Backdoor

What is “Backdoor:Win32/Bifrose!C”?

Malware Removal

The Backdoor:Win32/Bifrose!C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Bifrose!C virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Creates RWX memory
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Backdoor:Win32/Bifrose!C?


File Info:

crc32: B9213083
md5: 2580fd62ce31af466858583c9c782aa5
name: 2580FD62CE31AF466858583C9C782AA5.mlw
sha1: 825497f2fd9458b09351daa328f811de088461e1
sha256: c628c7094b806bc453df6dc17f91dd40c45b4167d6e407cb01041dd879ce1675
sha512: 89a5e1aea25874eadc54d22359df7f45e8198706cac1963196c8bf3b1c76fb1fe8e6d12cb17ad974e92ee69d8a4250948170adf662efbc0b512a8a6dce808999
ssdeep: 1536:c/7q3HQ+XIHZq/iTMkUm9uC81KewxwAYTX16/cr+HJAL+/3yD:cIHzwZIi4kUyu11KfxwA9y+K+/38
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor:Win32/Bifrose!C also known as:

BkavW32.AIDetect.malware1
LionicHacktool.Win32.Krap.kZ21
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop.14548
CynetMalicious (score: 100)
CMCGeneric.Win32.2580fd62ce!CMCRadar
CAT-QuickHealTrojan.Delfinject.17618
ALYacBackdoor.Bifrose.CC
CylanceUnsafe
ZillyaTrojan.Injector.Win32.118694
SangforTrojan.Win32.Delphi.Gen
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaBackdoor:Win32/Bifrose.418f8706
Cybereasonmalicious.2ce31a
CyrenW32/DelfInject.B.gen!Eldorado
SymantecW32.IRCBot
ESET-NOD32a variant of Win32/Injector.U
APEXMalicious
AvastWin32:IRCBot-DGN [Trj]
ClamAVWin.Trojan.Agent-54367
KasperskyBackdoor.Win32.Bifrose.fzrc
BitDefenderTrojan.Injector.AG
NANO-AntivirusTrojan.Win32.Drop.cwdpkv
ViRobotBackdoor.Win32.A.Bifrose.109568.E
MicroWorld-eScanTrojan.Injector.AG
TencentWin32.Backdoor.Bifrose.Hqvg
Ad-AwareTrojan.Injector.AG
SophosML/PE-A + Mal/Behav-154
ComodoBackdoor@#2yrtkn4aqvnnn
BitDefenderThetaAI:Packer.6CBC37F11E
VIPRETrojan-Spy.Win32.Zbot.gen (v)
TrendMicroTROJ_DELF.SMS
McAfee-GW-EditionBehavesLike.Win32.Eggnog.ch
FireEyeGeneric.mg.2580fd62ce31af46
EmsisoftTrojan.Injector.AG (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Buzus.ayr
WebrootW32.Bifrose.Gen
AviraTR/Dldr.Delphi.Gen
Antiy-AVLTrojan/Generic.ASMalwS.961C70
KingsoftWin32.Hack.Bifrose.fz.(kcloud)
MicrosoftBackdoor:Win32/Bifrose.gen!C
GDataTrojan.Injector.AG
McAfeeGeneric Dropper.dy
MAXmalware (ai score=100)
VBA32Trojan.Win32.Buzus.cw
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_DELF.SMS
RisingTrojan.Generic@ML.100 (RDML:z4KbBqkubMD5N61FPPKCBQ)
YandexBackdoor.Bifrose!bXNulMwGPYI
IkarusTrojan-Dropper.Win32.Sramler.a
MaxSecureTrojan.Malware.2019151.susgen
FortinetW32/Injector.fam!tr
AVGWin32:IRCBot-DGN [Trj]
Paloaltogeneric.ml

How to remove Backdoor:Win32/Bifrose!C?

Backdoor:Win32/Bifrose!C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment