Backdoor

BScope.Backdoor.MSIL.Agent (file analysis)

Malware Removal

The BScope.Backdoor.MSIL.Agent is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.Backdoor.MSIL.Agent virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Arabic (Libya)
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine BScope.Backdoor.MSIL.Agent?


File Info:

crc32: 244D2533
md5: 581935ed0181bbb862667e51161f2031
name: 581935ED0181BBB862667E51161F2031.mlw
sha1: ca344078c79618c4f84ff5521fe0ded0e009c74c
sha256: 4ce736beca7ebfdae1fca1c504ef9482ada58dbf573fd57434aef6de2b36c9d6
sha512: 726842ec030dfbc4ece9552ca8d349c083934a0ef8f37266a6fc380d630a5d14707e71ce3621d0ab3a642b275c40768f3191e038fc10bad3ee822f069b6b732a
ssdeep: 3072:ZRcgig6oHGxFiEz7IsDKE87a5O5HEIcPfjFX:EEGTiE3IsDKvwb
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: sojbmoiminu.ihe
ProductVersion: 8.79.590.38
Copyright: Copyrighz (C) 2021, fudkagata
Translation: 0x0129 0x0171

BScope.Backdoor.MSIL.Agent also known as:

Elasticmalicious (high confidence)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWHacktool ( 700007861 )
Cybereasonmalicious.8c7961
CyrenW32/Kryptik.EWJ.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:Backdoor.Win32.Mokes.gen
SophosML/PE-A
BitDefenderThetaGen:NN.ZexaF.34170.jq0@aOdHwSiO
McAfee-GW-EditionBehavesLike.Win32.Emotet.ch
FireEyeGeneric.mg.581935ed0181bbb8
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Mokes.eny
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ZoneAlarmUDS:DangerousObject.Multi.Generic
Acronissuspicious
McAfeePacked-GDT!581935ED0181
VBA32BScope.Backdoor.MSIL.Agent
MalwarebytesMachineLearning/Anomalous.93%
MaxSecureTrojan.Malware.300983.susgen
Paloaltogeneric.ml

How to remove BScope.Backdoor.MSIL.Agent?

BScope.Backdoor.MSIL.Agent removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment