Threat Database Trojans TrojanSpy:MSIL/Omaneat

TrojanSpy:MSIL/Omaneat

By GoldSparrow in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 3,076
First Seen: October 26, 2015
Last Seen: April 14, 2022
OS(es) Affected: Windows

TrojanSpy:MSIL/Omaneat is malware that collects data like software and hardware configuration, browsing history, OS type, installed AV products and browser on the system it infiltrates successfully. The TrojanSpy:MSIL/Omaneat malware is similar to Dyranges and CoreBot and users that store their passwords in their browser and plain text files are in danger of losing control over their social media profiles and online banking accounts. Moreover, the data that TrojanSpy:MSIL/Omaneat gathers may be sold by its operators on forums on the Dark Web for profit. The Omaneat trojan may be deployed to users as an attached file to spam emails and feature a double extension to fool users into thinking that they are opening an image, document and video. The TrojanSpy:MSIL/Omaneat malware can be detected under other names like MAL/MSIL-BZ, TR/AGENT.227328.119, MSIL/AGENT.AAD and Backdoor.MSIL.Omaneat. The Omaneat trojan may help its operators exploit vulnerabilities in your Webb browser to achieve remote code execution and install other malware such as CryptoWall and Coin Locker. The malware mentioned before uses cryptographic mechanisms to encrypt the victim's files and ask for ransom. The Omaneat trojan may connect to a remote host to download a keylogger like KeyBase to record your keystrokes and might record a feed of your desktop and take screenshots. Practically, the TrojanSpy:MSIL/Omaneat can not damage your system, but it may slow it down. The data that the Omaneat trojan gathers may be used by malware agents to manipulate your installed programs and file system remotely. The TrojanSpy:MSIL/Omaneat malware may use JavaScript to monitor your activity in Google Chrome, Internet Explorer and Mozilla Firefox. The TrojanSpy:MSIL/Omaneat malware may send information at regular intervals of time and appear in your Windows Task Manager as a background process without an accompanying description. Computer users need to install a credible anti-spyware solution to eliminate the TrojanSpy:MSIL/Omaneat malware efficiently.

SpyHunter Detects & Remove TrojanSpy:MSIL/Omaneat

File System Details

TrojanSpy:MSIL/Omaneat may create the following file(s):
# File Name MD5 Detections
1. helper.exe 661d117cc594f15610e6c6f5461e9283 411
2. clientmonitor.exe 7237d0204664becbfe05ce6a95c2c3ba 167
3. clientmonitor.exe 78a2bd7c83a7ce3ecbfbdc8adf45e816 28
4. client.exe 11cf641a692f987ed51cc8975788325b 24
5. clientmonitor.exe 0880120367c360ed8776073a27ef3dd9 22
6. clientmonitor.exe 0a99d856bc28485bced13aa6fe4cc273 19
7. clientmonitor.exe 603fa3000d3784d7418815c2df2eab8a 18
8. file.exe 7da7dce32928c4fc6490155c355aa95a 18
9. client.exe 47ad3912914b20a11521e83f2e5df914 15
10. helper.exe 88319a6d6248448208afccd7d223b8c5 12
11. helper.exe 6f840b8bb2c3e253388579b9454ef1b3 12
12. client.exe 3a785d07f2dec0b37ba2825ead0bf472 6
13. clientmonitor.exe d32b13599487fa20e164669df361393b 6
14. client.exe 90bcd4e727eb66daa3ffb185dda3cee4 5
15. clientmonitor.exe 41e402cfdc99209a682b98ed0f8f955a 5
16. clientmonitor.exe 4ad81bdeb64c789669f382ef173e7b98 4
17. clientmonitor.exe 80b1bb113fe4ccad9e5b3eddc06db412 4
18. clientmonitor.exe 7328ed6af960cc43c532331ff46711c9 4
19. clientmonitor.exe b8e3b0d40e04eb6993c0362b8b5f5ede 4
20. client.exe eb6e4ca1f24c5ee82066a9ead5472254 3
21. client.exe c6c64b3ad06426330a5ab74aec44b183 3
22. clientmonitor.exe 288b7906adde3397e2436acff9fab289 3
23. client.exe 5d0cc455b622a05ed4507e2dbac844d8 3
24. client.exe 023f7ec949ae85361d2c623dd22c2e33 2
25. clientmonitor.exe 1480800955db79479f95e357df0f99cd 2
26. clientmonitor.exe 30f25d59a89c61a7f26f335c4f671a2d 2
27. clientmonitor.exe 5452846503eae5e83b7cff2b990ebdf3 2
More files

Registry Details

TrojanSpy:MSIL/Omaneat may create the following registry entry or registry entries:
Regexp file mask
%ALLUSERSPROFILE%\Client\client.exe
%APPDATA%\clientmonitor.exe
%WINDIR%\SysWOW64\winloguptades.exe

Trending

Most Viewed

Loading...