Trojan

About “TrojanDropper:O97M/GraceWire.CU!MTB” infection

Malware Removal

The TrojanDropper:O97M/GraceWire.CU!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDropper:O97M/GraceWire.CU!MTB virus can do?

  • The office file contains 9 macros
  • The office file contains a macro with auto execution
  • The office file contains anomalous features
  • The office file contains a macro with potential indicators of compromise
  • The office file contains a macro with suspicious strings

Related domains:

z.whorecord.xyz

How to determine TrojanDropper:O97M/GraceWire.CU!MTB?


File Info:

crc32: 6FD24613
md5: 8edf39ec6fa723426aff97252b69b2ae
name: upload_file
sha1: bb05f29e0386ee9acb14403182e7b1faf553a479
sha256: 2c6f0629707ae81ab6f5870efc27a6cea2918f18744c8c52cf1b1a84d00ed71f
sha512: 461d378de4c7295870fa4fd52cf1f8518b14040f1b78c187c0631d7600a45b0dfb536f33530a8f0979f2c12526750d70aedc6949297c43b9a6c13fcbc9a06a61
ssdeep: 12288:sdc3fcFZbtBbU4UvL7j5/Si/oRouPCok/vj4WoeDrHF1:s8fcvG4oLtSHqo8vjRbHF
type: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.3, Code page: 1252, Last Saved By: Administrator, Name of Creating Application: Microsoft Excel, Create Time/Date: Mon Jun 22 11:41:03 2020, Last Saved Time/Date: Thu Aug 13 12:22:36 2020, Security: 0

Version Info:

0: [No Data]

TrojanDropper:O97M/GraceWire.CU!MTB also known as:

Elasticmalicious (moderate confidence)
ClamAVWin.Dropper.Hideproc-6663113-0
McAfeeRDN/Generic Dropper
AegisLabTrojan.Script.Generic.4!c
SangforMalware
SymantecTrojan.Mdropper
ESET-NOD32a variant of VBA/TrojanDropper.Agent.BJR
AvastScript:SNH-gen [Trj]
CynetMalicious (score: 85)
KasperskyHEUR:Trojan.Script.Generic
BitDefenderTrojan.GenericKD.34354085
MicroWorld-eScanTrojan.GenericKD.34354085
TencentWin32.Trojan.Razy.Efvj
Ad-AwareTrojan.GenericKD.34354085
Comodo.UnclassifiedMalware@0
F-SecureMalware.VBS/Drop.Agent.sxluz
DrWebTrojan.DownLoader34.18684
FireEyeTrojan.GenericKD.34354085
SentinelOneDFI – Malicious OLE
AviraVBS/Drop.Agent.sxluz
MAXmalware (ai score=99)
Antiy-AVLTrojan[Exploit]/OLE.CVE-2014-6352
MicrosoftTrojanDropper:O97M/GraceWire.CU!MTB
ArcabitTrojan.Generic.D20C33A5
ViRobotXLS.Z.Agent.738304
ZoneAlarmHEUR:Trojan.Script.Generic
GDataTrojan.GenericKD.34354085
ALYacTrojan.Downloader.XLS.gen
TACHYONSuspicious/W97.NS.Gen
ZonerProbably Heur.W97Call
RisingDropper.StealthLoader/VBA!1.C75E (CLASSIC)
IkarusTrojan-Dropper.VBA.Agent
FortinetW32/Dropper.GIF!tr
AVGScript:SNH-gen [Trj]
Qihoo-360Generic/Trojan.Script.ed4

How to remove TrojanDropper:O97M/GraceWire.CU!MTB?

TrojanDropper:O97M/GraceWire.CU!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment