Malware

ML/PE-A + Troj/Lumi-B (file analysis)

Malware Removal

The ML/PE-A + Troj/Lumi-B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + Troj/Lumi-B virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial binary language: Portuguese (Brazil)
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Binary compilation timestomping detected

How to determine ML/PE-A + Troj/Lumi-B?


File Info:

name: F6F78D39250A3E81FBE2.mlw
path: /opt/CAPEv2/storage/binaries/53f2ee1b609e48faf9713ed63b6110b5f22651b1d30549b3d035d34d862b30c8
crc32: 1BF6A144
md5: f6f78d39250a3e81fbe247a82ce048f1
sha1: 0a0974dbe782bec6943ba59eb9c874892c9f88ff
sha256: 53f2ee1b609e48faf9713ed63b6110b5f22651b1d30549b3d035d34d862b30c8
sha512: 16464b69de3cffa0b4883ab95ab3d3e99de0965ebd184f32994b8b9d908fd4aa0528718158fda243c0c77ae41e4e87bccd63d98245a104ebf4c196a0124e8102
ssdeep: 192:W5M/AZDNcJsb0v7U1M3wQWVXakQ/9eIoRxj/2781sgESP:W5yAZD0b/AQWVq9/9eIoLj+g1sgESP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EF9218E7F7D02108D819663006F24A6701626CFC3F7391CB9A89BB422E735D66B31EE5
sha3_384: c666883d30d2e3d818a3c04fda81481d963d4f1d3a71b0c32327e41e14d59a6d8149a4a228a81a85d446edf3b0668e44
ep_bytes: 55505050e819f2ffff5dc30015ff006a
timestamp: 2071-10-05 03:08:20

Version Info:

CompanyName: FASTER
FileDescription: FASTER company
FileVersion: Version 0.1.8
InternalName: FASTER
LegalCopyright: Copyright by FASTER Inc.
OriginalFilename: FASTER
Translation: 0x0416 0x04e4

ML/PE-A + Troj/Lumi-B also known as:

BkavW32.AIDetect.malware1
tehtrisGeneric.Malware
DrWebTrojan.Upatre.87
MicroWorld-eScanTrojan.Upatre.Gen.3
FireEyeGeneric.mg.f6f78d39250a3e81
CAT-QuickHealTrojanDwnldr.Upatre.AA4
ALYacTrojan.Upatre.Gen.3
CylanceUnsafe
ZillyaDownloader.Upatre.Win32.43
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0055e3da1 )
K7GWTrojan-Downloader ( 0055e3da1 )
Cybereasonmalicious.9250a3
BitDefenderThetaGen:NN.ZexaF.34592.bq1@amucNaeO
VirITTrojan.Win32.Generic.BZU
CyrenW32/A-10a39d23!Eldorado
SymantecDownloader.Upatre!gen5
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDownloader.Waski.A
APEXMalicious
ClamAVWin.Trojan.Downloader-64676
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Upatre.Gen.3
NANO-AntivirusTrojan.Win32.Upatre.dfsuve
SUPERAntiSpywareTrojan.Agent/Gen-Waski
AvastWin32:Agent-AULS [Trj]
RisingTrojan.Generic@AI.100 (RDML:dUglS/We59zY5NhSP92BSg)
Ad-AwareTrojan.Upatre.Gen.3
SophosML/PE-A + Troj/Lumi-B
ComodoTrojWare.Win32.TrojanDownloader.Waski.EB@5j320p
BaiduWin32.Trojan-Downloader.Waski.a
VIPRETrojan.Upatre.Gen.3
TrendMicroTROJ_UPATRE.SM37
McAfee-GW-EditionBehavesLike.Win32.Downloader.lm
Trapminemalicious.high.ml.score
EmsisoftTrojan.Upatre.Gen.3 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.Upatre.dt
GoogleDetected
AviraTR/Crypt.ZPACK.Gen2
MAXmalware (ai score=81)
Antiy-AVLTrojan/Generic.ASMalwS.3CF7
KingsoftWin32.TrojDownloader.Upatre.b.(kcloud)
MicrosoftTrojan:Win32/PWSZbot.GSB!MTB
ViRobotTrojan.Win32.Downloader.19456.KL
GDataWin32.Trojan.PSE1.QHQVJ
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Downloader.R120631
VBA32TrojanDownloader.Upatre
MalwarebytesTrojan.Dropper
TrendMicro-HouseCallTROJ_UPATRE.SM37
TencentMalware.Win32.Gencirc.10b690d0
YandexTrojan.DL.Waski!U1bYQeySbjw
IkarusTrojan-Downloader.Win32.Upatre
MaxSecureTrojan.Upatre.Gen
FortinetW32/Waski.A!tr
AVGWin32:Agent-AULS [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove ML/PE-A + Troj/Lumi-B?

ML/PE-A + Troj/Lumi-B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment