Malware

About “Pykspa.1” infection

Malware Removal

The Pykspa.1 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Pykspa.1 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Starts servers listening on 0.0.0.0:23584
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Looks up the external IP address
  • Sniffs keystrokes
  • Attempts to stop active services
  • A process attempted to delay the analysis task by a long amount of time.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Attempts to disable UAC
  • Attempts to modify UAC prompt behavior

Related domains:

whatismyipaddress.com
www.whatismyip.com
www.whatismyip.ca
whatismyip.everdot.org
www.showmyipaddress.com
www.youtube.com
pmqyiytmmx.info
cgukwi.com
wcqmugmkea.com
qciosegy.com
hfxopzdipuuv.info
sajwemq.net
pbeiiz.net
yhcobqp.net
fbnyyl.net
lvdcxndqfbx.com
ggugvtmktusm.net
lqbovzjihohy.info
qscuwesy.org
cwycgooioccq.org
gxtgdiwp.info
mcsaqymsqu.org
auvpkazrjyzd.net
dwzmnrj.org
cgmewuao.com
yqptagacn.info
eezpetudsgby.net
nytljqj.com
ghzzxunmwmj.info
fboeuwobai.net
dmdjjifv.info
wevadwrd.info
jrvabgzilsf.org
rgmeetrz.info
xlhmwhx.info
osrwxok.net
okgbne.net
zsrrov.info
zixobczkv.org
sxfgcr.net
uvimpmehsu.info
ufelzrktoeob.net
eygiowgqsc.org
ykvxjfp.info
ajmpqkruji.net
rxphgnqpxcfh.net
axhmlgnjshl.info
ngbaqzimfi.info
lpjyxmhwx.net
habkbu.info
ebzizmtkpa.net
rmnkuij.net
ckweqcigmy.org
jjrbfm.info

How to determine Pykspa.1?


File Info:

crc32: FB1CA8F3
md5: a7a4425e76fc9c1208a43c1cd9db92eb
name: A7A4425E76FC9C1208A43C1CD9DB92EB.mlw
sha1: 287155fd33415ca0a6600117307994e80853a378
sha256: e4be1ca51b21f2d903d05515ee3794f649db55c9c9ee116d1f1c158f90e39973
sha512: 8e4d60affc3b34415ccecd893fd9c098a66df3e50103e1ffd58509b7281823274352aa5aa3ae2df0264a60412e72b3170d43ec7dd13996573c063829c0a36551
ssdeep: 6144:M3Be8ySm8hQAAIfFrRXuEE+0l97mKwKbwHVlkk86JQPDHDdx/Qtqa:V/zkFF+EExZmKbbQVDPJQPDHvd
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Pykspa.1 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Siggen.36621
MicroWorld-eScanGen:Variant.Pykspa.1
FireEyeGeneric.mg.a7a4425e76fc9c12
CAT-QuickHealTrojan.Mauvaise.SL1
Qihoo-360Worm.Win32.Pykse.A
ALYacGen:Variant.Pykspa.1
CylanceUnsafe
VIPREWorm.Win32.Skyper.b (v)
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 003da8d71 )
BitDefenderGen:Variant.Pykspa.1
K7GWTrojan ( 003da8d71 )
Cybereasonmalicious.e76fc9
BitDefenderThetaGen:NN.ZexaF.34590.rnW@a8xcD8f
CyrenW32/Pykspa.A.gen!Eldorado
SymantecW32.Pykspa.D
TotalDefenseWin32/Vilsel.CE
ZonerTrojan.Win32.24407
TrendMicro-HouseCallWORM_VILSEL.SMC
AvastWin32:Renos-KY [Trj]
ClamAVWin.Worm.Pykspa-1
KasperskyTrojan-Ransom.Win32.Blocker.jcen
NANO-AntivirusTrojan.Win32.Agent.ctkmgw
ViRobotTrojan.Win32.Blocker.Gen.B
RisingWorm.Autorun!1.BC87 (CLOUD)
Ad-AwareGen:Variant.Pykspa.1
SophosML/PE-A + W32/Pykse-F
ComodoWorm.Win32.Autorun.Agent_TG0@1isiwy
F-SecureTrojan-Downloader:W32/Renos.gen!T
BaiduWin32.Worm.Autorun.o
ZillyaTrojan.Vilsel.Win32.3418
TrendMicroWORM_VILSEL.SMC
McAfee-GW-EditionBehavesLike.Win32.Pykse.tz
SentinelOneStatic AI – Malicious PE
EmsisoftGen:Variant.Pykspa.1 (B)
IkarusTrojan.Win32.AntiAV
JiangminTrojan/Blocker.lhz
WebrootW32.Trojan.Vilsel.Gen
AviraTR/Agent.327680.A
Antiy-AVLTrojan/Win32.AntiAV
MicrosoftWorm:Win32/Pykspa.C
ArcabitTrojan.Pykspa.1
SUPERAntiSpywareWorm.SkypeBot
ZoneAlarmTrojan-Ransom.Win32.Blocker.jcen
GDataWin32.Trojan.PSE.KF4I2L
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zepfod.R4378
Acronissuspicious
McAfeeW32/Pykse.worm.gen.a
MAXmalware (ai score=88)
VBA32Trojan.ChidikSun.28205
MalwarebytesGeneric.Worm.Agent.DDS
PandaTrj/Vilsel.B
APEXMalicious
ESET-NOD32Win32/AutoRun.Agent.TG
TencentWorm.Win32.Pykspa.a
YandexTrojan.GenAsa!R41E4MI3PTc
TACHYONRansom/W32.Blocker.1331200.B
eGambitUnsafe.AI_Score_99%
FortinetW32/Agent.XEK!tr
AVGWin32:Renos-KY [Trj]
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Ransom.Blocker.iprw

How to remove Pykspa.1?

Pykspa.1 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment