Trojan

Trojan:O97M/FalseCobra.A!dha malicious file

Malware Removal

The Trojan:O97M/FalseCobra.A!dha is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:O97M/FalseCobra.A!dha virus can do?

  • The office file contains a macro
  • The office file contains a macro with auto execution
  • The office file contains anomalous features
  • The office file contains a macro with potential indicators of compromise
  • The office file contains a macro with suspicious strings

Related domains:

z.whorecord.xyz

How to determine Trojan:O97M/FalseCobra.A!dha?


File Info:

crc32: C8D3A1E7
md5: 1479b531f30b50ed4c2509d4a49664bd
name: upload_file
sha1: 8316230b4dcee8934b06e9a85a66686a82831cd4
sha256: fa115fb6499783cabc60f6b0b893a5b622ba45e6f85fa02de5e6af1a547dbb4b
sha512: 98c449b377dc533a8f6cc34b365b1a11317da178532e66daab4ce84dc2f43f61162d86352aa737b57536b1b147b30f74974670811538a1697c011c42d15c02d6
ssdeep: 1536:Gc8tnpyTfy2+ipQiKDAlGoVpAO1ripeRU+a98neW9uxjF+FayUt:+nafyp0QpAEoDJ0eNnwjF6a
type: Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1252, Title: 2020 Parliament Election, Author: Stegen, Keywords: 2020Election, Template: Normal.dotm, Last Saved By: Higgsx, Revision Number: 95, Name of Creating Application: Microsoft Office Word, Total Editing Time: 07:04:00, Create Time/Date: Sat Aug 15 13:27:00 2020, Last Saved Time/Date: Wed Sep 9 19:44:00 2020, Number of Pages: 1, Number of Words: 844, Number of Characters: 4815, Security: 0

Version Info:

0: [No Data]

Trojan:O97M/FalseCobra.A!dha also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanVB.Heur2.PwShell.2.ED3838F5.Gen
CAT-QuickHealOle.Trojan.A808334
McAfeeRDN/Generic Downloader.x
SangforMalware
SymantecTrojan.Gen.NPE
TrendMicro-HouseCallTrojan.W97M.POWLOAD.THJOEBO
AvastPwrSh:Downloader-AB [Trj]
KasperskyHEUR:Trojan.MSOffice.SAgent.gen
BitDefenderVB.Heur2.PwShell.2.ED3838F5.Gen
NANO-AntivirusTrojan.Ole2.Vbs-heuristic.druvzi
ViRobotDOC.Z.Agent.110592.GT
RisingHeur.Macro.powershell.a (CLASSIC)
Ad-AwareVB.Heur2.PwShell.2.ED3838F5.Gen
TACHYONSuspicious/W97M.Obfus.Gen.8
EmsisoftVB.Heur2.PwShell.2.ED3838F5.Gen (B)
ComodoMalware@#16mj9hivmfjnp
F-SecureMalware.W97M/FalseCobra.jpldu
DrWebmodification of W97M.Suspicious.1
TrendMicroTrojan.W97M.POWLOAD.THJOEBO
McAfee-GW-EditionBehavesLike.OLE2.Downloader.cg
FireEyeVB.Heur2.PwShell.2.ED3838F5.Gen
SentinelOneDFI – Malicious OLE
AviraW97M/FalseCobra.jpldu
MicrosoftTrojan:O97M/FalseCobra.A!dha
ArcabitHEUR.VBA.CG.1
AegisLabTrojan.MSWord.Macro.4!c
ZoneAlarmHEUR:Trojan.MSOffice.SAgent.gen
GDataMacro.Trojan-Downloader.Agent.ADV
CynetMalicious (score: 85)
MAXmalware (ai score=83)
ZonerProbably Heur.W97Obfuscated
ESET-NOD32a variant of Generik.DIZNTBW
TencentHeur.Macro.Generic.a.e0205fc3
IkarusTrojan-Downloader.Script
FortinetVBA/Agent.DIZNTBW!tr
AVGPwrSh:Downloader-AB [Trj]
Qihoo-360virus.office.obfuscated.1

How to remove Trojan:O97M/FalseCobra.A!dha?

Trojan:O97M/FalseCobra.A!dha removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment