Trojan

MemScan:Trojan.Downloader.Delf.SCN (file analysis)

Malware Removal

The MemScan:Trojan.Downloader.Delf.SCN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MemScan:Trojan.Downloader.Delf.SCN virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (7 unique times)
  • ‘Dropbox’ in HTML Title but connection is not HTTPS. Possibly indicative of phishing.
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Sniffs keystrokes
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

xred.mooo.com
freedns.afraid.org
huczhiyuan.3322.org
ocsp.pki.goog
doc-14-14-docs.googleusercontent.com
www.dropbox.com
ocsp.digicert.com
xred.site50.net
www.000webhost.com
ocsp.comodoca.com

How to determine MemScan:Trojan.Downloader.Delf.SCN?


File Info:

crc32: 3F3E9F8C
md5: 96fc5bd3da96027dd050bfebaa6f61a1
name: 96FC5BD3DA96027DD050BFEBAA6F61A1.mlw
sha1: 93a4fc5a7286357b8af4dcd80f0541876b4b4612
sha256: d8d750910aac8726d8cb50476b6a5b6635e6d8ce3ecd02d562c637269d1a1088
sha512: 428061df69d1a940d9fc98ef6ada1b5b2c0616aae21d2106d8c3db82d9b9d76723f4aab52961bb1c05b52125df88fdf7aaa3c597073065478b9466e9c5e77fa4
ssdeep: 6144:MxhGOBT+HzsZJbEtQ2vcs77JC763yUtA6MIb7GcFS/T04U/iJ+QtavKa+FAK6b9e:ZloZZEOZYVCPauTr4vcS5LEwkVT
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName:
FileVersion: 1.0.0.4
CompanyName: Synaptics
LegalTrademarks:
Comments:
ProductName: Synaptics Pointing Device Driver
ProductVersion: 1.0.0.0
FileDescription: Synaptics Pointing Device Driver
OriginalFilename:
Translation: 0x041f 0x04e6

MemScan:Trojan.Downloader.Delf.SCN also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanMemScan:Trojan.Downloader.Delf.SCN
FireEyeGeneric.mg.96fc5bd3da96027d
McAfeeArtemis!96FC5BD3DA96
BitDefenderMemScan:Trojan.Downloader.Delf.SCN
Cybereasonmalicious.3da960
BitDefenderThetaAI:Packer.7642CD7B1B
CyrenW32/Troj_Obfusc.N.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Dogrobot [Drp]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
RisingTrojan.Generic@ML.100 (RDML:dnvydlAJ5H7sVfvpQAszCA)
Ad-AwareMemScan:Trojan.Downloader.Delf.SCN
ComodoTrojWare.Win32.Kryptik.~NNZ@1qgexn
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.DownLoader22.9658
McAfee-GW-EditionArtemis!Virus
EmsisoftMemScan:Trojan.Downloader.Delf.SCN (B)
IkarusBackdoor.Win32.Hupigon
WebrootW32.Infostealer.Qqpass
AviraTR/Crypt.XPACK.Gen
ArcabitTrojan.Downloader.Delf.SCN
AhnLab-V3Trojan/Win32.QQPass.R116748
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataMemScan:Trojan.Downloader.Delf.SCN
ESET-NOD32a variant of Win32/Delf.NBX
Acronissuspicious
VBA32BScope.Backdoor.DarkKomet
ALYacMemScan:Trojan.Downloader.Delf.SCN
MAXmalware (ai score=83)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Delf.NBX!tr
AVGWin32:Dogrobot [Drp]
CrowdStrikewin/malicious_confidence_70% (D)
Qihoo-360HEUR/QVM19.1.352F.Malware.Gen

How to remove MemScan:Trojan.Downloader.Delf.SCN?

MemScan:Trojan.Downloader.Delf.SCN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment