Trojan

Trojan.WacatacRI.S15111266 information

Malware Removal

The Trojan.WacatacRI.S15111266 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.WacatacRI.S15111266 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Creates a slightly modified copy of itself

Related domains:

qq274314920.top
fget-career.com

How to determine Trojan.WacatacRI.S15111266?


File Info:

crc32: E545E157
md5: dae159a1d5f38d5d8b5e58f63cb1b938
name: panda77.4.exe
sha1: e520a0977b5528a4eec7a12e35346cd33c4e8540
sha256: 545157ae9da9623523b33b9cd7245bc3e18ab3f8254f94364ab22284ae36d1a6
sha512: c3a8a6e210251381a0e10b1a5b69ca85bd6856a8326a25909ff686674144642509bbbe8c8b2a261b712fb867c6fb8ea99142a8c5ef3076188a136d70ebdcb827
ssdeep: 98304:KhasXGrUG6rIXrMk8MSVLR+Ed2z3J5SbWf+YFClaJIWLV:K1GCmrM3BS3JQaf+H
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.WacatacRI.S15111266 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.307227
FireEyeGeneric.mg.dae159a1d5f38d5d
CAT-QuickHealTrojan.WacatacRI.S15111266
CylanceUnsafe
SangforMalware
BitDefenderGen:Variant.Zusy.307227
Cybereasonmalicious.1d5f38
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:RmnDrp
ClamAVWin.Trojan.Ramnit-1847
Kasperskynot-a-virus:HEUR:WebToolbar.Win32.Generic
Ad-AwareGen:Variant.Zusy.307227
EmsisoftGen:Variant.Zusy.307227 (B)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
DrWebWin32.Rmnet
Invinceaheuristic
SentinelOneDFI – Malicious PE
JiangminTrojan.Nystprac.bw
MAXmalware (ai score=84)
Antiy-AVLGrayWare/Win32.FlyStudio.a
ArcabitTrojan.Zusy.D4B01B
ZoneAlarmnot-a-virus:HEUR:WebToolbar.Win32.Generic
MicrosoftTrojan:Win32/Fuery.C!cl
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C4134329
BitDefenderThetaGen:NN.ZexaF.34152.@tW@aCpiCYcb
ALYacGen:Variant.Zusy.307227
VBA32BScope.Backdoor.Poison
MalwarebytesRiskWare.FlyStudio
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
eGambitUnsafe.AI_Score_100%
GDataGen:Variant.Zusy.307227
AVGWin32:RmnDrp
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.WacatacRI.S15111266?

Trojan.WacatacRI.S15111266 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment