Backdoor

Backdoor.Win32.Plite.bhte information

Malware Removal

The Backdoor.Win32.Plite.bhte is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Plite.bhte virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Korean
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Anomalous binary characteristics

How to determine Backdoor.Win32.Plite.bhte?


File Info:

name: FC586EC9BF96F34C7F12.mlw
path: /opt/CAPEv2/storage/binaries/f3bfb5707bc3a4071be98789560b0ce9bd6f512c6d6f73e1df3949716a4db11f
crc32: 5E0F9C89
md5: fc586ec9bf96f34c7f12f4bd3179f195
sha1: 82f2691a1a9299fb5a905d4517be6c0de1e24fd2
sha256: f3bfb5707bc3a4071be98789560b0ce9bd6f512c6d6f73e1df3949716a4db11f
sha512: 3431bf04541061e2b913ee4288a8eecee8c735b40e63935e32a8f2d8997fe009e3802e8ff5ec8cd87c054894b4c322817338c174355f4d2440461383985aad27
ssdeep: 12288:2tuXx8TYuV176kkJcZgNjSHY809DZfKPyV:2tuXxSIkkq8WWZfJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DEB4CF025A410926F32D13791187E295887B9E3C62E5D68FE2387D79BE724639F7320F
sha3_384: 1c59d163eab4a74e3de6e5c15ead76ca9bcf2a6c6612bca1dfed2691cb4f52e48746ce3923a20581eda236158c661781
ep_bytes: b8e0b648005064ff3500000000648925
timestamp: 2013-08-22 13:11:54

Version Info:

0: [No Data]

Backdoor.Win32.Plite.bhte also known as:

BkavW32.AIDetect.malware1
DrWebTrojan.AVKill.33235
MicroWorld-eScanGen:Heur.Mint.SP.Urelas.1
FireEyeGeneric.mg.fc586ec9bf96f34c
CAT-QuickHealTrojan.Gupboot.G.mue
McAfeeCorrupt-FY!05C66B7E4722
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.9bf96f
BitDefenderThetaGen:NN.ZexaF.34712.FmXaaOwewwdO
VirITTrojan.Win32.AVKill.BXEH
CyrenW32/Urelas.E.gen!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Urelas.S
KasperskyBackdoor.Win32.Plite.bhte
BitDefenderGen:Heur.Mint.SP.Urelas.1
AvastMBR:Plite-I [Rtk]
TencentTrojan.Win32.Urelas.16000132
Ad-AwareGen:Heur.Mint.SP.Urelas.1
EmsisoftGen:Heur.Mint.SP.Urelas.1 (B)
ComodoTrojWare.Win32.Small.NAF@531prv
BaiduWin32.Rootkit.Agent.s
ZillyaTrojan.Urelas.Win32.42233
McAfee-GW-EditionBehavesLike.Win32.Corrupt.hh
Trapminesuspicious.low.ml.score
SophosML/PE-A + Troj/Urelas-AA
SentinelOneStatic AI – Malicious PE
GDataGen:Heur.Mint.SP.Urelas.1
JiangminBackdoor.Generic.zla
AviraTR/Spy.Gen2
MAXmalware (ai score=84)
ArcabitTrojan.Mint.SP.Urelas.1
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.Plite.C187581
VBA32BScope.Trojan.AVKill
MalwarebytesMalware.Heuristic.1001
APEXMalicious
RisingTrojan.Gupboot!1.9CEA (CLASSIC)
YandexTrojan.Urelas!8WIwK05ALTs
IkarusTrojan.Win32.Urelas
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Urelas.O!tr
AVGMBR:Plite-I [Rtk]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Backdoor.Win32.Plite.bhte?

Backdoor.Win32.Plite.bhte removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment