Malware

What is “Python/Filecoder.IL”?

Malware Removal

The Python/Filecoder.IL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Python/Filecoder.IL virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • CAPE detected the PyInstaller malware family

How to determine Python/Filecoder.IL?


File Info:

name: F46EB1DA34D733D60F31.mlw
path: /opt/CAPEv2/storage/binaries/e16fc7b99849314f39da35aec0693ea7b71b42b8b681d539a269aea86b63899e
crc32: 34B95DBF
md5: f46eb1da34d733d60f31ad0befeea217
sha1: 07ca63dfdd827ffe057cebc83eb8b4b4f7e961f8
sha256: e16fc7b99849314f39da35aec0693ea7b71b42b8b681d539a269aea86b63899e
sha512: f36eb0c2a287c722d5ef40bcdb99a79ab88e81c9a4a4b7c5b48d91fcc78f022dfea8d20f85534385ce927602c90ca6bf507a387df02a0f6b7484ed99a9f4da95
ssdeep: 196608:DUxMOHyjWSCoP1HSsimvlG2xCraGCOP0qy:DCSjP1P1pimtP4aGLZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B076231117D0E3B7EDD2297F4F33C2271A6F6B95A3B41CA25E00519D7922E53A0EB90E
sha3_384: 5faaeeec0ca11c15837e464c73a81ed71a19fa20ef2d3f012156a953b6ba1731d77a944710d0781ce4c1c7bcc05292b9
ep_bytes: e8a0040000e97afeffff558bec6a00ff
timestamp: 2021-08-01 04:40:34

Version Info:

0: [No Data]

Python/Filecoder.IL also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Bulz.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.593226
FireEyeGeneric.mg.f46eb1da34d733d6
McAfeeArtemis!F46EB1DA34D7
CylanceUnsafe
ZillyaTrojan.Disco.Win64.61
SangforTrojan.Win32.Sabsik.FL
CrowdStrikewin/malicious_confidence_60% (W)
SymantecML.Attribute.HighConfidence
ESET-NOD32Python/Filecoder.IL
APEXMalicious
Paloaltogeneric.ml
BitDefenderGen:Variant.Bulz.593226
AvastFileRepMalware
Ad-AwareGen:Variant.Bulz.593226
EmsisoftGen:Variant.Bulz.593226 (B)
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.OxyPump.wc
GDataWin32.Trojan.PSE.F31RV1
MAXmalware (ai score=80)
Antiy-AVLTrojan/Generic.ASMalwS.34559CE
MicrosoftTrojan:Win32/Woreflint.A!cl
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win.Backdoor.C4553837
BitDefenderThetaGen:NN.ZexaF.34182.@xZ@a8my7R
ALYacGen:Variant.Bulz.593226
TrendMicro-HouseCallTROJ_GEN.R011H0CIG21
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.120471346.susgen
FortinetW32/PossibleThreat
AVGFileRepMalware

How to remove Python/Filecoder.IL?

Python/Filecoder.IL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment