Trojan

Trojan:MSIL/Stealer!mclg (file analysis)

Malware Removal

The Trojan:MSIL/Stealer!mclg is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/Stealer!mclg virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Trojan:MSIL/Stealer!mclg?


File Info:

name: F4B707D2D51BF1DEF596.mlw
path: /opt/CAPEv2/storage/binaries/cd1855fddfcd94e400dea3fd44b8829aa8e84278fb9c750171ed7ac886a4caa8
crc32: B891C2C6
md5: f4b707d2d51bf1def5969fa8fa3dbcb1
sha1: ba1a60b251118f1c99409d8663f214a941223c4d
sha256: cd1855fddfcd94e400dea3fd44b8829aa8e84278fb9c750171ed7ac886a4caa8
sha512: 886088d6db14bdbde5eccb00a42d95bb9c42177f235b9ce13d57819007e14bdca52d941c1f45973ffd917ed8974811dc7996b9522d618327178cee25bda06309
ssdeep: 192:cz3++EyeN/dM9gJakARS7/pDfZgWwbhmIWfmOHPbWreA8HHMs:czO9N/d2O7TZJwbIIWfmOHPSr0Hs
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T119222A01DB8CDE35E5BF573C19B2222056F5D3160902AB8FA6D9916F9F422E18F625F0
sha3_384: f074c22857ff905ea7269821dd1c91960345f7281cda071b648ef55afdcac84702a435952f5eb3b7b8661b5589a65f98
ep_bytes: ff250020400000000000000000000000
timestamp: 2042-07-21 16:36:45

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: Updater
FileVersion: 1.0.0.0
InternalName: Updater.exe
LegalCopyright: Copyright © 2018
LegalTrademarks:
OriginalFilename: Updater.exe
ProductName: Updater
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Trojan:MSIL/Stealer!mclg also known as:

LionicTrojan.MSIL.Agent.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.37158168
McAfeeArtemis!F4B707D2D51B
MalwarebytesTrojan.KryptoCibule
VIPRETrojan.GenericKD.37158168
SangforInfostealer.Msil.Kryptocibule.Vbif
K7AntiVirusTrojan ( 0056da1f1 )
AlibabaTrojan:MSIL/Stealer.d1f6214c
K7GWTrojan ( 0056da1f1 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/KryptoCibule.B.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/KryptoCibule.A
APEXMalicious
KasperskyHEUR:Trojan.MSIL.Agent.gen
BitDefenderTrojan.GenericKD.37158168
AvastWin32:PWSX-gen [Trj]
TencentMsil.Trojan.Agent.Mcnw
EmsisoftTrojan.GenericKD.37158168 (B)
F-SecureHeuristic.HEUR/AGEN.1312819
ZillyaTrojan.Agent.Win32.1402806
TrendMicroTROJ_GEN.R002C0WFK23
McAfee-GW-EditionArtemis!Trojan
FireEyeTrojan.GenericKD.37158168
SophosMal/Generic-S
IkarusTrojan.MSIL.Kryptocibule
GDataTrojan.GenericKD.37158168
JiangminTrojan.MSIL.qkss
WebrootW32.Trojan.Gen
GoogleDetected
AviraHEUR/AGEN.1312819
Antiy-AVLTrojan/MSIL.Agent
ArcabitTrojan.Generic.D236FD18
ZoneAlarmHEUR:Trojan.MSIL.Agent.gen
MicrosoftTrojan:MSIL/Stealer!mclg
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.MSIL.C4554750
ALYacTrojan.GenericKD.37158168
MAXmalware (ai score=100)
VBA32TScope.Trojan.MSIL
Cylanceunsafe
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0WFK23
RisingTrojan.KryptoCibule!8.11F46 (CLOUD)
YandexTrojan.Agent!T4LGhgs0GeM
MaxSecureTrojan.Malware.8703358.susgen
FortinetW32/Agent.A!tr
AVGWin32:PWSX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:MSIL/Stealer!mclg?

Trojan:MSIL/Stealer!mclg removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment