Trojan

TrojanDropper:Win32/Pistolar!pz (file analysis)

Malware Removal

The TrojanDropper:Win32/Pistolar!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDropper:Win32/Pistolar!pz virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to masquerade or mimic a legitimate process or file name
  • Attempts to modify Explorer settings to prevent file extensions from being displayed
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine TrojanDropper:Win32/Pistolar!pz?


File Info:

name: 4EF51D5EEEC29C5B402A.mlw
path: /opt/CAPEv2/storage/binaries/4d03c90bed2a9add9daa8fad9be6f01f9284749cdd9c9af566570b639b46dc48
crc32: 5D87D2D7
md5: 4ef51d5eeec29c5b402ae5df24a71aa0
sha1: f98b7f3292deb5f651bc27c349eac7984c5eb837
sha256: 4d03c90bed2a9add9daa8fad9be6f01f9284749cdd9c9af566570b639b46dc48
sha512: 636363b2de807b35ff440de37179e1b41208abf4abc64a3f035efa47a767056c7970488012a4eb4c7dcd354c5fcfacbf3a6201c7609fac8102be07acb1459574
ssdeep: 6144:EuIlWqB+ihabs7Ch9KwyF5LeLodp2D1Mmakda0qLqIYT:v6Wq4aaE6KwyF5L0Y2D1PqLC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19D6413EA72A4E901D8B80272FE530381C5F07931EBB99B7BB1106A172CEF0156E5B75D
sha3_384: ef815820f35b1f05a5c932c97a171912f553b4b15471804bae18c6bbf8dc54ed4a21b3ed2e74445df8f94dbd5700a361
ep_bytes: 60be007047008dbe00a0f8ff57eb0b90
timestamp: 2012-01-29 21:32:28

Version Info:

FileDescription:
FileVersion: 3, 3, 8, 1
CompiledScript: AutoIt v3 Script: 3, 3, 8, 1
Translation: 0x0809 0x04b0

TrojanDropper:Win32/Pistolar!pz also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.Generic.lXua
Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.Generic.8121236
CAT-QuickHealTrojan.AutoIt.Pistolar.A
SkyhighBehavesLike.Win32.DropperAutoIt.fc
McAfeeAutoit.Dropper.gen.a
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.Generic.8121236
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 700000111 )
AlibabaTrojan:Win32/Pistolar.48e
K7GWTrojan ( 700000111 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Generic.D7BEB94
BaiduAutoIt.Worm.Agent.a
VirITTrojan.Win32.Autoit.ES
SymantecW32.SillyFDC
ESET-NOD32Win32/Autoit.HZ
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Autoit-6981134-0
KasperskyTrojan.Win32.Autoit.blz
BitDefenderTrojan.Generic.8121236
NANO-AntivirusTrojan.Script.AutoIt.dbycns
AvastAutoIt:Agent-DP [Trj]
TencentWin32.Trojan.Autoit.Mqil
EmsisoftTrojan.Generic.8121236 (B)
F-SecureTrojan.TR/Rogue.JH.7554630
DrWebBackDoor.IRC.Bot.3238
ZillyaTrojan.AutoIT.Win32.183967
SophosW32/AutoIt-QA
IkarusTrojan.Win32.Autoit
JiangminTrojan.MSIL.Zapchast.ag
VaristW32/AutoIt.AK.gen!Eldorado
AviraTR/Rogue.JH.7554630
Antiy-AVLTrojan[Dropper]/Script.Pistolar
Kingsoftmalware.kb.b.866
XcitiumTrojWare.Win32.Autoit.n@4p0xzq
MicrosoftTrojanDropper:Win32/Pistolar!pz
ZoneAlarmTrojan.Win32.Autoit.blz
GDataTrojan.Generic.8121236
GoogleDetected
AhnLab-V3Win-Trojan/Autoit.305824
BitDefenderThetaAI:Packer.05DA809615
MAXmalware (ai score=87)
VBA32Worm.Autoit.Rush
Cylanceunsafe
PandaTrj/Autoit.gen
RisingDropper.Pistolar/Autoit!1.A603 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Autoit.HZ!worm
AVGAutoIt:Agent-DP [Trj]
Cybereasonmalicious.292deb
DeepInstinctMALICIOUS

How to remove TrojanDropper:Win32/Pistolar!pz?

TrojanDropper:Win32/Pistolar!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment