Trojan

Trojan:Win32/Ymacco.AA04 (file analysis)

Malware Removal

The Trojan:Win32/Ymacco.AA04 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ymacco.AA04 virus can do?

  • The office file contains 2 macros
  • The office file contains a macro with auto execution
  • The office file contains anomalous features
  • The office file contains a macro with suspicious strings

How to determine Trojan:Win32/Ymacco.AA04?


File Info:

crc32: C4CFDF56
md5: 6d85a983890bd8a160e0efc8448aa718
name: upload_file
sha1: 5cd206c3ffea062192e63935ec2dddcf5abde3f1
sha256: 0453fae20f8759d4b93663ba58ad3a923f868ba094decd801c43eb9d270f3d8a
sha512: 949292c5744d0f27096763bd703564f19969044b9b96574fe96089cfdf4473750de3a23299e99488185d428fc5dd020cd949567efdddfc623b2d82b8750aea09
ssdeep: 3072:9j6yw1MgpQiBhGWb6esLbTh8YuyDRBFtdfGkxQq7IywL/RinF:9HgtEWPsL/aTyT9Gkxl7IywL/RE
type: Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Title: Eos., Author: Zoe Adam, Template: Normal.dotm, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Create Time/Date: Wed Aug 12 22:54:00 2020, Last Saved Time/Date: Wed Aug 12 22:54:00 2020, Number of Pages: 1, Number of Words: 2, Number of Characters: 16, Security: 0

Version Info:

0: [No Data]

Trojan:Win32/Ymacco.AA04 also known as:

Elasticmalicious (high confidence)
FireEyeVBA:Logan.857
CAT-QuickHealW97M.Emotet.38757
McAfeeRDN/Emotet
VIPRELooksLike.Macro.Malware.d (v)
SangforMalware
K7AntiVirusTrojan ( 0056c3f41 )
K7GWTrojan ( 0056c3f41 )
SymantecW97M.Downloader
TrendMicro-HouseCallTrojan.W97M.POWLOAD.EMI
AvastScript:SNH-gen [Trj]
CynetMalicious (score: 85)
KasperskyHEUR:Trojan.MSOffice.SAgent.gen
BitDefenderVBA:Logan.857
ViRobotDOC.Z.Agent.232080
AegisLabTrojan.MSWord.Logan.4!c
MicroWorld-eScanVBA:Logan.857
RisingTrojan.Obfus/VBA!1.C95A (CLASSIC)
Ad-AwareVBA:Logan.857
ComodoTrojWare.Win32.Agent.nyuag@0
DrWebExploit.Siggen2.17548
TrendMicroTrojan.W97M.POWLOAD.EMI
FortinetVBA/Agent.BIP!tr.dldr
SophosMal/DocDl-K
IkarusTrojan-Downloader.VBA.Emotet
CyrenW97M/Downldr.IE.gen!Eldorado
AviraVBA/Dldr.Agent.bmkmq
MAXmalware (ai score=99)
Antiy-AVLTrojan[Downloader]/MSOffice.Agent.uay
ArcabitVBA:Logan.857
MicrosoftTrojan:Win32/Ymacco.AA04
AhnLab-V3Downloader/DOC.Emotet.S1072
ALYacTrojan.Downloader.DOC.Gen
TACHYONSuspicious/W97M.Obfus.Gen.1
ZonerProbably Heur.W97Obfuscated
ESET-NOD32VBA/TrojanDownloader.Agent.UAY
TencentHeur.Macro.Generic.f.337ce396
GDataVBA:Logan.857
AVGScript:SNH-gen [Trj]
Qihoo-360virus.office.qexvmc.1065

How to remove Trojan:Win32/Ymacco.AA04?

Trojan:Win32/Ymacco.AA04 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment