Trojan

Trojan:Script/Wacatac.H!ml removal

Malware Removal

The Trojan:Script/Wacatac.H!ml is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Script/Wacatac.H!ml virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • A file with an unusual extension was attempted to be loaded as a DLL.
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Trojan:Script/Wacatac.H!ml?


File Info:

name: 3DCD07FF841B0B47C647.mlw
path: /opt/CAPEv2/storage/binaries/89f59a65509ae08b2b3147bbc0926e124fbf66558cf9d54a0af98906bf6b1ef2
crc32: EB84FECB
md5: 3dcd07ff841b0b47c6478fa606ffc239
sha1: 334a06ed7c58e4084892e9d9963d296d53397a88
sha256: 89f59a65509ae08b2b3147bbc0926e124fbf66558cf9d54a0af98906bf6b1ef2
sha512: 35bd95453ba9d7988e11799455a56b66a1258811db712c46f832e770c4a7ec0f79b22432dfb004401f2f09d3148917d3c7336018b9ebbddbcadf5eb524e3a69c
ssdeep: 1536:7vK3IIf9AeFq/HomJ471swGnUt7PIgEDTKKg+KzSbN:7ge9/Hof71Dt7ARJgPzSZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16C43F144FB3C9AA9E9CFE932B9A7C90844A97C205771274F5EDAF957037074312268B3
sha3_384: 2ca4a0273f089b3fb321752265350fb26c45a04c9fce239e9afac8e28947bba06e81a79751f35a0d52f1a32afaa57f34
ep_bytes: 60be000042008dbe0010feff57eb0b90
timestamp: 2022-07-24 17:01:21

Version Info:

Comments: Available on https://forum.ru-board.com
CompanyName: Warez_Down
FileVersion: 0.3
FileDescription: jv16 PowerTools 7.x *KeyGen*
InternalName: keygen
LegalCopyright: Copyright © 2022 Warez_Down
OriginalFilename: keygen.exe
ProductName: KeyGen
ProductVersion: 0.3
Translation: 0x0409 0x04e4

Trojan:Script/Wacatac.H!ml also known as:

CynetMalicious (score: 100)
McAfeeRDN/Generic.dx
SangforTrojan.Win32.Agent.Vb4r
Cybereasonmalicious.f841b0
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
APEXMalicious
Paloaltogeneric.ml
McAfee-GW-EditionBehavesLike.Win32.Trojan.qc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.3dcd07ff841b0b47
SentinelOneStatic AI – Malicious PE
MicrosoftTrojan:Script/Wacatac.H!ml
GDataWin32.Application.Keygen.B
VBA32BScope.TrojanPSW.Qqshou
MalwarebytesMalware.Heuristic.1003
IkarusVirus.Win32.Crypt.CQW
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
BitDefenderThetaGen:NN.ZexaF.34806.dmKfa83pUNei

How to remove Trojan:Script/Wacatac.H!ml?

Trojan:Script/Wacatac.H!ml removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment