Malware

Marsilia.31558 (file analysis)

Malware Removal

The Marsilia.31558 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Marsilia.31558 virus can do?

  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Marsilia.31558?


File Info:

name: A78BE58DDD3BB57CE83B.mlw
path: /opt/CAPEv2/storage/binaries/1bdeedd7c893ccc638cc7abe8ec931f2aff68864231fdf3d7c963157165c027a
crc32: 96079582
md5: a78be58ddd3bb57ce83b7e96e5e76cf0
sha1: 42b172bddb35b703366ecc894d5a8558353a9dd8
sha256: 1bdeedd7c893ccc638cc7abe8ec931f2aff68864231fdf3d7c963157165c027a
sha512: a9f7c31c7ac18645ec04ac2564e7545a662382701b9f11da6b3ddfbf0f68adb4ce750923e5520f7a931f649bbf4c3bb30148017ba5f5f2409fc4402ace7500d2
ssdeep: 96:1H9LjY17QKCRSMMoUXBcE2NYlnlYJnLrL0KffyF9yv1dRXmm/IG:3LC7gSvgVQnlYJLrLTkgd
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B9C1E91AA7D14377CB7B07734DB356410BB2E908DF67ABAF049493718E9311507A2B72
sha3_384: 2f36d59563255e8c65678d077e0936192974a5a859a70058a7cd53c26550e5afa6baef3696f4546afe0cc7e9efbc3731
ep_bytes: ff250020400000000000000000000000
timestamp: 2014-04-15 10:20:03

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: خميس.exe
LegalCopyright:
OriginalFilename: خميس.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Marsilia.31558 also known as:

BkavW32.AIDetectMalware.CS
LionicTrojan.Win32.Genome.lxQR
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Marsilia.31558
FireEyeGeneric.mg.a78be58ddd3bb57c
SkyhighBehavesLike.Win32.Generic.xt
McAfeeArtemis!A78BE58DDD3B
MalwarebytesGeneric.Malware/Suspicious
VIPREGen:Variant.Marsilia.31558
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0055e3e21 )
AlibabaTrojan:MSIL/Generic.055c503e
K7GWTrojan-Downloader ( 0055e3e21 )
Cybereasonmalicious.ddd3bb
VirITTrojan.Win32.MSIL_Heur.A
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/TrojanDownloader.Tiny.AS
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R002C0GBC24
KasperskyHEUR:Trojan-Downloader.MSIL.Snoload.gen
BitDefenderGen:Variant.Marsilia.31558
NANO-AntivirusTrojan.Win32.Tiny.cwykig
AvastWin32:DropperX-gen [Drp]
TencentWin32.Trojan.Generic.Wmhl
EmsisoftGen:Variant.Marsilia.31558 (B)
F-SecureTrojan.TR/Downloader.Gen9
DrWebTrojan.DownLoader9.27462
ZillyaDownloader.Tiny.Win32.25372
TrendMicroTROJ_GEN.R002C0GBC24
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
IkarusTrojan-Downloader.MSIL.Tiny
JiangminTrojan.Generic01.a
GoogleDetected
AviraTR/Downloader.Gen9
VaristW32/MSIL_Kryptik.COX.gen!Eldorado
Antiy-AVLTrojan/Win32.Badur
KingsoftMSIL.Trojan-Downloader.Snoload.gen
MicrosoftBackdoor:Win32/Bladabindi!ml
XcitiumMalware@#2fplvz4u91qec
ArcabitTrojan.Marsilia.D7B46
ZoneAlarmHEUR:Trojan-Downloader.MSIL.Snoload.gen
GDataGen:Variant.Marsilia.31558
BitDefenderThetaGen:NN.ZemsilF.36802.am0@aOZCGil
ALYacGen:Variant.Marsilia.31558
MAXmalware (ai score=99)
Cylanceunsafe
PandaTrj/CI.A
RisingDownloader.Tiny!8.245 (CLOUD)
YandexTrojan.Badur!LP+SWlymrMs
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Tiny.BB!tr.dldr
AVGWin32:DropperX-gen [Drp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)
alibabacloudTrojan[downloader]:MSIL/Snoload.gen

How to remove Marsilia.31558?

Marsilia.31558 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment