Backdoor

About “Backdoor.Win32.Defsel.go” infection

Malware Removal

The Backdoor.Win32.Defsel.go is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Defsel.go virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

How to determine Backdoor.Win32.Defsel.go?


File Info:

name: 1FD6A5A6C3012B3FBF33.mlw
path: /opt/CAPEv2/storage/binaries/bb30e1062f9215e2fb2381ebec85e414dbb48c6bfbd5bdb827a4213e305b9cc5
crc32: 9DEDDBA0
md5: 1fd6a5a6c3012b3fbf337a1d710843c2
sha1: e0b716f49265c7415ae713383c4ce27e2519908d
sha256: bb30e1062f9215e2fb2381ebec85e414dbb48c6bfbd5bdb827a4213e305b9cc5
sha512: fe6de8319a07e586c02f82c35656fc88eb6682ece6849f4c4f93e55f95dcec765af5b4a3d4ec8def904e4b724f032682b2fa21eed5a4b309d50c458dc3be5b15
ssdeep: 24576:qtb20pkaCqT5TBWgNQ7amCYpAteFqMLvyGUSSjmsSMSO6A:XVg5tQ7amCvtIqGUSC5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14955D01373DE8365C3B26273BA667701BE7B782506A1F86B2FD8093DA920121525E773
sha3_384: a1ca1802d670c2d5164dc82c0c4ca45cd7a41e68a0c4a331c1e30797ef6f54bf64e2ca68f0dfca7cf4d4210fac145fb7
ep_bytes: e86ace0000e97ffeffffcccc57568b74
timestamp: 2018-11-19 02:22:39

Version Info:

Translation: 0x0809 0x04b0

Backdoor.Win32.Defsel.go also known as:

LionicTrojan.Win32.Defsel.4!c
MicroWorld-eScanTrojan.GenericKD.40773263
FireEyeGeneric.mg.1fd6a5a6c3012b3f
ALYacTrojan.GenericKD.40773263
CylanceUnsafe
K7AntiVirusTrojan ( 005642691 )
AlibabaTrojan:Win32/AutoitU.ali2000008
K7GWTrojan ( 005642691 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/Injector.Autoit.DKY
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Agent-6825810-0-6852456-0
KasperskyBackdoor.Win32.Defsel.go
BitDefenderTrojan.GenericKD.40773263
NANO-AntivirusTrojan.Win32.Defsel.fklebf
AvastFileRepMalware
TencentWin32.Backdoor.Defsel.Edoo
Ad-AwareTrojan.GenericKD.40773263
TACHYONBackdoor/W32.Defsel.1330688
EmsisoftTrojan.GenericKD.40773263 (B)
ComodoMalware@#ua8x8sjl0lli
DrWebBackDoor.Paper.28
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PGJ21
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.tc
SophosMal/Generic-S
IkarusTrojan.Win32.Injector
GDataTrojan.GenericKD.40773263
AviraTR/AD.Hupignon.B
MicrosoftTrojan:Win32/Skeeyah.A!rfn
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C2848945
McAfeeArtemis!1FD6A5A6C301
MAXmalware (ai score=100)
VBA32Backdoor.Defsel
MalwarebytesMachineLearning/Anomalous.100%
TrendMicro-HouseCallTROJ_GEN.R002C0PGJ21
eGambitUnsafe.AI_Score_77%
FortinetAutoIt/Injector.DLB!tr
AVGFileRepMalware
PandaTrj/CI.A
MaxSecureTrojan.Malware.300983.susgen

How to remove Backdoor.Win32.Defsel.go?

Backdoor.Win32.Defsel.go removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment