Trojan

About “IL:Trojan.MSILMamut.675” infection

Malware Removal

The IL:Trojan.MSILMamut.675 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What IL:Trojan.MSILMamut.675 virus can do?

  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine IL:Trojan.MSILMamut.675?


File Info:

name: EA88F31D6CC55D8F7A92.mlw
path: /opt/CAPEv2/storage/binaries/33f77b1bca36469dd734af67950223a7b1babd62a25cb5f0848025f2a68b9447
crc32: 702ADE36
md5: ea88f31d6cc55d8f7a9260245988dab6
sha1: 9e725bae655c21772c10f2d64a5831b98f7d93dd
sha256: 33f77b1bca36469dd734af67950223a7b1babd62a25cb5f0848025f2a68b9447
sha512: 5952c4540b1ae5f2db48aaae404e89fb477d233d9b67458dd5cecc2edfed711509d2e968e6af2dbb3bd2099c10a4556f7612fc0055df798e99f9850796a832ad
ssdeep: 12288:9r5TpNl9E96cWBX2FqwaHJRZ3EW7Wsv8kixW3pFMcmyuWp7pPmTppppppppppppy:zTN9fBmdapHEaW0iUuyq8a9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T125F4D041FA90A7D0CC2D87741E7AC8350733BD7AA5B4D50C25D93EA73FBABA20015A97
sha3_384: fd9ae13f4116561f9940a757cfe834c2de40d35a1a13408429a9b65172574adeba9dae6a9fd71870984575812ba290f7
ep_bytes: ff250020400005000000030000000300
timestamp: 2083-07-26 09:56:07

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: 2dShooter
FileVersion: 1.0.0.0
InternalName: qNnxWvWndIY.exe
LegalCopyright: Copyright © 2020
LegalTrademarks:
OriginalFilename: qNnxWvWndIY.exe
ProductName: 2dShooter
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

IL:Trojan.MSILMamut.675 also known as:

BkavW32.AIDetectNet.01
LionicTrojan.MSIL.Crysan.m!c
tehtrisGeneric.Malware
MicroWorld-eScanIL:Trojan.MSILMamut.675
FireEyeGeneric.mg.ea88f31d6cc55d8f
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
McAfeePWS-FCSU!EA88F31D6CC5
ZillyaBackdoor.Crysan.Win32.5009
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
AlibabaBackdoor:MSIL/Crysan.df2f2dcb
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.d6cc55
BitDefenderThetaGen:NN.ZemsilF.36308.Um0@a45p0lk
VirITTrojan.Win32.Dnldr33.CTBB
SymantecTrojan.Gen.2
Elasticmalicious (high confidence)
ESET-NOD32a variant of Generik.HABKZHC
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Backdoor.MSIL.Crysan.gen
BitDefenderIL:Trojan.MSILMamut.675
NANO-AntivirusTrojan.Win32.Dwn.hkuryc
AvastWin32:TrojanX-gen [Trj]
TencentMsil.Backdoor.Crysan.Bdhl
EmsisoftIL:Trojan.MSILMamut.675 (B)
DrWebTrojan.DownLoader33.48023
VIPREIL:Trojan.MSILMamut.675
McAfee-GW-EditionPWS-FCSU!EA88F31D6CC5
SophosMal/Generic-S
IkarusTrojan.Crypt
GDataIL:Trojan.MSILMamut.675
JiangminBackdoor.MSIL.defi
WebrootW32.Trojan.Gen
GoogleDetected
AviraHEUR/AGEN.1250364
MAXmalware (ai score=100)
Antiy-AVLTrojan[Backdoor]/MSIL.Crysan
XcitiumMalware@#3ricinkg6ecod
ArcabitIL:Trojan.MSILMamut.675
ZoneAlarmHEUR:Backdoor.MSIL.Crysan.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.C4111723
VBA32TScope.Trojan.MSIL
ALYacIL:Trojan.MSILMamut.675
Cylanceunsafe
RisingMalware.Obfus/MSIL@AI.90 (RDM.MSIL2:UM7a7T26zninX6M2gPneiA)
YandexTrojan.Agent!XglvbNPPVe8
SentinelOneStatic AI – Malicious PE
FortinetMSIL/GenKryptik.ELNG!tr
AVGWin32:TrojanX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove IL:Trojan.MSILMamut.675?

IL:Trojan.MSILMamut.675 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment