Trojan

Trojan-Dropper.Win32.Scrop (file analysis)

Malware Removal

The Trojan-Dropper.Win32.Scrop is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Dropper.Win32.Scrop virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Spanish (Venezuela)
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to identify installed AV products by installation directory
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Anomalous binary characteristics

Related domains:

iplogger.org
apps.identrust.com
gferhrolklm.top

How to determine Trojan-Dropper.Win32.Scrop?


File Info:

crc32: 944D5096
md5: c5f9ffd8890ca4722cd2f6ebdc39566f
name: upload_file
sha1: ddeaf76ff2426dc3a7202dc3e84ed4bcbfa97893
sha256: 1ba87aa4f285a9e9cf905da0bc041df4eed434e6bff38aa189387dae4ba90dc5
sha512: 9c0c3811139a8d35ef2debaea44bad4ab34055394d578ac7fc2646b0c2eaa786a3ddf0fa283a134f551ea254ec1ebdecd22940434e783ba10666299cce069694
ssdeep: 12288:5FD4xAMf7dxzBq7K5PFM7D9miAVpBK7gCcNrIoa5xNpa:5FDyN7dxU+9kDnsxCokxba
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: wriheawtz.otu
FileVers: 1.2.58
Copyright: Copyrighd (C) 2020, gumke
TranslationUsi: 0x0431 0x0c55

Trojan-Dropper.Win32.Scrop also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.44274672
FireEyeGeneric.mg.c5f9ffd8890ca472
MalwarebytesTrojan.MalPack.GS
SangforMalware
K7GWTrojan ( 0057205d1 )
Cybereasonmalicious.ff2426
InvinceaGeneric ML PUA (PUA)
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyHEUR:Trojan-Dropper.Win32.Scrop.gen
BitDefenderTrojan.GenericKD.44274672
Paloaltogeneric.ml
Ad-AwareTrojan.GenericKD.44274672
EmsisoftTrojan.GenericKD.44274672 (B)
McAfee-GW-EditionBehavesLike.Win32.MultiPlug.bh
SentinelOneDFI – Malicious PE
GDataWin32.Trojan.AutoHotkey.V1UQN5
MAXmalware (ai score=83)
ArcabitTrojan.Generic.D2A393F0
ZoneAlarmHEUR:Trojan-Dropper.Win32.Scrop.gen
MicrosoftTrojan:Win32/Wacatac.D1!ml
CynetMalicious (score: 100)
Acronissuspicious
McAfeePacked-GCZ!C5F9FFD8890C
VBA32BScope.Trojan.Wacatac
ESET-NOD32a variant of Win32/Kryptik.HHCY
RisingMalware.Obscure/Heur!1.9E03 (CLASSIC)
IkarusTrojan.Win32.Glupteba
FortinetW32/Kryptik.HHCY!tr
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM10.1.F3CB.Malware.Gen

How to remove Trojan-Dropper.Win32.Scrop?

Trojan-Dropper.Win32.Scrop removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment