Trojan

About “IL:Trojan.MSILMamut.4397” infection

Malware Removal

The IL:Trojan.MSILMamut.4397 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What IL:Trojan.MSILMamut.4397 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Enumerates the modules from a process (may be used to locate base addresses in process injection)
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Injection with CreateRemoteThread in a remote process
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine IL:Trojan.MSILMamut.4397?


File Info:

name: 732BFD1394868F5F29FA.mlw
path: /opt/CAPEv2/storage/binaries/477beaf04f0026cd43e3229a1dfc76752513f10fa78524b65ca74de556eb1082
crc32: B476EA8D
md5: 732bfd1394868f5f29fac343b2013f04
sha1: 8180e7ff3aedc238dbd0b32b9a6715d8a4d70c7b
sha256: 477beaf04f0026cd43e3229a1dfc76752513f10fa78524b65ca74de556eb1082
sha512: f2a2d8b2d23a07af3e8869cc3db88c64de777d9372cb1f5a61b44b87b4e16a1bc9b2fc9d697b4306362723a275beefece53cd4200039520fa3ee7bbb0f6488e4
ssdeep: 1536:6PQc0IiI+7vAIIzuQ8Tr15WUkTdIOzq0ZDVnJvx/GlSyZXQAmzSETxy:UQc01zAf6QGkBIO20ZzvGgAzP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T161936C1977DC4EA6C2EE07B890B3436547B1E862A507D70F6DD864FA2C7338086527B7
sha3_384: d75d5b968750b04452fa1bf5f64070cd3929379b977f42acf06ee80cf89963bc5085029f8c44078f18288d818598e519
ep_bytes: ff250020400000000000000000000000
timestamp: 2012-06-02 12:12:48

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft Security Client Policy Configuration Tool
FileVersion: 4.18.18362.1 (WinBuild.160101.0800)
InternalName: ConfigSecurityPolicy.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: ConfigSecurityPolicy.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 4.18.18362.1
Translation: 0x0409 0x04b0

IL:Trojan.MSILMamut.4397 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.MulDrop20.13470
MicroWorld-eScanIL:Trojan.MSILMamut.4397
FireEyeGeneric.mg.732bfd1394868f5f
ALYacIL:Trojan.MSILMamut.4397
CylanceUnsafe
K7AntiVirusTrojan ( 700000121 )
K7GWTrojan ( 700000121 )
Cybereasonmalicious.394868
BitDefenderThetaGen:NN.ZemsilF.34742.fm0@ayFeFXgi
CyrenW32/MSIL_Agent.DJX.gen!Eldorado
tehtrisGeneric.Malware
ESET-NOD32a variant of MSIL/Agent.EF
ClamAVWin.Virus.Renamer-9953540-0
KasperskyHEUR:Trojan-Ransom.Win32.Generic
BitDefenderIL:Trojan.MSILMamut.4397
AvastWin32:MalwareX-gen [Trj]
Ad-AwareIL:Trojan.MSILMamut.4397
EmsisoftIL:Trojan.MSILMamut.4397 (B)
McAfee-GW-EditionGenericRXTG-FA!732BFD139486
Trapminesuspicious.low.ml.score
SophosMSIL/Grenam-A
SentinelOneStatic AI – Malicious PE
GDataIL:Trojan.MSILMamut.4397
AviraHEUR/AGEN.1235262
MAXmalware (ai score=82)
ArcabitIL:Trojan.MSILMamut.D112D
MicrosoftVirus:MSIL/Grenam.gen!A
CynetMalicious (score: 100)
McAfeeGenericRXTG-FA!732BFD139486
MalwarebytesMalware.AI.1691162887
APEXMalicious
RisingVirus.Grenam!1.A2DD (CLASSIC)
IkarusWorm.MSIL.Bladabindi
FortinetMSIL/Agent.EF!worm
AVGWin32:MalwareX-gen [Trj]
CrowdStrikewin/malicious_confidence_70% (D)

How to remove IL:Trojan.MSILMamut.4397?

IL:Trojan.MSILMamut.4397 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment