Trojan

Trojan.Waski.S28288290 (file analysis)

Malware Removal

The Trojan.Waski.S28288290 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Waski.S28288290 virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan.Waski.S28288290?


File Info:

name: 6DECBAF204522E1395A9.mlw
path: /opt/CAPEv2/storage/binaries/1b9daa8bc779ffc7a566636882fdc24ee4342d6e3ede624c2d14f29e33832523
crc32: 7DDC741F
md5: 6decbaf204522e1395a9f1d23b87aa02
sha1: 4d6fbf348878f7e881a3a48a3118ce82a306c4cc
sha256: 1b9daa8bc779ffc7a566636882fdc24ee4342d6e3ede624c2d14f29e33832523
sha512: 361cc9dc9cf287bcaea153a7ab035d6084e174f226417d8f6808f999bdfe1e0c934ec135cfa542cb3de36ee91a377d01911a2e59b17ad1aaa391c003338b8e09
ssdeep: 96:mBLYtOvLGaJlrqIZ6wAnQWRRUbw2CqDzq9THEWqNYRvZ7OGZetwU1lejZ5:mBLYtvIZmQWRRAwJ9o1GRvz4wUPQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T159E141296FD545B2F3BB8E718AF240C6AB74B1223E01CDAE50BB43454853AC1D9A1F0B
sha3_384: 2870a0e972db85c095cab7aa80e9ef8e7cb0016e02435bcb655987e37f2b87ffdbf76ec5c12cfb9d996a4f69e60bd5a5
ep_bytes: 81ec3408000053555633f65756897424
timestamp: 2014-05-13 06:44:14

Version Info:

0: [No Data]

Trojan.Waski.S28288290 also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
DrWebTrojan.DownLoad3.33216
MicroWorld-eScanTrojan.Ppatre.Gen.1
FireEyeGeneric.mg.6decbaf204522e13
CAT-QuickHealTrojan.Waski.S28288290
McAfeeGenericRXJA-WW!6DECBAF20452
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.Ppatre.Gen.1
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0055f33b1 )
K7GWTrojan-Downloader ( 0055f33b1 )
Cybereasonmalicious.48878f
BitDefenderThetaGen:NN.ZexaF.36738.auX@a8xcvAmi
VirITTrojan.Win32.Upatre.AZ
CyrenW32/S-47db96bb!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDownloader.Waski.E
APEXMalicious
ClamAVWin.Downloader.Upatre-9994794-0
KasperskyHEUR:Trojan-Downloader.Win32.Upatre.gen
BitDefenderTrojan.Ppatre.Gen.1
NANO-AntivirusTrojan.Win32.DownLoad3.gaapvu
AvastWin32:Evo-gen [Trj]
TencentTrojan-Downloader.Win32.Upatre.we
EmsisoftTrojan.Ppatre.Gen.1 (B)
F-SecureHeuristic.HEUR/AGEN.1320027
ZillyaDownloader.Waski.Win32.14885
TrendMicroTROJ_UPATRE.SM37
McAfee-GW-EditionBehavesLike.Win32.Generic.zt
Trapminemalicious.moderate.ml.score
SophosMal/EncPk-ACO
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan-Downloader.Upatre.BJ
JiangminTrojanSpy.Zbot.ffhh
WebrootW32.Trojan.Dropper
GoogleDetected
AviraHEUR/AGEN.1320027
MAXmalware (ai score=86)
Antiy-AVLTrojan/Win32.Waski.a
Kingsoftmalware.kb.a.997
XcitiumTrojWare.Win32.TrojanDownloader.Waski.ADW@8mzp93
ArcabitTrojan.Ppatre.Gen.1
ZoneAlarmHEUR:Trojan-Downloader.Win32.Upatre.gen
MicrosoftTrojan:Win32/Vindor!pz
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Upatre.R158192
Acronissuspicious
VBA32SScope.Trojan-Downloader.1454
ALYacTrojan.Ppatre.Gen.1
TACHYONTrojan/W32.Ppatre.7450.C
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SM37
RisingDropper.Injector!8.DC (TFE:3:JrFJf4jCRlD)
IkarusTrojan-Downloader.Win32.Waski
MaxSecureTrojan.Upatre.Gen
FortinetW32/Waski.B!tr.dldr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Waski.S28288290?

Trojan.Waski.S28288290 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment