Malware

Win32/Injector.EPGT (file analysis)

Malware Removal

The Win32/Injector.EPGT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.EPGT virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/Injector.EPGT?


File Info:

name: 2F6C270F40F8E416B580.mlw
path: /opt/CAPEv2/storage/binaries/dc87c97a18f1c18c14859483064226616ab5178f25066511432d00ec8be326b0
crc32: B3F0207F
md5: 2f6c270f40f8e416b58083ef2f722476
sha1: a6dd7b89ba744178a4d000e474454f084c27e8ae
sha256: dc87c97a18f1c18c14859483064226616ab5178f25066511432d00ec8be326b0
sha512: 9ac039006e2102930806ce84757c8aa458713b4ae02a8c461f383ecc6c50decb36cf77f51864e20eee009d9ba03dc7ed6514be61cb064dd54386d6ec956d7ee8
ssdeep: 1536:tY4XL8yM7VuRiYm6b9JUjzx4gzbZPCuZnPp5dvITpzCt38ToFSbgPgAU22Wrp1hP:6y2r6Vul1c2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T175C33F923780F977E89984F1ABD9022C14A32F74691B7507F78B766826F0BF4414CBA7
sha3_384: 5c691590bd297bc9b4d2198f6b1df9e9ceb5a09f9b42798312f99c03c64ef216e29a290961aec70e28d74ad9f82942d9
ep_bytes: 68341d4000e8eeffffff000000000000
timestamp: 2021-05-04 21:50:52

Version Info:

Translation: 0x0409 0x04b0
Comments: AstroPiccon
CompanyName: AstroPiccon
FileDescription: AstroPiccon
LegalCopyright: AstroPiccon
LegalTrademarks: AstroPiccon
ProductName: AstroPiccon
FileVersion: 2.00
ProductVersion: 2.00
InternalName: OMLASTENDES
OriginalFilename: OMLASTENDES.exe

Win32/Injector.EPGT also known as:

LionicTrojan.Win32.Androm.m!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.36852260
FireEyeGeneric.mg.2f6c270f40f8e416
CAT-QuickHealBackdoor.AndromVMF.S21190443
ALYacTrojan.GenericKD.36852260
CylanceUnsafe
VIPRETrojan.GenericKD.36852260
SangforBackdoor.Win32.Androm.uocb
K7AntiVirusTrojan ( 0057bf591 )
AlibabaBackdoor:Win32/VBInject.2cff7d18
K7GWTrojan ( 0057bf591 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZevbaF.34646.hm0@auIr!7ci
VirITTrojan.Win32.VBZenPack_Heur
CyrenW32/VB_Troj.BI.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Injector.EPGT
APEXMalicious
Paloaltogeneric.ml
KasperskyBackdoor.Win32.Androm.uocb
BitDefenderTrojan.GenericKD.36852260
NANO-AntivirusTrojan.Win32.FCYP.ivirhr
AvastWin32:Trojan-gen
Ad-AwareTrojan.GenericKD.36852260
SophosMal/Generic-R + Troj/VB-KYM
ZillyaBackdoor.Androm.Win32.77011
TrendMicroTROJ_GEN.R007C0DHV22
McAfee-GW-EditionPWS-FCYP!2F6C270F40F8
EmsisoftTrojan.GenericKD.36852260 (B)
IkarusTrojan.VB.Crypt
WebrootW32.Trojan.Gen
GoogleDetected
AviraHEUR/AGEN.1206901
MAXmalware (ai score=83)
MicrosoftTrojan:Win32/VBInject.VAM!MTB
GDataTrojan.GenericKD.36852260
CynetMalicious (score: 100)
McAfeePWS-FCYP!2F6C270F40F8
VBA32BScope.Trojan.Sabsik.FL
MalwarebytesTrojan.GuLoader
TrendMicro-HouseCallTROJ_GEN.R007C0DHV22
RisingTrojan.Injector!8.C4 (TFE:5:BA3dJtnCOyM)
SentinelOneStatic AI – Suspicious PE
FortinetW32/Kryptik.EPLG!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.f40f8e
PandaTrj/GdSda.A

How to remove Win32/Injector.EPGT?

Win32/Injector.EPGT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment