PUA

Masscan (PUA) (file analysis)

Malware Removal

The Masscan (PUA) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Masscan (PUA) virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Masscan (PUA)?


File Info:

name: 2473E1195E6FF0ED6B11.mlw
path: /opt/CAPEv2/storage/binaries/e58ea52e54d7beb563c2918f295096004781162c9694c6f5ab60e051436dc6c3
crc32: 3B58EBAB
md5: 2473e1195e6ff0ed6b11d7fb21371cec
sha1: 491fc0a47c7acabe153232be4a45d102b134fca1
sha256: e58ea52e54d7beb563c2918f295096004781162c9694c6f5ab60e051436dc6c3
sha512: 998ee623618abd91b1ccbe583809651b1cd2dabc5cc32bfe8b8426d53496bcacd753a55126f83ab7067051044143b93e712f1064dabcd157682f3597931d435e
ssdeep: 12288:i2t7OCHYqhkBwR2BQPo/TsH42Qub6ZyxRX0OwtR:dOEWCQBQPo/Td2DI
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T197C45C11E210F06AF18311F25BE565F0E5F47A31838624E3B7886DB8A7197E8D636B1F
sha3_384: 866f8405d88f616af88fc456a11338dca32401b9b57d9729336493984e93c59149c683e9a4d12296c678c7222532dba9
ep_bytes: 558bece808fdffff5dc3cccccccccccc
timestamp: 2022-09-30 18:45:05

Version Info:

0: [No Data]

Masscan (PUA) also known as:

CynetMalicious (score: 100)
ESET-NOD32a variant of Win32/NetTool.Masscan.B potentially unsafe
APEXMalicious
McAfee-GW-EditionGenericRXRA-ZE!2473E1195E6F
SophosMasscan (PUA)
IkarusHackTool.Win32.Masscan
MicrosoftTrojan:Script/Wacatac.B!ml
GoogleDetected
McAfeeGenericRXRA-ZE!2473E1195E6F
RisingTrojan.Generic@AI.85 (RDMK:cmRtazpBL7pt1xY4ONhcbbxAfvpR)

How to remove Masscan (PUA)?

Masscan (PUA) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment