Malware

What is “Python/Agent.CM”?

Malware Removal

The Python/Agent.CM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Python/Agent.CM virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Writes a potential ransom message to disk
  • CAPE detected the PyInstaller malware family

How to determine Python/Agent.CM?


File Info:

name: C971AAF8B9B8B4504D9E.mlw
path: /opt/CAPEv2/storage/binaries/3e0ad711c5a1bfe4792854e2fa8db745fb29e0e9d1cb6374b6d9fbfb0fa9c57d
crc32: 641A37DF
md5: c971aaf8b9b8b4504d9e859b0a0faf90
sha1: 6cf59a13c5f89031fc49e70f767327dfd7e9075e
sha256: 3e0ad711c5a1bfe4792854e2fa8db745fb29e0e9d1cb6374b6d9fbfb0fa9c57d
sha512: 1c35adaf0afdb0d4548bf3c309cdf554c5667e78ce375d0a5a2018e0f0b2a472b8507a19197b3554ae6cc5efed2b2e1108a65a6510009cf13c4a131c7ee2cd38
ssdeep: 393216:RvUWSQcXu8mSxrInEroX/lh2plfEqirRRoCWcRS3JTEon8dWMs:9UmcXxzx0ErUNQppwv2TREongs
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T1D4F6331C2FE118DDF6B6803065318602957978EF0790D49BFAB8139B4FD7ADA9F36A40
sha3_384: 65fe3d2808f405ec551a254d8a8287a857a1e0889b1882b753075e666ac9455856f41a550204231b88d1bf2adeb87239
ep_bytes: 4883ec28e8f70400004883c428e97afe
timestamp: 2021-08-01 04:39:46

Version Info:

0: [No Data]

Python/Agent.CM also known as:

McAfeeArtemis!C971AAF8B9B8
MalwarebytesSpyware.PasswordStealer
SangforTrojan.Win32.Wacatac.B
K7AntiVirusTrojan ( 0052923b1 )
AlibabaTrojanSpy:Win32/Almi_KeyLogger.e
K7GWTrojan ( 0052923b1 )
CyrenW64/S-d6d7eeed!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32Python/Agent.CM
APEXMalicious
KasperskyTrojan-Ransom.Win64.Alien.bj
AvastFileRepMalware
SophosMal/Generic-S
ComodoTrojWare.Win32.Agent.arvzh@0
DrWebTrojan.Siggen16.17544
ZillyaTrojan.Disco.Win32.1337
TrendMicroTrojan.Win64.WACATAC.AE
McAfee-GW-EditionBehavesLike.Win64.Generic.wc
IkarusTrojan.Python.Agent
AviraTR/Drop.Agent.caokt
Antiy-AVLTrojan/Generic.ASMalwS.34493BB
MicrosoftTrojan:Win32/Wacatac.B!ml
GridinsoftRansom.Win64.Wacatac.sa
GDataWin32.Trojan-Stealer.PyStealer.0825X4
CynetMalicious (score: 99)
VBA32TrojanRansom.Win64.Alien
CylanceUnsafe
TrendMicro-HouseCallTrojan.Win64.WACATAC.AE
TencentWin32.Trojan.Agent.Szkz
FortinetPython/Agent.CM!tr
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.133195122.susgen

How to remove Python/Agent.CM?

Python/Agent.CM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment