Backdoor

How to remove “Backdoor.Bot.138484”?

Malware Removal

The Backdoor.Bot.138484 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Bot.138484 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Starts servers listening on 0.0.0.0:5005
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • Operates on local firewall’s policies and settings
  • Creates a copy of itself
  • Harvests credentials from local FTP client softwares

How to determine Backdoor.Bot.138484?


File Info:

name: 57CA18EC478892E15FFE.mlw
path: /opt/CAPEv2/storage/binaries/aae6e1601563e828f3d915f83aaf2150abfce0ba0dcd5039e027760423d45e53
crc32: 752C59C0
md5: 57ca18ec478892e15ffe930ca41bb4db
sha1: e246073aad62e18753cc9af5979a808e48066aa4
sha256: aae6e1601563e828f3d915f83aaf2150abfce0ba0dcd5039e027760423d45e53
sha512: 25899f0fa33ef81706e4f143b59d681899cc59b9d31af6a5892d4f9f5a2a4d7525be5d47c16a82d297dbd9cb05c410f6afeaf9fdfd8621a56270e4429e7191b8
ssdeep: 3072:olK6mVy/Ikp39vWYqezcYIOqNC+ndFzakZhsYzpRdS:mKONZfqeQlOqw+ndFR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T168E301A069983F20D423A230712B2F758AFA9B1F777E224CEDFE0779A125D010B97195
sha3_384: 23c702c0444e1d0a18ffcf4a57dca7395ad2d74f00e26f18cf2c560298005a7836087787f38f926fbfc18a7626151171
ep_bytes: 60be0070d2008dbe00a06dff57eb0b90
timestamp: 2003-02-24 09:27:07

Version Info:

CompanyName: Gvxiypa Rajpdcwo
FileDescription: Gvxiypa Udxqop Xrqrisacv
FileVersion: 49, 113, 85, 70
InternalName: Gvxiypa
LegalCopyright: Copyright © Gvxiypa Rajpdcwo 1999-2011
OriginalFilename: Gvxiypa.exe
ProductName: Gvxiypa Udxqop Xrqrisacv
ProductVersion: 49, 113, 85, 70
Translation: 0x0409 0x04e4

Backdoor.Bot.138484 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanBackdoor.Bot.138484
FireEyeGeneric.mg.57ca18ec478892e1
McAfeeW32/Pinkslipbot.gen.af
CylanceUnsafe
ZillyaTrojan.Jorik.Win32.6192
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( f1000f011 )
AlibabaBackdoor:Win32/Obfuscator.263fcee0
K7GWTrojan ( f1000f011 )
Cybereasonmalicious.c47889
BitDefenderThetaAI:Packer.70CB283F1F
CyrenW32/Zbot.DA.gen!Eldorado
SymantecTrojan.Ransomlock!gen4
ESET-NOD32a variant of Win32/Kryptik.QTU
TrendMicro-HouseCallMal_Kryptik-3
Paloaltogeneric.ml
ClamAVWin.Trojan.Agent-491598
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderBackdoor.Bot.138484
NANO-AntivirusTrojan.Win32.TrjGen.cryyo
AvastWin32:Evo-gen [Susp]
TencentWin32.Trojan.Generic.Sxyo
Ad-AwareBackdoor.Bot.138484
EmsisoftBackdoor.Bot.138484 (B)
ComodoMalware@#3jb9i89i9uqpz
DrWebBackDoor.DarkNess.126
VIPREPacked.Win32.PWSZbot.gen (v)
TrendMicroMal_Kryptik-3
McAfee-GW-EditionW32/Pinkslipbot.gen.af
SentinelOneStatic AI – Malicious PE
SophosML/PE-A + Mal/Zbot-CX
APEXMalicious
GDataBackdoor.Bot.138484
JiangminTrojan/Jorik.fwk
eGambitGeneric.Malware
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan/Generic.ASMalwS.A40AAC
ArcabitBackdoor.Bot.D21CF4
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftBackdoor:Win32/Votwup.B
CynetMalicious (score: 100)
VBA32Trojan.Zeus.EA.0999
ALYacBackdoor.Bot.138484
MAXmalware (ai score=100)
RisingBackdoor.Votwup!8.87E (CLOUD)
YandexTrojan.GenAsa!cL5zCAH/y+k
IkarusTrojan.Win32.Ransom
FortinetW32/Kryptik.NAS!tr
AVGWin32:Evo-gen [Susp]
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Backdoor.Bot.138484?

Backdoor.Bot.138484 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment