Backdoor

Backdoor:Win32/Bifrose!pz (file analysis)

Malware Removal

The Backdoor:Win32/Bifrose!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Bifrose!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the embedded win api malware family
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Backdoor:Win32/Bifrose!pz?


File Info:

name: 662F1C9A213619B17A38.mlw
path: /opt/CAPEv2/storage/binaries/51038523710774a5424acd475f8c0ac1e41bebd04a61034f598723b45bbf5287
crc32: E0A7CC98
md5: 662f1c9a213619b17a38f31a24259dc7
sha1: 63fc28f4b0e5fac536ab79db41ed81627fa21398
sha256: 51038523710774a5424acd475f8c0ac1e41bebd04a61034f598723b45bbf5287
sha512: 952725334687c199d4ea284633dd8ab436568c7adf1a51186b5ecafb9f3c87470928ac52d6ea5e67e1bc61264b6114e9b93634c60e37e47a23bce8b92677f0ca
ssdeep: 768:ZLh7TzTBziifTeiZSVWihwEEnh0L7OTLeNfQffJP:ZZ/nEEh8OTKNOP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T135E2D08552DA58C1E1A2FF7C4CED0BE9A19889329EA6130F93BE80FD5F5064624AD4CD
sha3_384: 06c2d4c7d27726bbb69ba35ce1296a590155a5130659c833c636bf51142f2902619bea10e8e8acd3ec992bff3f7b700f
ep_bytes: 558bec83ec4456ff15181040008bf08a
timestamp: 2007-12-28 14:11:35

Version Info:

0: [No Data]

Backdoor:Win32/Bifrose!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Dropper.SAG
ClamAVWin.Trojan.Bifrose-28231
FireEyeGeneric.mg.662f1c9a213619b1
CAT-QuickHealBackdoor.Bifrose.AE
SkyhighBehavesLike.Win32.Sality.nc
ALYacTrojan.Dropper.SAG
Cylanceunsafe
ZillyaVirus.Bitforse.Win32.1
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/Bifrose.6e1da63e
K7GWTrojan ( 004bff5e1 )
K7AntiVirusBackdoor ( 0040f49a1 )
BitDefenderThetaAI:Packer.3F768CFC1E
VirITTrojan.Win32.Agent.BILX
SymantecBackdoor.Bifrose
ESET-NOD32Win32/Bifrose.NEE
ZonerTrojan.Win32.36495
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Bifrose.fxv
BitDefenderTrojan.Dropper.SAG
NANO-AntivirusTrojan.Win32.Bifrose.enscfe
SUPERAntiSpywareTrojan.Agent/Gen-FraudPack
AvastWin32:BackDoor-ZR [Trj]
TencentTrojan.Win32.Refroso.dejg
TACHYONTrojan/W32.Midgare.32637
EmsisoftTrojan.Dropper.SAG (B)
BaiduWin32.Backdoor.Bifrose.a
F-SecureBackdoor:W32/Bifrose.gen!E
DrWebTrojan.Inject.5077
VIPRETrojan.Dropper.SAG
TrendMicroBKDR_BIFROSE.SMA
Trapminemalicious.high.ml.score
SophosMal/Bifrose-X
IkarusBackdoor.Win32.Prorat
GDataTrojan.Dropper.SAG
JiangminBackdoor/Bifrose.fzf
WebrootW32.Bifrose.Gen
GoogleDetected
AviraBDS/Bifrose.aec
Antiy-AVLTrojan[Backdoor]/Win32.Bifrose.fxv
KingsoftWin32.Hack.Bifrose.fxv
XcitiumBackdoor.Win32.Bifrost.~Q@7opw
ArcabitTrojan.Dropper.SAG
ViRobotBackdoor.Win32.A.Bifrose.32637.KZ
ZoneAlarmBackdoor.Win32.Bifrose.fxv
MicrosoftBackdoor:Win32/Bifrose!pz
VaristW32/Trojan2.BTDY
AhnLab-V3Backdoor/Win32.Bifrose.R2880
Acronissuspicious
McAfeeBackDoor-CEP.gen.g
MAXmalware (ai score=100)
VBA32SScope.Trojan.Buzus.ak
MalwarebytesGeneric.Malware.AI.DDS
PandaBck/Bifrose.BFX
TrendMicro-HouseCallBKDR_BIFROSE.SMA
RisingTrojan.Win32.Midgare.hhn (CLASSIC)
YandexTrojan.GenAsa!4E42FGF2k2Y
SentinelOneStatic AI – Malicious PE
MaxSecureBackdoor.W32.Refroso.djjg
FortinetW32/Bifrose.ZXE!tr
AVGWin32:BackDoor-ZR [Trj]
Cybereasonmalicious.4b0e5f
DeepInstinctMALICIOUS

How to remove Backdoor:Win32/Bifrose!pz?

Backdoor:Win32/Bifrose!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment