Trojan

Trojan.Generic.15591112 information

Malware Removal

The Trojan.Generic.15591112 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Generic.15591112 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Korean
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Anomalous binary characteristics

How to determine Trojan.Generic.15591112?


File Info:

name: 2589275387D5AF4C9006.mlw
path: /opt/CAPEv2/storage/binaries/0aa2d0e3fe731005297b45696613ba54e82fab1e477e4fa853bf70d11901b898
crc32: 082FAEC6
md5: 2589275387d5af4c90069f51a4505c0c
sha1: 132b7e0e614d16b1d4366554d635d596117b74cf
sha256: 0aa2d0e3fe731005297b45696613ba54e82fab1e477e4fa853bf70d11901b898
sha512: b924c5a736561296fb93cf1baef2d91234db6e57299aa6b4554ec78bbe313f2ae057344149e20fa15b4574cdc1c25d45855035f2bdd2eb04ad2619d178860907
ssdeep: 12288:VHjcoe9PH96vB/fAuBcm9TyOE/xG3muGx44MG4Yx:VDgINfAuBcgcZG2uG24MG4Y
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T155251212A6005888F70E0B706946F8E04A99DDBD58D9F50EF5BCBE37A8360579EB740F
sha3_384: 14888c1dc20e0dcd20b22e1810c1405d8d59c0b18513ea7df71d8c17c9917a01ee3823da85f55fd1c2e7132c76a49a32
ep_bytes: 60e80000000058055a0b00008b3003f0
timestamp: 2012-11-09 07:14:38

Version Info:

CompanyName: Apple
FileDescription: Apple iCloud
FileVersion: 1, 0, 0, 85
InternalName: Apple New Ipad
LegalCopyright: Copyright (C) 2012
OriginalFilename: app stroe
ProductName: Apple iPad
ProductVersion: 1, 0, 0, 85
Translation: 0x0412 0x04b0

Trojan.Generic.15591112 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.15591112
FireEyeGeneric.mg.2589275387d5af4c
CAT-QuickHealTrojan.Gupboot.B.mue
McAfeeGeneric BackDoor.zw
CylanceUnsafe
ZillyaTrojan.Urelas.Win32.98
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderTrojan.Generic.15591112
K7GWTrojan ( 004da1581 )
K7AntiVirusTrojan ( 004da1581 )
BaiduWin32.Rootkit.Agent.s
VirITTrojan.Win32.Generic.CDAZ
CyrenW32/Xpack.D.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Urelas.AR
APEXMalicious
ClamAVWin.Trojan.Urelas-6997280-0
KasperskyRootkit.Win32.Plite.pvf
NANO-AntivirusTrojan.Win32.AVKill.cmxsfa
RisingTrojan.Agent!1.9D23 (RDMK:cmRtazoqAEAhJOmb3NS1Fy57V7bJ)
SophosML/PE-A + Troj/Gupboot-C
ComodoTrojWare.Win32.Gupboot.AD@8mgdy0
DrWebTrojan.AVKill.25437
VIPRETrojan.Win32.Urelas.b (v)
TrendMicroTROJ_SPNR.30CE13
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.tt
EmsisoftTrojan.Generic.15591112 (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Generic.cgfj
AviraTR/Crypt.XPACK.ncr
Antiy-AVLTrojan/Generic.ASMalwS.2C41F5
KingsoftHeur.SSC.2672588.1216.(kcloud)
MicrosoftTrojan:Win32/Gupboot.B
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
GDataWin32.Trojan.PSE.1WIQGLX
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Wecod.R41369
BitDefenderThetaGen:NN.ZexaF.34182.anxaaO0OE1gO
ALYacTrojan.Generic.15591112
MAXmalware (ai score=85)
VBA32Trojan.Packed
MalwarebytesTrojan.Urelas
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_SPNR.30CE13
TencentTrojan.Win32.Agent.afj
YandexTrojan.GenAsa!fWGIDzv5BFM
IkarusTrojan.Win32.Urelas
eGambitUnsafe.AI_Score_99%
FortinetW32/Generic.AC.28C4AD!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.387d5a
AvastWin32:Trojan-gen
MaxSecureTrojan.Malware.121218.susgen

How to remove Trojan.Generic.15591112?

Trojan.Generic.15591112 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment