Backdoor

Backdoor.Bifrose (file analysis)

Malware Removal

The Backdoor.Bifrose is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Bifrose virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Queries information on disks, possibly for anti-virtualization
  • Checks for the presence of known windows from debuggers and forensic tools
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks the version of Bios, possibly for anti-virtualization
  • Detected Armadillo packer using a known mutex
  • Collects information to fingerprint the system

How to determine Backdoor.Bifrose?


File Info:

crc32: 82F2D43D
md5: 26dd1dbcb9eed60d5e5a006b103fb06b
name: max8keygen.exe
sha1: 5879cd56562e38c3385421820f906c86f092b68a
sha256: 4763f784c888f77c2d0537dc4c8c6fd2d6ae3c3e09f2f08972245b0660b064eb
sha512: 7597d1be37e48cd01c8c97efeea3d38e24d0a94ae72e027d29013aeee2aa6b0936b7279e5763ee489e0426731f969c01ea2571a7f907c879f57b890b4a494bad
ssdeep: 6144:uCHNhhsTnLV2pPUGw4gAOzKLbpvvpfdH0OpeEbUfpnBSKN84uvdk5Wcff8Drj:uCHNnynLVUMxkbpXzU+tApnBxcSZ6
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor.Bifrose also known as:

BkavW32.AIDetectVM.malware2
CAT-QuickHealBackdoor.Ursap
McAfeeGeneric.elo
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
CrowdStrikewin/malicious_confidence_60% (W)
TrendMicroHKTL_KEYGEN
F-ProtW32/Backdoor.BCBM
SymantecPUA.Keygen
TrendMicro-HouseCallHKTL_KEYGEN
ClamAVWin.Trojan.Sality-74707
GDataWin32.Trojan.Agent.Q0XXQG
AlibabaBackdoor:Win32/Generic.411a7e6d
AegisLabTrojan.Win32.Generic.4!c
Invinceaheuristic
McAfee-GW-EditionGeneric.elo
SentinelOneDFI – Suspicious PE
Trapminemalicious.high.ml.score
APEXMalicious
CyrenW32/Backdoor.FTRN-2687
WebrootW32.Malware.Gen
MicrosoftTrojan:Win32/Wacatac.C!ml
SUPERAntiSpywareTrojan.Agent/Gen-Packed
VBA32Backdoor.Bifrose
MAXmalware (ai score=96)
PandaBck/DService.TK
YandexBackdoor.Agent!Fw84WMafZQg
IkarusTrojan.Win32.Agent
FortinetRiskware/KeyGen
AVGFileRepMetagen [Malware]
MaxSecureTrojan.Malware.2588.susgen

How to remove Backdoor.Bifrose?

Backdoor.Bifrose removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment