Trojan

About “Trojan:Win32/Ymacco.AB0A” infection

Malware Removal

The Trojan:Win32/Ymacco.AB0A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ymacco.AB0A virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Attempts to modify proxy settings

How to determine Trojan:Win32/Ymacco.AB0A?


File Info:

name: 68F05B49ED095A6862C2.mlw
path: /opt/CAPEv2/storage/binaries/0ac4389039bbbf47638260ae3d676e869ee90a52eb1bcc53da9a0bb19bc62893
crc32: 351CDAF7
md5: 68f05b49ed095a6862c20c0657433e0a
sha1: 16e6b8d3797cf097ad07af1970eda39d63cf16da
sha256: 0ac4389039bbbf47638260ae3d676e869ee90a52eb1bcc53da9a0bb19bc62893
sha512: a2f76f35e21560d0a23013a7fd3b47cc4e4f7723abd3788767682c2c1fd317b4a5ebb5c6c2d859ee91cb19b8652c1326e64b4be5f0e51801efdcb28d534d98d5
ssdeep: 3072:Ld0PWstRMNOz1lPMXleQGZZy0AmBJbxbQDH5eJfIPTG1YE2ek3LQ:50PdRMNvlAieJfECOEY3LQ
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1D2D302860360091EF11A96BBC3E61B7A6D32554491EB795ECDC6BFFC4E2A1F3C2605D0
sha3_384: 6046bcd16019d683bcfd42a0ed3876780dae47bdcb52e60d28ec066fe29444c721c30fcb9762cff42efd40ad4f8eb6df
ep_bytes: 5589e5bb0000000089f989c0b894e27c
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan:Win32/Ymacco.AB0A also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Copak.4!c
MicroWorld-eScanGen:Trojan.Heur.imW@!hBy@@e
FireEyeGeneric.mg.68f05b49ed095a68
ALYacGen:Trojan.Heur.imW@!hBy@@e
CylanceUnsafe
K7AntiVirusTrojan ( 0057cf3b1 )
K7GWTrojan ( 0057cf3b1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.335106D81B
CyrenW32/Kryptik.DZR.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
TrendMicro-HouseCallTROJ_GEN.R002C0RL721
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Copak.pef
BitDefenderGen:Trojan.Heur.imW@!hBy@@e
NANO-AntivirusTrojan.Win32.Copak.jirvom
AvastWin32:Trojan-gen
TencentWin32.Trojan.Copak.Wske
Ad-AwareGen:Trojan.Heur.imW@!hBy@@e
SophosMal/Generic-S + Mal/HckPk-A
ComodoPacked.Win32.MUPX.Gen@24tbus
DrWebTrojan.Packed2.43250
TrendMicroTROJ_GEN.R002C0RL721
McAfee-GW-EditionBehavesLike.Win32.Generic.cm
EmsisoftGen:Trojan.Heur.imW@!hBy@@e (B)
IkarusTrojan.Win32.Injector
GDataGen:Trojan.Heur.imW@!hBy@@e
JiangminTrojan.Copak.bfqn
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=85)
Antiy-AVLTrojan/Generic.ASCommon.1FB
GridinsoftRansom.Win32.Wacatac.sa
ViRobotTrojan.Win32.Z.Injector.136192.ASCW
APEXMalicious
MicrosoftTrojan:Win32/Ymacco.AB0A
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C2860595
McAfeeGenericRXAA-FA!68F05B49ED09
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Crypt
RisingMalware.Heuristic!ET#94% (RDMK:cmRtazowBQS09Vxqv3BOF2QzsW/P)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_90%
FortinetW32/Kryptik.EAHK!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.9ed095
PandaTrj/Genetic.gen

How to remove Trojan:Win32/Ymacco.AB0A?

Trojan:Win32/Ymacco.AB0A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment