Trojan

IL:Trojan.MSILMamut.3955 (file analysis)

Malware Removal

The IL:Trojan.MSILMamut.3955 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What IL:Trojan.MSILMamut.3955 virus can do?

  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • CAPE detected the RevengeRAT malware family

How to determine IL:Trojan.MSILMamut.3955?


File Info:

name: 3CA8F4E3F574B30EF023.mlw
path: /opt/CAPEv2/storage/binaries/141c28c995bbd1b0a3407dca0495ea091e0da8d409941a768becc119d1367c51
crc32: 17F7760D
md5: 3ca8f4e3f574b30ef0237bf4fed8698f
sha1: 1980d9de674066ab97e9675b9d0554f39d989923
sha256: 141c28c995bbd1b0a3407dca0495ea091e0da8d409941a768becc119d1367c51
sha512: 937688fd9d4cb0bb4cbc56ccb39a9e7a3fe62b36bf98ee6be49e2b41a4afd2906597152077a2999743237a8bcc4d02f6abc7c633f68d207de1ab6dd700abb8e8
ssdeep: 24576:4RuNDhi2NSoaHNawtozblBGvGhsGR1SLyHFRJgBO5y+Bygf7RnFi73c:2TESNtwPN4yah0e7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T162D539342DEA502AB273EF699BE475DADA6FB7733B03545D10A1038A0723A41DDC163E
sha3_384: f03d6ef3506f6e87f329a53cc811f6e6007b26364df7f119c61330e46b406c5adb09cd2df62687ae00fe8f3da6f28c66
ep_bytes: ff250020400000000000000000000000
timestamp: 2019-06-19 00:16:14

Version Info:

0: [No Data]

IL:Trojan.MSILMamut.3955 also known as:

LionicTrojan.Win32.RRAT.4!c
ElasticWindows.Trojan.Revengerat
DrWebTrojan.DownLoader28.62145
MicroWorld-eScanIL:Trojan.MSILMamut.3955
ClamAVWin.Trojan.RevengeRat-6344273-0
FireEyeGeneric.mg.3ca8f4e3f574b30e
ALYacIL:Trojan.MSILMamut.3955
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Agent.Win32.1107048
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005000cf1 )
AlibabaBackdoor:MSIL/RevengeRat.16c30f7d
K7GWTrojan ( 005000cf1 )
Cybereasonmalicious.3f574b
BitDefenderThetaAI:Packer.0A98BAC21F
CyrenW32/Revetrat.A.gen!Eldorado
SymantecTrojan.Revetrat
ESET-NOD32a variant of MSIL/Agent.APN
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.RRAT.gen
BitDefenderIL:Trojan.MSILMamut.3955
NANO-AntivirusTrojan.Win32.RRAT.ftlxvu
AvastWin32:RATX-gen [Trj]
TencentWin32.Trojan.Rrat.Kjgl
EmsisoftIL:Trojan.MSILMamut.3955 (B)
F-SecureTrojan.TR/Dropper.Gen
VIPREIL:Trojan.MSILMamut.3955
McAfee-GW-EditionBehavesLike.Win32.Dropper.vt
SophosMal/Revet-A
IkarusBackdoor-Rat.Revenge
GDataIL:Trojan.MSILMamut.3955
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.RRAT
ArcabitIL:Trojan.MSILMamut.DF73
ZoneAlarmHEUR:Trojan.Win32.RRAT.gen
MicrosoftBackdoor:MSIL/RevengeRat.GA!MTB
GoogleDetected
AhnLab-V3Trojan/Win32.RL_Generic.C3454586
Acronissuspicious
McAfeeReventRat!3CA8F4E3F574
MAXmalware (ai score=100)
VBA32Dropper.MSIL.gen
Cylanceunsafe
PandaTrj/GdSda.A
RisingBackdoor.Revetrat!1.B8DA (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/RevengeRat.APN!tr
AVGWin32:RATX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove IL:Trojan.MSILMamut.3955?

IL:Trojan.MSILMamut.3955 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment