Backdoor

Backdoor:Win32/Bifrose.HU (file analysis)

Malware Removal

The Backdoor:Win32/Bifrose.HU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Bifrose.HU virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.

How to determine Backdoor:Win32/Bifrose.HU?


File Info:

crc32: 1E7274A4
md5: beea819b39c1bd74b4c3d80f85ae37af
name: BEEA819B39C1BD74B4C3D80F85AE37AF.mlw
sha1: bd6d6e08d989f379036a2135aad621688cdf43da
sha256: 5c56dd4af6c0ffd05252cc2226e81415886e6f4ba21b72ac14dfc671aceea77d
sha512: 2d4511c972787ff0b09da937ebcc153d03fe34b0db9565c6a01f7a8efd04eadbca3a949053ba51012f1520d5d3d8d27442d941b6428ed7d0773075a31ee59b39
ssdeep: 12288:Zy9H3GhJmN4A0lN1ygMageHHlVH0ppa+ZcVPV2ZZa7/zeKVMKPURARJ/O0g4x5:8p2mNcNcgMmn/8abpIZqXMKPd/W01x
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x7248x6743x6240x6709 (C) 2007
InternalName: gh0st RAT
FileVersion: 3, 5, 0, 0
CompanyName:
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: gh0st x5e94x7528x7a0bx5e8f
SpecialBuild:
ProductVersion: 3, 5, 0, 0
FileDescription: Gh0st RAT By CoolDiyer
OriginalFilename: gh0st.EXE
Translation: 0x0804 0x04b0

Backdoor:Win32/Bifrose.HU also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebBackDoor.Siggen.52105
MicroWorld-eScanGenPack:Generic.PcClient2.659D68DD
FireEyeGeneric.mg.beea819b39c1bd74
ALYacGenPack:Generic.PcClient2.659D68DD
CylanceUnsafe
VIPRETrojan-Dropper.Win32.Resdro.b (v) (not malicious)
K7AntiVirusTrojan ( 0052c8a31 )
BitDefenderGenPack:Generic.PcClient2.659D68DD
K7GWTrojan ( 0052c8a31 )
Cybereasonmalicious.b39c1b
BitDefenderThetaAI:Packer.6F0BBBB321
APEXMalicious
AvastWin32:Small-NGK [Trj]
ClamAVWin.Dropper.Ramnit-7076131-0
KasperskyTrojan-GameThief.Win32.Magania.actz
AlibabaBackdoor:Win32/Magania.c7174091
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
RisingBackdoor.Bifrose!8.B24 (CLOUD)
Ad-AwareGenPack:Generic.PcClient2.659D68DD
EmsisoftGenPack:Generic.PcClient2.659D68DD (B)
SophosML/PE-A + Troj/Zegost-U
AviraHEUR/AGEN.1140256
MicrosoftBackdoor:Win32/Bifrose.HU
GDataGenPack:Generic.PcClient2.659D68DD
CynetMalicious (score: 100)
ESET-NOD32a variant of Win32/Farfli.ARN
Acronissuspicious
McAfeeBackDoor-EXZ
MAXmalware (ai score=80)
VBA32BScope.Trojan.MulDrop
TencentWin32.Trojan.Generic.Plaw
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Filecoder.FV!tr.ransom
AVGWin32:Small-NGK [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.41f

How to remove Backdoor:Win32/Bifrose.HU?

Backdoor:Win32/Bifrose.HU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment