Backdoor

Backdoor.Plite malicious file

Malware Removal

The Backdoor.Plite is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Plite virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location
  • Anomalous binary characteristics

How to determine Backdoor.Plite?


File Info:

name: 739E64EAC8C4FC21B4F7.mlw
path: /opt/CAPEv2/storage/binaries/b42900a179563f547e8446c22967579665a922ac21de53dcc7276444b7ce3ec0
crc32: 88E62EB2
md5: 739e64eac8c4fc21b4f7bbb21c9ac7fe
sha1: a861cd5dc38196d117bb968623b2c6a9b688e1f8
sha256: b42900a179563f547e8446c22967579665a922ac21de53dcc7276444b7ce3ec0
sha512: a57cd89ae92b7750e859ef290ad784b9755edd05c3b42b1e8e6275ad7d58582020bf69a77e77b583cef4332f6099b6f55e3e9e2dcd0c7fc15b94246a3fa2f634
ssdeep: 3072:0G7ZveDrZ5pzqO5kDEjUrqfZZY577T9LngvBe/GJI9E5UJmkJU1:04e33pzqO56QUufZK577hLn6eF9Jmky
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T180444C213680C032E356273049E6E6F55AA97C794AA4E64FF7B47F391E315938A3720F
sha3_384: f1fc8db685a86e6204e9a38d637b74b1381238f3584833af372ccdf22a74cd2308bdf52ed8ad5e0fecedc8a1e566b65e
ep_bytes: e8f4830000e979feffff8bff558bec8b
timestamp: 2014-07-04 06:16:57

Version Info:

0: [No Data]

Backdoor.Plite also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Mint.SP.Urelas.1
FireEyeGeneric.mg.739e64eac8c4fc21
CAT-QuickHealBackdoor.PlitePMF.S22785952
CylanceUnsafe
VIPRETrojan.Win32.Urelas.ab (v)
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
BitDefenderGen:Heur.Mint.SP.Urelas.1
K7GWBackdoor ( 0053e8561 )
K7AntiVirusBackdoor ( 0053e8561 )
ArcabitTrojan.Mint.SP.Urelas.1
BitDefenderThetaGen:NN.ZexaF.34294.qCX@aKfrLmdi
CyrenW32/Urelas.BB.gen!Eldorado
ESET-NOD32a variant of Win32/Urelas.U
BaiduWin32.Trojan.Urelas.b
ClamAVWin.Malware.Urelas-6717394-0
KasperskyBackdoor.Win32.Plite.bhtg
NANO-AntivirusTrojan.Win32.Plite.fwxvjh
RisingTrojan.Urelas!1.BE13 (CLASSIC)
Ad-AwareGen:Heur.Mint.SP.Urelas.1
EmsisoftGen:Heur.Mint.SP.Urelas.1 (B)
ComodoTrojWare.Win32.Urelas.ASE@5izxb0
DrWebBackDoor.Golf.260
ZillyaBackdoor.Plite.Win32.19520
SophosML/PE-A + Troj/Urelas-Q
APEXMalicious
JiangminTrojan/GenericCryptor.bt
eGambitUnsafe.AI_Score_91%
AviraTR/Spy.Gen2
MAXmalware (ai score=80)
Antiy-AVLTrojan/Generic.ASCommon.177
MicrosoftTrojan:Win32/Urelas.AA
GDataWin32.Trojan.PSE.1BSN4LX
AhnLab-V3Trojan/Win.Urelas.R445939
Acronissuspicious
McAfeePWS-FBQQ!739E64EAC8C4
VBA32Backdoor.Plite
MalwarebytesMalware.AI.847887156
IkarusTrojan.Win32.Beaugrit
PandaTrj/Genetic.gen
TencentTrojan.Win32.BitCoinMiner.la
YandexBackdoor.Plite!4viDI0bWM0Y
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Urelas.U!tr
AVGWin32:Malware-gen
Cybereasonmalicious.ac8c4f
AvastWin32:Malware-gen

How to remove Backdoor.Plite?

Backdoor.Plite removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment