Malware

ML/PE-A + Mal/Tinba-L information

Malware Removal

The ML/PE-A + Mal/Tinba-L is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + Mal/Tinba-L virus can do?

  • Executable code extraction
  • Compression (or decompression)
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Hongkong)
  • Looks up the external IP address
  • Uses Windows utilities for basic functionality
  • Attempts to remove evidence of file being downloaded from the Internet
  • Attempts to delete volume shadow copies
  • Deletes its original binary from disk
  • Exhibits behavior characteristic of Alphacrypt/Teslacrypt ransomware
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Connects to Tor Hidden Services through a Tor gateway
  • Creates a known TeslaCrypt/AlphaCrypt ransomware decryption instruction / key file.
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
ipinfo.io
computercentral.info
competitiveelectronics.info
camerasforyou.info
fgainterests.com
serenitynowbooksandgifts.com
www.serenitynowbooksandgifts.com
kb63vhjuk3wh4ex7.onion.to
kb63vhjuk3wh4ex7.tor2web.org

How to determine ML/PE-A + Mal/Tinba-L?


File Info:

crc32: 9BF67F8E
md5: 060d41f75055ed0ffd43a408e6a5801e
name: 060D41F75055ED0FFD43A408E6A5801E.mlw
sha1: 96a466c5dbc7e4a10257afb3bd8b790f965084d9
sha256: 34e1b92e38659dd6407c5065a3dd0cd8b791b182af5eaeb26b2a4573bc2177ea
sha512: 663cd0f6d73fd7a91a6b7058c201bfe8f6797c94b90f1690119ad7b80f560e8f913143ed8e46c8efcf5d1450aa4eb5b69a0ad1ffc2646fe86f53fc96ecb014ff
ssdeep: 6144:44oibXfchTduH5Gwqp5ASxhJq94C1ORG+v4igk72RC/kVp4uOebbkYCDG:NjbMQk5AOhJFGBmkVpvnkYz
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Swarming xa9 2044
InternalName: Sealants
FileVersion: 145, 28, 111, 66
CompanyName: Safer-Networking Ltd.
ProductName: Shred Salver
FileDescription: Reword
OriginalFilename: Shafts.exe

ML/PE-A + Mal/Tinba-L also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0055e3ef1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.1731
CynetMalicious (score: 100)
CAT-QuickHealRansom.Tescrypt.MUE.A4
CylanceUnsafe
ZillyaTrojan.Deshacop.Win32.185
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/generic.ali2000010
K7GWTrojan ( 0055e3ef1 )
Cybereasonmalicious.75055e
SymantecRansom.TeslaCrypt
ESET-NOD32Win32/Filecoder.TeslaCrypt.D
APEXMalicious
AvastWin32:TeslaCrypt-DT [Trj]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Cripack.Gen.1
NANO-AntivirusTrojan.Win32.Deshacop.dvrwhh
ViRobotTrojan.Win32.Ransom.353633
MicroWorld-eScanTrojan.Cripack.Gen.1
TencentMalware.Win32.Gencirc.114c7adc
Ad-AwareTrojan.Cripack.Gen.1
SophosML/PE-A + Mal/Tinba-L
ComodoTrojWare.Win32.TrojanDownloader.Upatre.EBO@5zjcok
BitDefenderThetaGen:NN.ZexaF.34688.vq3@aaBs1@Ub
VIPRETrojan.Win32.Generic!BT
TrendMicroCryp_HpMyApp
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
FireEyeGeneric.mg.060d41f75055ed0f
EmsisoftTrojan.Cripack.Gen.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Deshacop.cv
WebrootTrojan.Dropper.Gen
AviraHEUR/AGEN.1118866
eGambitGeneric.Malware
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftRansom:Win32/Tescrypt.C
ArcabitTrojan.Cripack.Gen.1
GDataTrojan.Cripack.Gen.1
AhnLab-V3Win-Trojan/Lockycrypt.Gen
Acronissuspicious
McAfeeTeslaCrypt!060D41F75055
MAXmalware (ai score=100)
VBA32Trojan.Deshacop
MalwarebytesTrojan.Agent.QDD
PandaTrj/Genetic.gen
TrendMicro-HouseCallCryp_HpMyApp
RisingRansom.Tescrypt!8.3AF (CLOUD)
YandexTrojan.GenAsa!pVeuL38xTPU
IkarusTrojan.Win32.Filecoder
FortinetW32/Deshacop.XO!tr
AVGWin32:TeslaCrypt-DT [Trj]
Paloaltogeneric.ml

How to remove ML/PE-A + Mal/Tinba-L?

ML/PE-A + Mal/Tinba-L removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment