Trojan

Trojan.MSIL.BitCoin information

Malware Removal

The Trojan.MSIL.BitCoin is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.MSIL.BitCoin virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Manipulates data from or to the Recycle Bin
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • CAPE detected the RevengeRAT malware family
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.MSIL.BitCoin?


File Info:

name: 34D662495549A945626A.mlw
path: /opt/CAPEv2/storage/binaries/e9d726746ccccb05f3cebbe220c3a066fa3465bd4d2972b5b75790316721237f
crc32: 0B9AE360
md5: 34d662495549a945626acea7a700322c
sha1: 378549306c5779a6715662b93fe3adca9e448876
sha256: e9d726746ccccb05f3cebbe220c3a066fa3465bd4d2972b5b75790316721237f
sha512: f7d36e5371736650bbbcbd15c865b5821f699416c1ed6e4de62210fb5643a19d83e527920be1cd44fb1ffee5f5be9c073b70368da740a9ddbeee22f37f16baf0
ssdeep: 3072:UGF+oP20i9zc5Ev79gvZb4YzAx6hDz0wz5OdRS+:7F+ou0b6Duv+YEwNaS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T170147B397B4ACF52C61C517950D7B615A3B05B975F33DA0E1ED834AE28933830E8A1DB
sha3_384: 17c7413beaa04318b725746866cb630f4207abe3792464278a1e508ef8bae41afba335d36df3e299c417ed2537170a82
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-11-01 23:22:32

Version Info:

CompanyName: Google LLC
FileDescription: Google Chrome
FileVersion: 95.0.4638.69
InternalName: chrome.exe
LegalCopyright: Copyright 2021 Google LLC. All rights reserved.
OriginalFilename: chrome.exe
LegalTrademarks:
ProductName: Google Chrome
ProductVersion: 95.0.4638.69
Translation: 0x0409 0x04b0

Trojan.MSIL.BitCoin also known as:

LionicTrojan.MSIL.BitCoin.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
FireEyeGeneric.mg.34d662495549a945
ALYacGen:Variant.MSILPerseus.64509
CylanceUnsafe
SangforTrojan.MSIL.Agent.AZM
K7AntiVirusTrojan ( 700000121 )
AlibabaTrojan:Win32/csharp.ali2000008
K7GWTrojan ( 700000121 )
Cybereasonmalicious.95549a
CyrenW32/MSIL_Kryptik.AXV.gen!Eldorado
SymantecTrojan.Revetrat
ESET-NOD32a variant of MSIL/Agent.AZM
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Generic-6332612-0
KasperskyHEUR:Trojan.MSIL.BitCoin.gen
BitDefenderGen:Variant.MSILPerseus.64509
NANO-AntivirusTrojan.Win32.BitCoin.jgxaqc
MicroWorld-eScanGen:Variant.MSILPerseus.64509
AvastWin32:RATX-gen [Trj]
TencentMsil.Trojan.Bitcoin.Llhm
Ad-AwareGen:Variant.MSILPerseus.64509
SophosMal/Generic-R + Mal/Revet-A
DrWebBackDoor.SpyBotNET.20
McAfee-GW-EditionGenericRXCE-BF!34D662495549
EmsisoftGen:Variant.MSILPerseus.64509 (B)
IkarusTrojan.MSIL.Agent
GDataGen:Variant.MSILPerseus.64509
AviraTR/ATRAPS.Gen2
Antiy-AVLTrojan/MSIL.Agent
GridinsoftRansom.Win32.Bladabindi.sa
ArcabitTrojan.MSILPerseus.DFBFD
ViRobotTrojan.Win32.Z.Agent.203264.ADC
MicrosoftTrojan:Win32/Bladabindi!BV
AhnLab-V3Trojan/Win32.MSIL.R351711
Acronissuspicious
McAfeeGenericRXCE-BF!34D662495549
MAXmalware (ai score=89)
VBA32TScope.Trojan.MSIL
MalwarebytesBackdoor.RevengeRAT
TrendMicro-HouseCallTROJ_GEN.R002C0DK421
RisingTrojan.RevengrRat!8.12539 (CLOUD)
YandexTrojan.BitCoin!xcBy5xtTMUs
SentinelOneStatic AI – Malicious PE
eGambitTrojan.Generic
FortinetMSIL/Agent.AZM!tr
BitDefenderThetaGen:NN.ZemsilF.34160.mq0@au@lDNbG
AVGWin32:RATX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan.MSIL.BitCoin?

Trojan.MSIL.BitCoin removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment