Trojan

OScope.Trojan.MSIL.Crypt.s1 (file analysis)

Malware Removal

The OScope.Trojan.MSIL.Crypt.s1 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What OScope.Trojan.MSIL.Crypt.s1 virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine OScope.Trojan.MSIL.Crypt.s1?


File Info:

name: 5A030F817D22DF2CAD8D.mlw
path: /opt/CAPEv2/storage/binaries/a072290d19126c5452644c38d146d9c4dfc341c03ad93b8effbd144ea35e6bbe
crc32: 6EA09BB2
md5: 5a030f817d22df2cad8d8bbaba3abfac
sha1: 0af692f9b5b75ac3c787551b65a7aa288f683698
sha256: a072290d19126c5452644c38d146d9c4dfc341c03ad93b8effbd144ea35e6bbe
sha512: 5ccb7f4b235913d5bb86cf196690db7cb4475da59a082e9f6cf68bd98eddb0e55a92132f672f294d1a6b37c8112ca26e9cca0ef6d9557e7ae824f7a94c2d028f
ssdeep: 6144:hQUsJiTy14tsLK0lNa98yihojYAYe5etev6Mc:uJJoyCGLtlk98yihoshBeyMc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C8241260A7C44488D9764E723A6B81570660FA78D572D09C78E4F03E0FB27D9398EADF
sha3_384: 13178c3c9010967da397fc519247c2636b7dbad77727569d56d018c6b51cc7ad0e49c8d796ea1aecad9da01f74bc12e1
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-08-30 00:42:16

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: CBXVBCXNHDF
FileVersion: 1.0.0.0
InternalName: CBXVBCXNHDF.exe
LegalCopyright: Copyright © 2022
LegalTrademarks:
OriginalFilename: CBXVBCXNHDF.exe
ProductName: CBXVBCXNHDF
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

OScope.Trojan.MSIL.Crypt.s1 also known as:

Elasticmalicious (high confidence)
FireEyeGeneric.mg.5a030f817d22df2c
Cybereasonmalicious.9b5b75
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/TrojanDownloader.Agent.JSF
APEXMalicious
CynetMalicious (score: 100)
KasperskyVHO:Backdoor.MSIL.Androm.gen
AvastPWSX-gen [Trj]
DrWebTrojan.DownloaderNET.345
SentinelOneStatic AI – Malicious PE
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
VBA32OScope.Trojan.MSIL.Crypt.s1
MalwarebytesMachineLearning/Anomalous.95%
RisingMalware.Obfus/MSIL@AI.93 (RDM.MSIL:9TGdICMz8ZeYmpVZu5+UyA)
BitDefenderThetaGen:NN.ZemsilCO.34606.nm2@amDeXRm
AVGPWSX-gen [Trj]
CrowdStrikewin/malicious_confidence_70% (D)

How to remove OScope.Trojan.MSIL.Crypt.s1?

OScope.Trojan.MSIL.Crypt.s1 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment