Backdoor

Backdoor:Win32/Bifrose.ACI (file analysis)

Malware Removal

The Backdoor:Win32/Bifrose.ACI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Bifrose.ACI virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Backdoor:Win32/Bifrose.ACI?


File Info:

crc32: D583A2B9
md5: 5a5432ebe6fe46aa0b142bfd717b488b
name: 5A5432EBE6FE46AA0B142BFD717B488B.mlw
sha1: 7cd6a12d5b1fb3de0eccd9c56967ddac276e1f1e
sha256: dd7c21e65998b6ea0094154eb2788d15a7d5e2d8841a19c3253e3937395cc4e3
sha512: d955186c292a17fccb8bef689de264b5d789bfdfb4f450bafc6a32e66105b9614e4de2b53cd64f655b2f55baa77e43937f1a01f68861ca10ec7417b3b933c205
ssdeep: 1536:HDhzGpmOPSencocsC8OJVHYH+zN+Qx66G6B7HH4yU:jhzgm9FojOo+Zx6P6Cy
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor:Win32/Bifrose.ACI also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebBackDoor.Pigeon.12912
MicroWorld-eScanGen:Trojan.Heur.eGW@IPianfci
FireEyeGeneric.mg.5a5432ebe6fe46aa
ALYacGen:Trojan.Heur.eGW@IPianfci
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 0055e3df1 )
BitDefenderGen:Trojan.Heur.eGW@IPianfci
K7GWTrojan ( 0055e3df1 )
Cybereasonmalicious.be6fe4
BitDefenderThetaAI:Packer.5262749A1C
CyrenW32/Risk.CWMZ-3609
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_KRAP.SMOG
AvastWin32:Konar-B [Trj]
ClamAVWin.Trojan.Bifrose-8772
KasperskyBackdoor.Win32.SdBot.pyv
NANO-AntivirusTrojan.Win32.Bifrose.beqgh
ViRobotTrojan.Win32.Downloader.326656
RisingTrojan.Generic@ML.100 (RDML:Kq9B25SNNBzVsfg9vqvwEA)
Ad-AwareGen:Trojan.Heur.eGW@IPianfci
TACHYONBackdoor/W32.DP-SdBot.75776
EmsisoftGen:Trojan.Heur.eGW@IPianfci (B)
ComodoTrojWare.Win32.TrojanDropper.Agent.~YCA@197ro
F-SecureTrojan.TR/Crypt.XDR.Gen
ZillyaBackdoor.Hupigon.Win32.161098
TrendMicroTROJ_KRAP.SMOG
McAfee-GW-EditionBehavesLike.Win32.Wabot.lc
SophosML/PE-A + Troj/Bifrose-XU
IkarusTrojan.Win32.Midgare
JiangminTrojanDropper.Wlord.bn
AviraTR/Crypt.XDR.Gen
Antiy-AVLTrojan[Backdoor]/Win32.SdBot
KingsoftWin32.Hack.SdBot.p.(kcloud)
MicrosoftBackdoor:Win32/Bifrose.ACI
ArcabitTrojan.Heur.EB908D
ZoneAlarmBackdoor.Win32.SdBot.pyv
GDataGen:Trojan.Heur.eGW@IPianfci
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Bifrose.R77038
Acronissuspicious
McAfeeGenericRXGB-VR!5A5432EBE6FE
MAXmalware (ai score=85)
VBA32Backdoor.SdBot
MalwarebytesMalware.AI.3164477497
PandaGeneric Malware
APEXMalicious
ESET-NOD32a variant of Win32/TrojanDropper.Surldoe.B
TencentBackdoor.Win32.Sdbot.pyv
YandexTrojan.GenAsa!gs4h0fYpeDA
SentinelOneStatic AI – Suspicious PE
FortinetW32/Generic.AC.1F068E!tr
AVGWin32:Konar-B [Trj]
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360Win32/Backdoor.BO.8fe

How to remove Backdoor:Win32/Bifrose.ACI?

Backdoor:Win32/Bifrose.ACI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment