Malware

MSILHeracles.13493 (B) removal

Malware Removal

The MSILHeracles.13493 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSILHeracles.13493 (B) virus can do?

  • Dynamic (imported) function loading detected
  • .NET file is packed/obfuscated with Confuser
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine MSILHeracles.13493 (B)?


File Info:

name: 62023203C5D05281C720.mlw
path: /opt/CAPEv2/storage/binaries/2bd6b2ebd2d150258dce30f9b4d46790566f61defca08233b98f0a09c0153faf
crc32: CAF6D6F0
md5: 62023203c5d05281c7203e9292b444f8
sha1: 41f0c7c1ff9f12946412e862ce41bb017a315775
sha256: 2bd6b2ebd2d150258dce30f9b4d46790566f61defca08233b98f0a09c0153faf
sha512: 16388f58011ec5e00eb3735b662298370a1ed5900b8c95e62664e12af6f89fd9860411cf1ff3df521b33dcceb040cc37943ecccb6a3bb8dfa5d987a2e48c6dbe
ssdeep: 3072:MtdUcO74Aoem0EiRv1Zmmp06PwNjCnXuW2DrTI2h5E/ipflNwh654RCUjxo:Mt2z8Abm0Ewj1G6PsdW27IaaoNycQx
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1D524130997CD7F6FC5AB87368E852E64C7B0F56A8723C3AF2709C092545B7C9C22152B
sha3_384: de302650f92b5f15b10824943dc1fe1f70196c734ea5067fa6d300eed82056e82e6d1edf7f24843db087fd9c46aca285
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-02-01 13:31:01

Version Info:

Translation: 0x0000 0x04b0
Comments: update64x
CompanyName:
FileDescription: Tele64x
FileVersion: 1.0.0.0
InternalName: TelegramRAT.exe
LegalCopyright: Copyright © 2021
LegalTrademarks:
OriginalFilename: TelegramRAT.exe
ProductName: Tele64x
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

MSILHeracles.13493 (B) also known as:

LionicTrojan.MSIL.Stealer.i!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.MSILHeracles.13493
FireEyeGeneric.mg.62023203c5d05281
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
ALYacGen:Variant.MSILHeracles.13493
CylanceUnsafe
SangforInfostealer.MSIL.Stealer.gen
K7AntiVirusPassword-Stealer ( 005634971 )
K7GWPassword-Stealer ( 005634971 )
Cybereasonmalicious.3c5d05
BitDefenderThetaGen:NN.ZemsilF.34182.om0@aW1cp0j
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/PSW.Agent.RPT
TrendMicro-HouseCallTROJ_GEN.R002H0CB122
Paloaltogeneric.ml
KasperskyHEUR:Trojan-PSW.MSIL.Stealer.gen
BitDefenderGen:Variant.MSILHeracles.13493
AvastWin32:Trojan-gen
TencentMsil.Trojan-qqpass.Qqrob.Wklm
Ad-AwareGen:Variant.MSILHeracles.13493
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
SentinelOneStatic AI – Malicious PE
EmsisoftGen:Variant.MSILHeracles.13493 (B)
APEXMalicious
WebrootW32.Trojan.MSIL.Stealer
AviraTR/PSW.Agent.toipz
MAXmalware (ai score=89)
Antiy-AVLTrojan/Generic.ASMalwS.351DB22
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ZoneAlarmHEUR:Trojan-PSW.MSIL.Stealer.gen
GDataGen:Variant.MSILHeracles.13493
CynetMalicious (score: 100)
McAfeeArtemis!62023203C5D0
MalwarebytesSpyware.TelegramRAT
RisingMalware.Obfus/MSIL@AI.98 (RDM.MSIL:QvOrWDw8XGwXwh/9o1gEhQ)
eGambitUnsafe.AI_Score_74%
FortinetMSIL/Agent.RPT!tr.pws
AVGWin32:Trojan-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_60% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove MSILHeracles.13493 (B)?

MSILHeracles.13493 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment