Trojan

Trojan.Agent.CSCJ (file analysis)

Malware Removal

The Trojan.Agent.CSCJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.CSCJ virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Spanish (Modern)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan.Agent.CSCJ?


File Info:

name: 5CD6C0E614C1FEFAA23E.mlw
path: /opt/CAPEv2/storage/binaries/66e91646fe36cfdbbc832d031d3e715d28f5afc61aa02e7ba38f641f57a25e2e
crc32: 247B8C75
md5: 5cd6c0e614c1fefaa23e80800ce68e57
sha1: 02d5c5281d3bdf2a6985d07fdaaeab090ad77115
sha256: 66e91646fe36cfdbbc832d031d3e715d28f5afc61aa02e7ba38f641f57a25e2e
sha512: 6d269a52d3b2e646696e33be1725712b59d24ca17e7bb84fb601b3eced49b4dc512f6eb6384197a5456e45a02dd5d03ec363dda89fb7702640832b2df0567fb2
ssdeep: 6144:awAbSPYNqoShrFjxQ32wULFKyAPmyICJZjnuJQLuB8kH/JVSJ1hNe0lDidqMzSoo:rP2qoShr3FLFhAAurqjVSJ1hNe62dqDB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13A842362524FF197E956237A378551AEF379C07B8A3F662582D2700D4C91FB86D0AF30
sha3_384: 203e12a755aca8089d9b0e4ced37b9806c7af49a5a6be89f5541bf7afc3ea1db7ac8da2ec63926538b3ab398a6730312
ep_bytes: 60be00a046008dbe0070f9ffc7879c20
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Trojan.Agent.CSCJ also known as:

DrWebTrojan.Siggen7.30475
MicroWorld-eScanTrojan.Agent.CSCJ
FireEyeGeneric.mg.5cd6c0e614c1fefa
ALYacTrojan.Agent.CSCJ
ZillyaTrojan.Injector.Win32.621912
SangforTrojan.Win32.Injector.DUEO
K7AntiVirusTrojan ( 0051f82d1 )
AlibabaBackdoor:MSIL/Bladabindi.8927cb9b
K7GWTrojan ( 0051f82d1 )
Cybereasonmalicious.614c1f
BitDefenderThetaAI:Packer.2E73215421
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DUEO
APEXMalicious
Paloaltogeneric.ml
KasperskyBackdoor.MSIL.Bladabindi.ahcg
BitDefenderTrojan.Agent.CSCJ
NANO-AntivirusTrojan.Win32.Scrop.exluiq
TencentMsil.Backdoor.Bladabindi.Tafm
Ad-AwareTrojan.Agent.CSCJ
EmsisoftTrojan.Agent.CSCJ (B)
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PK921
McAfee-GW-EditionPacked-WC!3A87F793AADC
SophosMal/Generic-S
IkarusTrojan.Win32.Injector
GDataTrojan.Agent.CSCJ
JiangminTrojanSpy.SpyEyes.obe
eGambitUnsafe.AI_Score_99%
AviraHEUR/AGEN.1102476
Antiy-AVLTrojan/Generic.ASMalwS.2348FA5
GridinsoftRansom.Win32.Bladabindi.sa
MicrosoftBackdoor:MSIL/Bladabindi
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.Reconyc.C2112974
McAfeeArtemis!5CD6C0E614C1
MAXmalware (ai score=95)
VBA32TrojanDropper.Scrop
CylanceUnsafe
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0PK921
RisingTrojan.Injector!8.C4 (CLOUD)
YandexTrojan.GenAsa!TgQBO9hT4uY
SentinelOneStatic AI – Malicious PE
FortinetW32/Injector.DUEO!tr
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Agent.CSCJ?

Trojan.Agent.CSCJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment