Trojan

What is “Trojan:Win32/Manuscrypt.GBY!MTB”?

Malware Removal

The Trojan:Win32/Manuscrypt.GBY!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Manuscrypt.GBY!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • HTTPS urls from behavior.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • A HTTP/S link was seen in a script or command line
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities to create a scheduled task
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Checks for the presence of known windows from debuggers and forensic tools
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Attempts to modify Windows Defender using PowerShell
  • Harvests cookies for information gathering
  • Attempts to execute suspicious powershell command arguments
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Manuscrypt.GBY!MTB?


File Info:

name: 501E01EF5A83953609A5.mlw
path: /opt/CAPEv2/storage/binaries/1172918c38d514bd012034bf851e62f99eeab284ebdb5ad9a20bf6464cde50d5
crc32: 3C40CDA7
md5: 501e01ef5a83953609a5156130acc180
sha1: 68efc31872bb4112c847de9e5159303ef74b6b86
sha256: 1172918c38d514bd012034bf851e62f99eeab284ebdb5ad9a20bf6464cde50d5
sha512: 5464cdc741e55abee17797db43d976338ddbb534211149baf1003b642ca24e7a47da1e87e49eb6a24ba1830f3b2860f2b452af53020390daa9f9517ec4ea08b4
ssdeep: 98304:xcpO0OA8HZQhqijnlQDPDNYFyR9AnzH9TlhbmXIIUGVMpP1B5jkMkzIjCt:xcqZQh7QDaFPzZyXZOpP1jkhImt
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A546337177E5C8F7D72241706814BEA6B1BFE2E90A38269377D0DB1F1632085D2B296C
sha3_384: 20d046a39a32b8a271d12abe3ab4f57e4e753ca697a37dd7406f2e1cb8c9113d4cc81458e84109299bdde74f3ff62fd8
ep_bytes: 558bec6aff6898c24100680691410064
timestamp: 2019-02-21 16:00:00

Version Info:

CompanyName: Igor Pavlov
FileDescription: 7z Setup SFX
FileVersion: 19.00
InternalName: 7zS.sfx
LegalCopyright: Copyright (c) 1999-2018 Igor Pavlov
OriginalFilename: 7zS.sfx.exe
ProductName: 7-Zip
ProductVersion: 19.00
Translation: 0x0409 0x04b0

Trojan:Win32/Manuscrypt.GBY!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Manuscrypt.4!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader45.27627
MicroWorld-eScanDropped:Trojan.GenericKD.63556952
ClamAVWin.Packed.Jaik-9863991-0
FireEyeDropped:Trojan.GenericKD.63556952
CAT-QuickHealTrojan.TiggreRI.S28978929
ALYacDropped:Trojan.GenericKD.63556952
MalwarebytesTrojan.Downloader
VIPREDropped:Trojan.GenericKD.63556952
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0059a1341 )
AlibabaBackdoor:Win32/Injuke.fc072805
K7GWTrojan-Downloader ( 0059a1341 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.36250.hC0@aGsrH8di
CyrenW32/ABRisk.BIYI-2203
SymantecTrojan.Gen.MBT
ESET-NOD32multiple detections
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Manuscrypt.bl
BitDefenderDropped:Trojan.GenericKD.63556952
NANO-AntivirusTrojan.Win32.Manuscrypt.jtfeae
AvastWin32:DropperX-gen [Drp]
TencentWin32.Backdoor.Manuscrypt.Hjgl
EmsisoftDropped:Trojan.GenericKD.63556952 (B)
F-SecureHeuristic.HEUR/AGEN.1312428
TrendMicroTROJ_GEN.R002C0PK322
McAfee-GW-EditionBehavesLike.Win32.Lockbit.tc
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GDataDropped:Trojan.GenericKD.63556952
JiangminTrojan.Generic.hhjod
AviraHEUR/AGEN.1312428
MAXmalware (ai score=85)
Antiy-AVLGrayWare/Win32.Generic
XcitiumMalware@#isvlibowlk75
ArcabitTrojan.Generic.D3C9CD58
ViRobotTrojan.Win32.Z.Jaik.5818318
ZoneAlarmBackdoor.Win32.Manuscrypt.bl
MicrosoftTrojan:Win32/Manuscrypt.GBY!MTB
GoogleDetected
AhnLab-V3Downloader/Win.Powershell.C5345506
Acronissuspicious
McAfeeArtemis!501E01EF5A83
VBA32BScope.Backdoor.Manuscrypt
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0PK322
RisingTrojan.Starter!1.DDB6 (CLASSIC:bWQ1Op92/PBWuRq4)
IkarusTrojan-Downloader.Win32.Agent
FortinetW32/Agent_AGen.BC!tr
AVGWin32:DropperX-gen [Drp]
Cybereasonmalicious.f5a839
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Manuscrypt.GBY!MTB?

Trojan:Win32/Manuscrypt.GBY!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment