Backdoor

Backdoor.PowerShell (file analysis)

Malware Removal

The Backdoor.PowerShell is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.PowerShell virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • A script or command line contains a long continuous string indicative of obfuscation
  • Attempts to execute suspicious powershell command arguments

How to determine Backdoor.PowerShell?


File Info:

name: B72AC5DDB1AB0D55F8C6.mlw
path: /opt/CAPEv2/storage/binaries/1849b011354bfd83db0b8e3620c1223c8449d263fa528ae5000c6e131391b195
crc32: 13B4DF22
md5: b72ac5ddb1ab0d55f8c6a2c16c628fab
sha1: 6391d7c0e264aa874d8e9055bdf7b7d0217a73e0
sha256: 1849b011354bfd83db0b8e3620c1223c8449d263fa528ae5000c6e131391b195
sha512: 65e7a60141b4f5c87360b7314a4d285e6af21edce9d6624fc235b72b31b971fd06e7f688a3cd1cad65964d9ab56d21403f31d94a30d3b252b2c1c83bcc68d44b
ssdeep: 3072:+2sMWkzbJh1qZ9QW69hd1MMdxPe9N9uA0hu9TBfcXzO:/bJhs7QW69hd1MMdxPe9N9uA0hu9TBaO
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T1D1C33966B2E01198DBB581F6D9921706EB7074721B15A3DB6BB853B31B2B4C68F3C3D0
sha3_384: e1029c17028e1f44ce96f73e1e8078546270125c2eaefbbbb3ca7c339d6f436ce4afc0291f3b52132f4956c9a1d168c2
ep_bytes: 4883ec2849c7c0600100004831d248b9
timestamp: 2018-02-01 19:43:24

Version Info:

0: [No Data]

Backdoor.PowerShell also known as:

LionicTrojan.PowerShell.Agent.m!c
Elasticmalicious (high confidence)
MicroWorld-eScanHeur.BZC.PZQ.Boxter.762.2D404150
FireEyeGeneric.mg.b72ac5ddb1ab0d55
McAfeeArtemis!B72AC5DDB1AB
CylanceUnsafe
CrowdStrikewin/malicious_confidence_80% (W)
AlibabaBackdoor:Win32/Kryptik.e15bd1f3
K7GWTrojan ( 0052796d1 )
K7AntiVirusTrojan ( 0052796d1 )
CyrenW64/Kryptik.CJC.gen!Eldorado
SymantecDownloader
ESET-NOD32PowerShell/Kryptik.H
APEXMalicious
Paloaltogeneric.ml
KasperskyUDS:Trojan-Downloader.Win32.PsDownload
BitDefenderHeur.BZC.PZQ.Boxter.762.2D404150
AvastFileRepMalware
TencentWin32.Backdoor.Agent.Pdvu
Ad-AwareHeur.BZC.PZQ.Boxter.762.2D404150
SophosMal/Generic-S
TrendMicroTROJ_GEN.R002C0WKN21
McAfee-GW-EditionBehavesLike.Win64.Dropper.ch
EmsisoftHeur.BZC.PZQ.Boxter.762.2D404150 (B)
IkarusTrojan.PowerShell.Crypt
GDataHeur.BZC.PZQ.Boxter.762.2D404150
eGambitUnsafe.AI_Score_51%
AviraTR/B2E.Dropper.Gen
MAXmalware (ai score=80)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win64.RL_Generic.R345984
ALYacHeur.BZC.PZQ.Boxter.762.2D404150
VBA32Backdoor.PowerShell
MalwarebytesTrojan.PowerShell
TrendMicro-HouseCallTROJ_GEN.R002C0WKN21
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.73799730.susgen
FortinetW64/Agent.C317!tr
AVGFileRepMalware
Cybereasonmalicious.db1ab0

How to remove Backdoor.PowerShell?

Backdoor.PowerShell removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment