Trojan

Trojan.MalPack.FFS malicious file

Malware Removal

The Trojan.MalPack.FFS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.MalPack.FFS virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Code injection with CreateRemoteThread in a remote process
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Injection with CreateRemoteThread in a remote process
  • Collects and encrypts information about the computer likely to send to C2 server
  • Creates a hidden or system file
  • Collects information to fingerprint the system

How to determine Trojan.MalPack.FFS?


File Info:

name: A95276D949AE7E70A527.mlw
path: /opt/CAPEv2/storage/binaries/f2d2a984cc7d2a832cfc4b4721b6175834e14328b6efe9ad0493595ee97eaaed
crc32: E9EABEB0
md5: a95276d949ae7e70a5273f187bd63394
sha1: d81255ee2f805669a8c01a37441d2828baece2cb
sha256: f2d2a984cc7d2a832cfc4b4721b6175834e14328b6efe9ad0493595ee97eaaed
sha512: 4cd28b27c46076c80ae61e89afe646cb8a70b35114172724efc4e911b6881a8765a0bb8e06eab2a550e05137961d65c1a2154a20b2c0ef2e7a26cda1a49315f4
ssdeep: 6144:5Vc4Y0oPrI80Jj/5aLUp7RLaJEVhBTfvfLkv2Q4VJdCfra6:nc4Y0q0jBaLU2ohhc2nVJds
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EC640169469D8633D03118F76EF1BA4EE9391A731F10805071806C16FE2FEB4667EACB
sha3_384: df7d60bba6d079a828f3a0ca8336742e00b44f64b44b10381b04f60ea617a64478afc86907eae9c3b360c29875999304
ep_bytes: 5458663d00f0907250b8605040008bc8
timestamp: 2007-04-18 11:23:51

Version Info:

0: [No Data]

Trojan.MalPack.FFS also known as:

Elasticmalicious (high confidence)
DrWebTrojan.PWS.PandaENT.4379
MicroWorld-eScanTrojan.VIZ.Gen.1
FireEyeGeneric.mg.a95276d949ae7e70
CAT-QuickHealTrojanPWS.Zbot.Gen
McAfeeGeneric-FANP!A95276D949AE
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.165366
SangforTrojan.Win32.Urausy.555487665
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 0040f64b1 )
K7AntiVirusTrojan ( 0040f64b1 )
BitDefenderThetaGen:NN.ZexaF.34084.tqW@aOO5RO
SymantecPacked.Generic.443
ESET-NOD32a variant of Win32/Kryptik.BLKA
TrendMicro-HouseCallTROJ_SPNR.14J813
ClamAVWin.Packed.Zbot-6948621-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.VIZ.Gen.1
NANO-AntivirusTrojan.Win32.PandaENT.crofwn
SUPERAntiSpywareTrojan.Agent/Gen-Fareit
AvastWin32:Downloader-UJP [Trj]
TencentWin32.Trojan.Generic.Lmuc
Ad-AwareTrojan.VIZ.Gen.1
EmsisoftTrojan.VIZ.Gen.1 (B)
ComodoTrojWare.Win32.Kryptik.BLU@52bnxs
BaiduWin32.Trojan.Kryptik.q
VIPRETrojan.Win32.Kryptik.mwe (v)
TrendMicroTROJ_SPNR.14J813
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
SophosML/PE-A + Troj/Zbot-GKZ
IkarusTrojan-Spy.Win32.Zbot
GDataTrojan.VIZ.Gen.1
JiangminTrojanSpy.Zbot.dvyg
MaxSecureTrojan.Malware.300983.susgen
AviraTR/Urausy.555487665
MAXmalware (ai score=84)
Antiy-AVLTrojan/Win32.Unknown
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.VIZ.Gen.1
MicrosoftPWS:Win32/Zbot!GO
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Fareit.R83793
Acronissuspicious
VBA32Heur.Trojan.Hlux
ALYacTrojan.VIZ.Gen.1
MalwarebytesTrojan.MalPack.FFS
APEXMalicious
RisingBackdoor.Agent!1.9D63 (CLASSIC)
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.BDPK!tr
AVGWin32:Downloader-UJP [Trj]
Cybereasonmalicious.949ae7
PandaTrj/Tepfer.B

How to remove Trojan.MalPack.FFS?

Trojan.MalPack.FFS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment