Malware

Marsilia.6848 removal

Malware Removal

The Marsilia.6848 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Marsilia.6848 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded win api malware family
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Marsilia.6848?


File Info:

name: 7B129FAD1B4F6AE893F9.mlw
path: /opt/CAPEv2/storage/binaries/2ddd66ec609d0860e6e334bf6751b9eb952684eb8a091df8f43db5e88be0314e
crc32: 6DEDF0AD
md5: 7b129fad1b4f6ae893f9e146f364542d
sha1: 41a8290731dba5a5ff623b99eb9b1df1f63d497a
sha256: 2ddd66ec609d0860e6e334bf6751b9eb952684eb8a091df8f43db5e88be0314e
sha512: 75cae5f7db5f19ca736ad1d3f2f3842597d5a69f3b91f7e612969cd55da6197f3e40c4d8aa9838f39b47d6cc7b5ae5e0cce48c06679376698393c3c88dd9f058
ssdeep: 12288:07blMcQ9777qZTtCwPbVPURznr2Cegd1B26EzQEmUWM:07bl7m777q7hPxzCP1B26SQw9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T132A402D2D7CFC576E9A29EB8A8E95231D267FF182C3C6009B0AD38495B374C4590EF52
sha3_384: 13f8c096b9a950a087998e8d25ee576abb44946c0c24084b1d322c21c1433f090b35a21691ef296b6556cf4968dafed3
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription:
FileVersion:
LegalCopyright:
ProductName:
ProductVersion:
Translation: 0x0000 0x04b0

Marsilia.6848 also known as:

BkavW32.AIDetectMalware
CynetMalicious (score: 100)
SkyhighBehavesLike.Win32.ObfuscatedPoly.gc
McAfeeRDN/Generic PWS.y
MalwarebytesGeneric.Malware.AI.DDS
ZillyaDropper.Sysn.Win32.4907
K7AntiVirusSpyware ( 0055e3ec1 )
K7GWSpyware ( 0055e3ec1 )
Cybereasonmalicious.731dba
ArcabitTrojan.Marsilia.D1AC0
BitDefenderThetaGen:NN.ZemsilF.36680.om0@aO0nGrl
SymantecTrojan.Gen.9
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Spy.Agent.APY
APEXMalicious
KasperskyTrojan.Win32.CoinMiner.txg
BitDefenderGen:Variant.Marsilia.6848
NANO-AntivirusTrojan.Win32.Mlw.eusovo
MicroWorld-eScanGen:Variant.Marsilia.6848
AvastWin32:Malware-gen
EmsisoftGen:Variant.Marsilia.6848 (B)
F-SecureHeuristic.HEUR/AGEN.1310661
VIPREGen:Variant.Marsilia.6848
FireEyeGen:Variant.Marsilia.6848
IkarusTrojan.MSIL.Spy
JiangminTrojan.Generic.evekh
GoogleDetected
AviraHEUR/AGEN.1332285
Antiy-AVLTrojan/Win32.Agent
MicrosoftTrojan:Win32/Meterpreter!ml
ZoneAlarmTrojan.Win32.CoinMiner.txg
GDataGen:Variant.Marsilia.6848
VaristW32/A-17b8a5e1!Eldorado
ALYacGen:Variant.Marsilia.6848
Cylanceunsafe
RisingSpyware.Agent!8.C6 (CLOUD)
FortinetMSIL/Agent.APY!tr.spy
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Marsilia.6848?

Marsilia.6848 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment