Trojan

What is “IL:Trojan.MSILMamut.6015”?

Malware Removal

The IL:Trojan.MSILMamut.6015 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What IL:Trojan.MSILMamut.6015 virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Creates known Njrat/Bladabindi RAT registry keys

How to determine IL:Trojan.MSILMamut.6015?


File Info:

name: 1514176439174DC66EDF.mlw
path: /opt/CAPEv2/storage/binaries/67f03424955507f0c5672d2de191fac1bacfa44623ef456bf05f9a5483f9b4d8
crc32: 00AEC032
md5: 1514176439174dc66edfbb5a4644e625
sha1: 9381b8551e3784f43e07c8a17150062f0baffd2f
sha256: 67f03424955507f0c5672d2de191fac1bacfa44623ef456bf05f9a5483f9b4d8
sha512: f4a7e3b9ff3df9e6310a72b9dc0d8cd9f9bdcaf110c1d7f3dfcd0c825242d413a2812a2b61333fa88193855430043122b23c16a83fc90a41c2261516595f3942
ssdeep: 384:70NJLSXLSwB/aCxbWEFdc0//34LAZSTDMnC:70NY75vdHqGnC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C1A228CD37E8C608D6EC1AB508F36314A372D1838A42DB1E5EDE909B2F237954954EE9
sha3_384: 3350a15d3c9f666bc8dc4411220fc21ea936f7eebaae16da9a78b99e5bcd61219a8a8cd0820cfcc4d433dad1267ec8f3
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-11-12 10:53:36

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: Stub.exe
LegalCopyright:
OriginalFilename: Stub.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

IL:Trojan.MSILMamut.6015 also known as:

BkavW32.AIDetectNet.01
CynetMalicious (score: 100)
ALYacIL:Trojan.MSILMamut.6015
MalwarebytesTrojan.MalPack
ZillyaTrojan.Keylogger.Win32.68996
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
K7GWTrojan ( 700000121 )
Cybereasonmalicious.439174
BaiduMSIL.Backdoor.Bladabindi.a
CyrenW32/Razy.CS.gen!Eldorado
SymantecBackdoor.Ratenjay!gen3
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Bladabindi.AZ
APEXMalicious
ClamAVWin.Packed.njRAT-7445143-0
KasperskyHEUR:Trojan-Spy.MSIL.KeyLogger.gen
BitDefenderIL:Trojan.MSILMamut.6015
MicroWorld-eScanIL:Trojan.MSILMamut.6015
AvastWin32:KeyloggerX-gen [Trj]
RisingBackdoor.njRAT!1.9E49 (CLASSIC)
TACHYONTrojan-Dropper/W32.DN-Keylogger.22528.B
EmsisoftIL:Trojan.MSILMamut.6015 (B)
DrWebBackDoor.Bladabindi.15957
VIPREIL:Trojan.MSILMamut.6015
McAfee-GW-EditionTrojan-FSHK!151417643917
FireEyeGeneric.mg.1514176439174dc6
SophosML/PE-A
IkarusTrojan.MSIL.Bladabindi
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.4AD6
MicrosoftBackdoor:MSIL/BladiBindi.GC!MTB
ArcabitIL:Trojan.MSILMamut.D177F
ZoneAlarmHEUR:Trojan-Spy.MSIL.KeyLogger.gen
GDataIL:Trojan.MSILMamut.6015
GoogleDetected
AhnLab-V3Trojan/Win32.Bladabindi.C3454901
Acronissuspicious
McAfeeTrojan-FSHK!151417643917
MAXmalware (ai score=84)
VBA32Trojan.MSIL.gen.c.1
CylanceUnsafe
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Bladabindi.HT!tr
BitDefenderThetaGen:NN.ZemsilF.34784.bm0@aqvhkqe
AVGWin32:KeyloggerX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove IL:Trojan.MSILMamut.6015?

IL:Trojan.MSILMamut.6015 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment