Trojan

MemScan:Trojan.Downloader.Delf.SCN (B) (file analysis)

Malware Removal

The MemScan:Trojan.Downloader.Delf.SCN (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MemScan:Trojan.Downloader.Delf.SCN (B) virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (7 unique times)
  • ‘Dropbox’ in HTML Title but connection is not HTTPS. Possibly indicative of phishing.
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Sniffs keystrokes
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
xred.mooo.com
freedns.afraid.org
ocsp.pki.goog
huczhiyuan.3322.org
doc-14-14-docs.googleusercontent.com
www.dropbox.com
ocsp.digicert.com
xred.site50.net
www.000webhost.com
ocsp.comodoca.com

How to determine MemScan:Trojan.Downloader.Delf.SCN (B)?


File Info:

crc32: 279CA8DA
md5: 60c32a0168eeb115b7f4794895f6eec3
name: 60C32A0168EEB115B7F4794895F6EEC3.mlw
sha1: b2fe7904568959a991b105b47ed5c25948240c45
sha256: 3dd7fd114be1aeadcb539d4b993b043332e570faa28f5faf8bb13dc9a7f219bf
sha512: 71726d2ac408ebee3e8830c4146144a09bbd05d2ec6d92eb7b54ae6b5dad877a8c6762a7336139b27ffec9f820d17ba9ff99b6fa73c91d139f3ef55d0bd1077a
ssdeep: 6144:kxhGOBT+HzsZJbEtQ2vcs77JC763yUtA6MIb7GcFS/T04U/iJ+QtavKa+FAK6b9e:RloZZEOZYVCPauTr4vcS5LEwkVT
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName:
FileVersion: 1.0.0.4
CompanyName: Synaptics
LegalTrademarks:
Comments:
ProductName: Synaptics Pointing Device Driver
ProductVersion: 1.0.0.0
FileDescription: Synaptics Pointing Device Driver
OriginalFilename:
Translation: 0x041f 0x04e6

MemScan:Trojan.Downloader.Delf.SCN (B) also known as:

Elasticmalicious (high confidence)
DrWebTrojan.DownLoader22.9658
MicroWorld-eScanMemScan:Trojan.Downloader.Delf.SCN
FireEyeGeneric.mg.60c32a0168eeb115
ALYacMemScan:Trojan.Downloader.Delf.SCN
K7GWTrojan ( 000112511 )
Cybereasonmalicious.168eeb
InvinceaMal/Generic-S
BitDefenderThetaAI:Packer.7642CD7B1B
CyrenW32/Troj_Obfusc.N.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyTrojan.Win32.XRed.jk
BitDefenderMemScan:Trojan.Downloader.Delf.SCN
TencentTrojan.Win32.Farfli.aaf
Ad-AwareMemScan:Trojan.Downloader.Delf.SCN
EmsisoftMemScan:Trojan.Downloader.Delf.SCN (B)
ComodoTrojWare.Win32.Kryptik.~NNZ@1qgexn
F-SecureTrojan.TR/Crypt.XPACK.Gen
VIPREWorm.Win32.AutoRun
TrendMicroTROJ_GEN.R06EC0DKI20
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
SophosMal/Generic-S
IkarusWin32.Outbreak
GDataMemScan:Trojan.Downloader.Delf.SCN
AviraTR/Crypt.XPACK.Gen
ZoneAlarmTrojan.Win32.XRed.jk
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.QQPass.R116748
Acronissuspicious
MAXmalware (ai score=89)
VBA32BScope.Backdoor.DarkKomet
ESET-NOD32a variant of Win32/Delf.NBX
TrendMicro-HouseCallTROJ_GEN.R06EC0DKI20
RisingBackdoor.Zegost!8.177 (TFE:2:iIjYI9AcFlR)
SentinelOneStatic AI – Malicious PE
FortinetW32/Delf.NBX!tr
AvastWin32:Dogrobot [Drp]
CrowdStrikewin/malicious_confidence_70% (D)
Qihoo-360HEUR/QVM19.1.5DB7.Malware.Gen

How to remove MemScan:Trojan.Downloader.Delf.SCN (B)?

MemScan:Trojan.Downloader.Delf.SCN (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment