Malware

What is “BScope.Exploit.ShellCode”?

Malware Removal

The BScope.Exploit.ShellCode is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.Exploit.ShellCode virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Serbian
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to identify installed AV products by installation directory
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
iplogger.org
redblur.top

How to determine BScope.Exploit.ShellCode?


File Info:

crc32: 70EDAD07
md5: b22fd4e4907e4a7c1f467a87ee2fa19b
name: B22FD4E4907E4A7C1F467A87EE2FA19B.mlw
sha1: a00c12a770dbd28b027cb263ba71101ddd3daf64
sha256: 1fa201e26aa0cf62b7449e39ad3c16f86f12e9832b99846c738c8d6536255659
sha512: 7edfd72e0dfef9b7c117489b0468e636b77d758353b4575c7f8f104dc3921097c807dd11e60775ec1be9fcf1b816c400c4846cb5ffffea7aba1de46f6b233bfa
ssdeep: 12288:op/+wlLEsY1ihOuIFcHA9Bq6mEswRQoRvhALd2px1:oE8EsYcoBCg9Bqzcvhwd2pX
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: voygcuadage.exe
FileVersion: 1.7.38.44
Copyright: Copyrighz (C) 2020, wodkagudy
ProductVersions: 1.16.44
Translation: 0x0273 0x011e

BScope.Exploit.ShellCode also known as:

K7AntiVirusTrojan ( 0056f9be1 )
LionicTrojan.Win32.Agent.m!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.37237428
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaRansom:Win32/GandCrab.2ab10814
K7GWTrojan ( 0056f9be1 )
CyrenW32/Kryptik.EQG.gen!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.HLSK
APEXMalicious
AvastWin32:DropperX-gen [Drp]
KasperskyHEUR:Exploit.Win32.Shellcode.gen
BitDefenderTrojan.GenericKD.37237428
MicroWorld-eScanTrojan.GenericKD.37237428
Ad-AwareTrojan.GenericKD.37237428
SophosMal/Generic-S
ComodoTrojWare.Win32.Agent.irvof@0
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
FireEyeGeneric.mg.b22fd4e4907e4a7c
SentinelOneStatic AI – Suspicious PE
WebrootW32.Trojan.Gen
AviraTR/Crypt.Agent.mvekd
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Caynamer.A!ml
GridinsoftTrojan.Win32.Packed.lu!heur
ArcabitTrojan.Generic.D23832B4
ZoneAlarmHEUR:Exploit.Win32.Shellcode.gen
GDataTrojan.GenericKD.37237428
AhnLab-V3Trojan/Win.MalPE.R431576
Acronissuspicious
McAfeeRDN/RedLineStealer
MAXmalware (ai score=80)
VBA32BScope.Exploit.ShellCode
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002H07GE21
RisingTrojan.Generic@ML.98 (RDML:RmoKKs0dwtAs+RMM3LyDmA)
IkarusTrojan.Win32.FileCrypter
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.ERHN!tr
AVGWin32:DropperX-gen [Drp]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HwoClpsA

How to remove BScope.Exploit.ShellCode?

BScope.Exploit.ShellCode removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment