Trojan

Trojan.NSIS.Sod.cup (file analysis)

Malware Removal

The Trojan.NSIS.Sod.cup is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.NSIS.Sod.cup virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
edgedl.me.gvt1.com
update.googleapis.com

How to determine Trojan.NSIS.Sod.cup?


File Info:

crc32: F3AB648A
md5: 9d1924b5b5a47ab7caa69e4164b5a2f2
name: 9D1924B5B5A47AB7CAA69E4164B5A2F2.mlw
sha1: 0f55233600b27bdc86f4d354a04d3562f4c679a2
sha256: 2c16b64d03434aabfd4d21f9ffee6bd9f7854c716d414759e0de7dfcacf4386e
sha512: 75a3505ef8f5c8f7313f72e129cb36ac99bb5c53a3b74c8d3fcf645fbecd91d544dbcb8c72f6943086119ee0d6a042f9642fe65a846dc65861497e2d908a14a9
ssdeep: 12288:qntD3aVM0Mj1fIslerekwpjmOFIwPDcfPnhUEJmUj8h:mj0MhRIYeowsDcfPhUwmUjO
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Trojan.NSIS.Sod.cup also known as:

BkavW32.AIDetect.malware2
LionicTrojan.NSIS.Sod.4!c
DrWebTrojan.Encoder.761
CAT-QuickHealRansom.Cerber.A
ALYacTrojan.Ransom.cryptolocker
CylanceUnsafe
ZillyaTrojan.Sod.Win32.61
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaRansom:Win32/Enestedel.7d912741
K7GWTrojan ( 004e24c81 )
K7AntiVirusTrojan ( 004e24c81 )
CyrenW32/Filecoder.FRJV-4194
ESET-NOD32Win32/Filecoder.TorrentLocker.A
ZonerTrojan.Win32.54137
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyTrojan.NSIS.Sod.cup
BitDefenderTrojan.GenericKD.4285525
NANO-AntivirusTrojan.Win32.DKOE.eopobh
ViRobotTrojan.Win32.Z.Agent.430418
MicroWorld-eScanTrojan.GenericKD.4285525
TencentNsis.Trojan.Sod.Htvt
Ad-AwareTrojan.GenericKD.4285525
SophosMal/Generic-R + Mal/Cerber-Z
ComodoMalware@#11csohmgfljp0
F-SecureTrojan.TR/Dropper.vrxqo
BitDefenderThetaGen:NN.ZedlaF.34088.dq4@aWQy7Vk
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CRYPTLOCK.F117B1
McAfee-GW-EditionW32/Teerac.b
FireEyeGeneric.mg.9d1924b5b5a47ab7
EmsisoftTrojan.GenericKD.4285525 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Nisloder.lt
WebrootW32.Trojan.Gen
AviraTR/Dropper.bmsgj
Antiy-AVLTrojan/Win32.BTSGeneric
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftRansom:Win32/Teerac
ArcabitTrojan.Generic.D416455
SUPERAntiSpywareRansom.CryptoLocker/Variant
ZoneAlarmTrojan.NSIS.Sod.cup
GDataWin32.Trojan.Agent.8FQSEN
McAfeeW32/Teerac.b
MAXmalware (ai score=100)
VBA32Trojan.Sod
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/WLT.C
TrendMicro-HouseCallRansom_CRYPTLOCK.F117B1
RisingTrojan.Win32.FileCryptor.aw (CLASSIC)
YandexTrojan.Injector!1cIXlUU5rxE
IkarusTrojan.Win32.Filecoder
FortinetW32/InjectorGen.DLBW!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan.NSIS.Sod.cup?

Trojan.NSIS.Sod.cup removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment