Trojan

Trojan:Win32/GraceWire.BL!dha malicious file

Malware Removal

The Trojan:Win32/GraceWire.BL!dha is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/GraceWire.BL!dha virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the shellcode patterns malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/GraceWire.BL!dha?


File Info:

name: 1F72054DB015765232F8.mlw
path: /opt/CAPEv2/storage/binaries/84f7c3fcf3a53f37ecbb21d0b9368d332901fe8c3f06b3d1a92123479c567c95
crc32: D7D1568F
md5: 1f72054db015765232f83e9c2e14ece9
sha1: ae519a0d94d438879c226de569918eb034599217
sha256: 84f7c3fcf3a53f37ecbb21d0b9368d332901fe8c3f06b3d1a92123479c567c95
sha512: 877912d3cb9e93bc1c69735b74cc7bcd24b17d073e99547b40c1b97a07d943f7432a9bb7b91e3ac6384efab0e0232998109645954a08e29384ffadcdc8a4fcf8
ssdeep: 6144:w019JRWc5TaSdzyNJpeAOG7bwci1VnlF:w+J3CJpeAO7dh
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T13A54D05986B62448D4B55835E3895CBA5D156F333B44EC4393AB02B7DCB002BF60BABF
sha3_384: 467d7bba025948f8599a44ae39b957bff5fa34d8aa56c9770a286814c95a6af5239c8bb37bf19c07f0a3ec936dfab49f
ep_bytes: 558bec83ec50891d302b0410893d202b
timestamp: 2016-09-09 20:05:36

Version Info:

0: [No Data]

Trojan:Win32/GraceWire.BL!dha also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Agent.Y!c
DrWebTrojan.DownLoader30.20316
MicroWorld-eScanGen:Variant.Razy.566869
FireEyeGeneric.mg.1f72054db0157652
SkyhighTrojan-FRPG!1F72054DB015
McAfeeTrojan-FRPG!1F72054DB015
Cylanceunsafe
ZillyaBackdoor.Agent.Win32.75071
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/GraceWire.25aaa99b
K7GWTrojan ( 005597681 )
K7AntiVirusTrojan ( 005597681 )
BitDefenderThetaGen:NN.ZedlaF.36744.ry4@auhmJKm
VirITTrojan.Win32.Dnldr30.BEBK
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.GXFT
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Agent.mytqur
BitDefenderGen:Variant.Razy.566869
NANO-AntivirusTrojan.Win32.Kryptik.gdrlyo
AvastWin32:Evo-gen [Trj]
RisingTrojan.Kryptik!1.BDB8 (CLASSIC)
EmsisoftGen:Variant.Razy.566869 (B)
F-SecureTrojan.TR/AD.MalwareCrypter.arl
VIPREGen:Variant.Razy.566869
TrendMicroTrojan.Win32.TORSED.A
SophosMal/Generic-S
IkarusTrojan.Win32.Crypt
GDataGen:Variant.Razy.566869
JiangminBackdoor.Agent.hai
WebrootW32.Trojan.Gen
AviraTR/AD.MalwareCrypter.arl
Antiy-AVLTrojan/Win32.Ta505
XcitiumMalware@#2rvnx3o2nttpl
ArcabitTrojan.Razy.D8A655
ViRobotTrojan.Win32.Z.Agent.282624.BAR
ZoneAlarmBackdoor.Win32.Agent.mytqur
MicrosoftTrojan:Win32/GraceWire.BL!dha
VaristW32/ABTrojan.ZOFX-3612
AhnLab-V3Trojan/Win32.Reflect.R295123
ALYacTrojan.Agent.Carpcdl
MAXmalware (ai score=100)
VBA32BScope.Backdoor.Agent
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojan.Win32.TORSED.A
TencentWin32.Backdoor.Agent.Iajl
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.74627787.susgen
FortinetW32/Kryptik.HAHT!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/GraceWire.BL!dha?

Trojan:Win32/GraceWire.BL!dha removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment