Malware

Troj/Emotet-CTH (file analysis)

Malware Removal

The Troj/Emotet-CTH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Emotet-CTH virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine Troj/Emotet-CTH?


File Info:

crc32: 5BE555A3
md5: c8134327344ba557fcc6e1f1ce8a0d84
name: C8134327344BA557FCC6E1F1CE8A0D84.mlw
sha1: 6469e19dcb7541f245cc4410001f5555f35da83c
sha256: 13c646eea5ad6705e2aa84922486158b8726f77b2f2eaaa84161955e371fef29
sha512: 18de6add6b2c2df0cf29c11f47393491e2f7ded2c76d659b47231ee393897554afe53afb39f455093b2fa4f6d742efe772fc7d02d6c896ce26d667f4f9f53955
ssdeep: 3072:3y6WakjVBA+TsO7ckDsvMR166DYvecpc+/uccGJG7Iu5HjqWkMuq5MALTax6:V8TsDksERFYvjOKG7/5HLkEtLTW
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2003
InternalName: EffectDemo
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: EffectDemo Application
ProductVersion: 1, 0, 0, 1
FileDescription: EffectDemo MFC Application
OriginalFilename: EffectDemo.EXE
Translation: 0x0409 0x04b0

Troj/Emotet-CTH also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.EmotetU.Gen.oq0@hGMJAzfi
McAfeeEmotet-FSF!C8134327344B
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
BitDefenderTrojan.EmotetU.Gen.oq0@hGMJAzfi
K7GWTrojan ( 005600261 )
K7AntiVirusTrojan ( 005605291 )
ArcabitTrojan.EmotetU.Gen.ED1610D
InvinceaMal/Generic-R + Troj/Emotet-CTH
CyrenW32/Trickbot.CO.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
ClamAVWin.Trojan.Emotet-9783052-0
KasperskyHEUR:Trojan-Banker.Win32.Emotet.gen
AlibabaTrojan:Win32/Kryptik.0f6cc35d
NANO-AntivirusTrojan.Win32.Emotet.iaqwmw
RisingWorm.Stration!8.13C (TFE:3:HdCJEHEBjPN)
Ad-AwareTrojan.EmotetU.Gen.oq0@hGMJAzfi
EmsisoftTrojan.Emotet (A)
F-SecureTrojan.TR/Crypt.Agent.nbwrk
DrWebTrojan.DownLoader35.6860
TrendMicroTrojanSpy.Win32.EMOTET.SMU.hp
McAfee-GW-EditionBehavesLike.Win32.Emotet.dh
FireEyeGeneric.mg.c8134327344ba557
SophosTroj/Emotet-CTH
SentinelOneStatic AI – Suspicious PE
AviraTR/Crypt.Agent.nbwrk
MAXmalware (ai score=85)
MicrosoftTrojan:Win32/Ymacco.AA13
ZoneAlarmHEUR:Trojan-Banker.Win32.Emotet.gen
GDataWin32.Trojan-Spy.Emotet.PSROBL
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Emotet.R353886
ALYacTrojan.EmotetU.Gen.oq0@hGMJAzfi
TACHYONTrojan/W32.EmotetU.229376.C
MalwarebytesTrojan.MalPack.TRE
ESET-NOD32a variant of Win32/Kryptik.HGZG
TrendMicro-HouseCallTrojanSpy.Win32.EMOTET.SMU.hp
TencentMalware.Win32.Gencirc.10ce12df
IkarusTrojan-Banker.Emotet
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Emotet.AMH!tr
BitDefenderThetaGen:NN.ZexaF.34634.oq0@aGMJAzfi
AVGWin32:BankerX-gen [Trj]
AvastWin32:BankerX-gen [Trj]
Qihoo-360Generic/Trojan.a11

How to remove Troj/Emotet-CTH?

Troj/Emotet-CTH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment