md5: 1133200f1bb3089c8026c1e40d7e1be0
sha1: c94b8e49e74635e4e93450f9cd8017e60d68e7cb
sha256: 7c07470d750f8fa9393a92227c1a4cd8eb4e53801a67651da458df5225b1c03e
sha512: 476d9ef03101ccfcda8b21c6c5af0a83773a7464453c5e35fd70e5776466de4cc2799d86eeb2b22d14c741dd36b2c1e59471201c22a07ce4a86918acb930754e
ssdeep: 12288:mhkDgouVA2nxKkorvdRgQriDwOIxmxiZnYQE7PJcbNm0D3c2d:WRmJkcoQricOIQxiZY1WNmCs2d
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T143F4AF21F5C68036C2B327B19E7EF76A9A3D79360336D19727C82D315EA05816B29733
sha3_384: b674c22e7f5e0770084c172a66f8084155973b35b5aad063a4ad60cdceee72bf12f3ccd39f091d372de56814c5a70ffa
ep_bytes: e816900000e989feffffcccccccccc55
timestamp: 2012-01-29 21:32:28

Version Info:

FileDescription:
FileVersion: 3, 3, 8, 1
CompiledScript: AutoIt v3 Script: 3, 3, 8, 1
Translation: 0x0809 0x04b0

Mal/Sohana-A also known as:

BkavW32.AIDetectNet.01
AVGAutoIt:Agent-DP [Trj]
MicroWorld-eScanTrojan.GenericKD.46532138
FireEyeGeneric.mg.1133200f1bb3089c
CAT-QuickHealTrojan.AutoIt.Pistolar.A
ALYacTrojan.GenericKD.46532138
MalwarebytesGeneric.Trojan.Malicious.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0055e3fd1 )
K7GWTrojan ( 0055e3fd1 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Trojan.AutoIt.a
CyrenW32/AutoIt.AQ2.gen!Eldorado
SymantecBloodhound.Malautoit
Elasticmalicious (high confidence)
ESET-NOD32multiple detections
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Autoit-6991628-0
KasperskyTrojan.Win32.Autoit.aza
BitDefenderTrojan.GenericKD.46532138
NANO-AntivirusTrojan.Win32.Autoit.fkkztg
AvastAutoIt:Agent-DP [Trj]
SophosMal/Sohana-A
DrWebTrojan.DownLoader9.25733
VIPRETrojan.GenericKD.46532138
McAfee-GW-EditionBehavesLike.Win32.Comame.bh
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.46532138 (B)
IkarusTrojan.Win32.Autoit
GDataTrojan.GenericKD.46532138
AviraTR/AutoIt.axovq
Antiy-AVLTrojan/Win32.AutoIt
XcitiumTrojWare.Win32.Agent.AZAB@59q48x
ArcabitTrojan.Generic.D2C6062A
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3HEUR/Fakon.mwf.X1381
McAfeeComame.b
MAXmalware (ai score=80)
VBA32Trojan.Autoit.Wirus
Cylanceunsafe
RisingMalware.FakeFolder/ICON!1.6AA9 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Autoit.AZA
FortinetW32/Sohana.A!tr
PandaTrj/Genetic.gen

How to remove Mal/Sohana-A?

Mal/Sohana-A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment