Malware

Mal/Sohana-A malicious file

Malware Removal

The Mal/Sohana-A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Sohana-A virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Mal/Sohana-A?


File Info:

name: FEF8C6F590C1C1938E4F.mlw
path: /opt/CAPEv2/storage/binaries/5dba2b89869140413c7466b09b11f92617ea56fcfcade5b4b2961b1070b3f605
crc32: E17DE8BD
md5: fef8c6f590c1c1938e4fe958493aef01
sha1: 414d52c147bb1081c0a26ce2f8702fd7c88e9ee3
sha256: 5dba2b89869140413c7466b09b11f92617ea56fcfcade5b4b2961b1070b3f605
sha512: 5d761da7f605f2b69ec7b90a97dd06942f5d74564d275799ee11568000b81e9eb1b9d8e743f73675fe5433c214a81c3287b61f36e0c75da7e1aa2b1d67292031
ssdeep: 12288:mhkDgouVA2nxKkorvdRgQriDwOIxmxiZnYQE7PJcbNm/3c2e:WRmJkcoQricOIQxiZY1WNm/s2e
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A6E4AF21F5C68036C2B327B19E7EF76A9A3D79360336D19727C82D315EA05816B29733
sha3_384: a0fe89c64afc0dda63411b1cd29d82c2be31f43419fe41fd7fe3e8af2db1415414ba02ba3d0c45121d63cde2bcb0f0fa
ep_bytes: e816900000e989feffffcccccccccc55
timestamp: 2012-01-29 21:32:28

Version Info:

FileDescription:
FileVersion: 3, 3, 8, 1
CompiledScript: AutoIt v3 Script: 3, 3, 8, 1
Translation: 0x0809 0x04b0

Mal/Sohana-A also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.fef8c6f590c1c193
CAT-QuickHealTrojan.Skeeyah.S11718
McAfeePacked-GAI!FEF8C6F590C1
Cylanceunsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
K7GWTrojan ( 0055e3fd1 )
K7AntiVirusTrojan ( 0055e3fd1 )
BaiduWin32.Trojan.AutoIt.a
CyrenW32/AutoIt.AQ2.gen!Eldorado
SymantecBloodhound.Malautoit
ESET-NOD32a variant of Win32/Packed.Autoit.NBT suspicious
APEXMalicious
ClamAVWin.Malware.Autoit-6991628-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKD.46532138
MicroWorld-eScanTrojan.GenericKD.46532138
AvastWin32:Evo-gen [Trj]
SophosMal/Sohana-A
VIPRETrojan.GenericKD.46532138
McAfee-GW-EditionBehavesLike.Win32.Ransomware.jh
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.46532138 (B)
IkarusTrojan.Win32.Autoit
GDataTrojan.GenericKD.46532138
AviraTR/AutoIt.axovq
Antiy-AVLTrojan/Win32.AutoIt
XcitiumTrojWare.Win32.Agent.AZAB@59q48x
ArcabitTrojan.Generic.D2C6062A
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3HEUR/Fakon.mwf.X1381
BitDefenderThetaAI:Packer.D7D05DD419
ALYacTrojan.GenericKD.46532138
MAXmalware (ai score=82)
VBA32Trojan.Skeeyah
RisingMalware.FakeFolder/ICON!1.6AA9 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Autoit.AZA
FortinetW32/Autoit.NLQ!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.590c1c

How to remove Mal/Sohana-A?

Mal/Sohana-A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment