Spy

Python/Spy.Agent.CG (file analysis)

Malware Removal

The Python/Spy.Agent.CG is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Python/Spy.Agent.CG virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the PyInstaller malware family
  • Deletes executed files from disk

How to determine Python/Spy.Agent.CG?


File Info:

name: 97766937C8D41850BAD1.mlw
path: /opt/CAPEv2/storage/binaries/696d3894d122154c4e8f315173f268132bdf112d0a113a43ca9b32c06326bfcf
crc32: 49D13104
md5: 97766937c8d41850bad1dd369d927d02
sha1: d0f08f32d2e46f355d0085ad0d23a1370eee21a8
sha256: 696d3894d122154c4e8f315173f268132bdf112d0a113a43ca9b32c06326bfcf
sha512: 94f438ab51180e63bc53d2608e1dbb5d133b1e299776daa105d0b8e6c8bd59e3f0145b8f92fe7e429a09c5cd629f318a3ee9894b0e49d0f3dc3c4b80eba180cb
ssdeep: 98304:5CEzTSp3NeJKOoqLR2+9F1HJ/ocr4Rt8PnP22YdHLbuvEMfAdO+PXt4NhcN:kEzT63NvqLRpucr4r8mvBuvExWNhcN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EE66220225BC8FE6C8022D3991A0F3360E642F90DA868AB657F17DD7F9355A5FE244DC
sha3_384: 875f0090c915a7ec9ddaccfc6ce841d39c8def00da5c060fe0decdc610f420185a285479854afa526fa7b2ebfc55f630
ep_bytes: e866050000e978feffffcccccccccccc
timestamp: 2022-03-03 13:15:57

Version Info:

0: [No Data]

Python/Spy.Agent.CG also known as:

MicroWorld-eScanTrojan.GenericKD.61497993
ClamAVWin.Malware.Fugrafa-9938779-0
FireEyeGeneric.mg.97766937c8d41850
McAfeeArtemis!97766937C8D4
CylanceUnsafe
VIPRETrojan.GenericKD.61497993
SangforTrojan.Win32.Agent.Vc70
K7AntiVirusTrojan ( 005644291 )
BitDefenderTrojan.GenericKD.61497993
K7GWTrojan ( 005644291 )
CrowdStrikewin/malicious_confidence_70% (W)
ArcabitTrojan.Generic.D3AA6289
SymantecTrojan.Gen.2
Elasticmalicious (high confidence)
ESET-NOD32Python/Spy.Agent.CG
Paloaltogeneric.ml
CynetMalicious (score: 100)
AlibabaTrojanSpy:Win32/Generic.ba5343f9
Ad-AwareTrojan.GenericKD.61497993
SophosMal/Generic-S
F-SecureTrojan.TR/Spy.Agent.irprt
McAfee-GW-EditionArtemis!Virus
EmsisoftTrojan.GenericKD.61497993 (B)
AviraTR/Spy.Agent.arwcy
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataWin32.Trojan.Agent.W810FX
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R497733
ALYacTrojan.GenericKD.61497993
MAXmalware (ai score=89)
MalwarebytesMalware.AI.1679675805
TrendMicro-HouseCallTROJ_GEN.R002H0DHP22
IkarusVirus.Win32.Slugin
AVGWin32:Evo-gen [Trj]
AvastWin32:Evo-gen [Trj]

How to remove Python/Spy.Agent.CG?

Python/Spy.Agent.CG removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment