Trojan

IL:Trojan.MSILMamut.5867 malicious file

Malware Removal

The IL:Trojan.MSILMamut.5867 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What IL:Trojan.MSILMamut.5867 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Checks adapter addresses which can be used to detect virtual network interfaces
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

How to determine IL:Trojan.MSILMamut.5867?


File Info:

name: DBFE3A0CFFA1B0469AA8.mlw
path: /opt/CAPEv2/storage/binaries/457df6b6e5614aafb62ea0e25a9a2e020be4bb9fef5e2d3c7aaaef294859e77f
crc32: 87C4EFC5
md5: dbfe3a0cffa1b0469aa8006ddbd304ae
sha1: abd0925eaf0eef53e82fa2e5a11c5a3cce3cc07b
sha256: 457df6b6e5614aafb62ea0e25a9a2e020be4bb9fef5e2d3c7aaaef294859e77f
sha512: 2b9a7fe633411d504b01053d71da069949a9136e7c242ccb343ae81d65bb51726d4bcf1b16e3cbe2c06003d8c572338f9b76788335f21c9065d930acc4899edf
ssdeep: 1536:WoRoH370GvsLEoLuRm92zTCJXy61RdE+PTEzh:WokL0HLam92zTCFyARdJbEd
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12CB34F91F25C7A26E2FD3ABBC5A441200219BF035B60D9EF9E77FE8D30163568941E27
sha3_384: 5ff45870c4b22d30a1e38f238fd04372ee0c9941eca5419fd58f628f337182fe82ba6fb12b2694d2748126180a5148cb
ep_bytes: ff250020400000000000000000000000
timestamp: 2016-02-10 20:13:44

Version Info:

Translation: 0x0000 0x04b0
CompanyName: Microsoft
FileDescription: Microsoft services defender
FileVersion: 3.0.0.5
InternalName: servicesdefender.exe
LegalCopyright: Microsoft Copyright © Microsoft 2016
OriginalFilename: servicesdefender.exe
ProductName: Microsoft
ProductVersion: 3.0.0.5
Assembly Version: 3.0.0.5

IL:Trojan.MSILMamut.5867 also known as:

MicroWorld-eScanIL:Trojan.MSILMamut.5867
FireEyeGeneric.mg.dbfe3a0cffa1b046
CAT-QuickHealTrojanAPT.MsoClnt.MC3
McAfeeRDN/Real Protect-LS
MalwarebytesMalware.AI.3299069677
VIPREIL:Trojan.MSILMamut.5867
SangforTrojan.Win32.Crimson.Vefi
K7AntiVirusTrojan ( 0055e3e71 )
AlibabaTrojan:Win32/Crimson.1069983b
K7GWTrojan ( 0055e3e71 )
BitDefenderThetaGen:NN.ZemsilF.34582.gm2@aeG55xh
CyrenW32/ABTrojan.GRXW-0865
SymantecTrojan.Scarimson!gen1
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of MSIL/Agent.AFB
TrendMicro-HouseCallTROJ_GEN.R002C0OGQ22
Paloaltogeneric.ml
ClamAVWin.Trojan.CrimsonRAT-7591455-0
KasperskyHEUR:Trojan.Win32.Crimson.gen
BitDefenderIL:Trojan.MSILMamut.5867
NANO-AntivirusTrojan.Win32.Crimson.jqzuzv
TencentMalware.Win32.Gencirc.12020154
Ad-AwareIL:Trojan.MSILMamut.5867
TrendMicroTROJ_GEN.R002C0OGQ22
McAfee-GW-EditionRDN/Real Protect-LS
SentinelOneStatic AI – Malicious PE
EmsisoftIL:Trojan.MSILMamut.5867 (B)
APEXMalicious
GDataIL:Trojan.MSILMamut.5867
JiangminTrojan.Crimson.ar
AviraTR/Spy.Gen
MAXmalware (ai score=81)
Antiy-AVLTrojan/Generic.ASMalwS.103
ArcabitIL:Trojan.MSILMamut.D16EB
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.Crimson.C4220762
ALYacIL:Trojan.MSILMamut.5867
RisingBackdoor.Crimson!1.CA75 (CLASSIC)
YandexTrojan.Scar!M7kr+uZnToo
IkarusTrojan.Win32.Turla
MaxSecureTrojan.Malware.11087077.susgen
FortinetMSIL/Agent.AIF!tr
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove IL:Trojan.MSILMamut.5867?

IL:Trojan.MSILMamut.5867 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment