Malware

About “MacOS:IPStorm-A [Trj]” infection

Malware Removal

The MacOS:IPStorm-A [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MacOS:IPStorm-A [Trj] virus can do?

  • At least one process apparently crashed during execution
  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Uses Windows utilities for basic functionality
  • A potential decoy document was displayed to the user
  • Network activity detected but not expressed in API logs

How to determine MacOS:IPStorm-A [Trj]?


File Info:

crc32: 468D0AF9
md5: b43468685e48a4f71f59415b34cb5d64
name: upload_file
sha1: 91d081be3c2a2e0056b1f8860602bb33345e11d6
sha256: fbd5e48ee691df949e0dd3687755c80cc5b9d1a1a89e7dc486694370697de893
sha512: 8c670b354ad40519956e7e75758ac38a40d8b624a78f9b180648c6098aeeac0c81f0482a0dc78f663c07d862f534ed20dd9e36f152528db27a59596308351e9d
ssdeep: 393216:ajWVIhZdSXnBRBOY0239qzR1ilXdmoPp7rgz9:aqTl8zl9
type: ELF 64-bit LSB executable, ARM aarch64, version 1 (SYSV), statically linked, stripped

Version Info:

0: [No Data]

MacOS:IPStorm-A [Trj] also known as:

CAT-QuickHealElf.Trojan.A965938
AegisLabTrojan.Multi.Generic.4!c
ArcabitTrojan.Linux.IPStorm.A
CyrenE64/Trojan.TVAH-5
SymantecTrojan.IPStorm
TrendMicro-HouseCallTrojan.Linux.IPSTORM.USELVJ420
AvastMacOS:IPStorm-A [Trj]
CynetMalicious (score: 85)
KasperskyHEUR:Trojan.Linux.Alien.a
BitDefenderTrojan.Linux.IPStorm.A
MicroWorld-eScanTrojan.Linux.IPStorm.A
Ad-AwareTrojan.Linux.IPStorm.A
EmsisoftTrojan.Linux.IPStorm.A (B)
ComodoMalware@#294yu9xs3d7ei
F-SecureTrojan.TR/Casdet.zbqns
TrendMicroTrojan.Linux.IPSTORM.USELVJ420
FireEyeTrojan.Linux.IPStorm.A
SophosMal/Generic-S
IkarusTrojan.Win32.Casdet
AviraTR/Casdet.zbqns
MicrosoftTrojan:Win32/Casdet!rfn
ZoneAlarmHEUR:Trojan.Linux.Alien.a
GDataTrojan.Linux.IPStorm.A
ALYacTrojan.Linux.IPStorm.A
MAXmalware (ai score=88)
AVGMacOS:IPStorm-A [Trj]
Qihoo-360Linux/Trojan.4e8

How to remove MacOS:IPStorm-A [Trj]?

MacOS:IPStorm-A [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment