Backdoor

Should I remove “Backdoor:Win32/Konus!rfn”?

Malware Removal

The Backdoor:Win32/Konus!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Konus!rfn virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Starts servers listening on 127.0.0.1:32767, 127.0.0.1:32768
  • The binary likely contains encrypted or compressed data.
  • Queries information on disks, possibly for anti-virtualization
  • Executed a process and injected code into it, probably while unpacking
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent file extensions from being displayed
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

Related domains:

z.whorecord.xyz
a.tomx.xyz
updateserver2.top

How to determine Backdoor:Win32/Konus!rfn?


File Info:

crc32: B3C8EF28
md5: bc6244c6adddc594e3fd61d69003f047
name: BC6244C6ADDDC594E3FD61D69003F047.mlw
sha1: 9238b1fc8cb81b62e771a2a5b62a6e488187c069
sha256: de53755146bf38db456dc62fd0b64d3ea74363ceba4f3f90fb22c330d3091fff
sha512: 4a58cc605fe37c38e7bb0ebb69627b094923728be7e580a18e98e4a08ac3372be1a45c05bbb72f54c2427d598ff284b65aed2606bc6837605b6101f4b17381b4
ssdeep: 6144:62t++Meb3X89ar8SId3Zu9UA72lOnmvzmAxTnrdcM3mnRbKAtwAuem2:62tVbP63c9U+2lOnmvz7nr6OJNer
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: Sharecrop2
FileVersion: 1.06.0006
CompanyName: JetCaz
ProductName: Svc
ProductVersion: 1.06.0006
FileDescription: Hvine
OriginalFilename: Sharecrop2.exe

Backdoor:Win32/Konus!rfn also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.PonyStealer.wm0@cWtFIAli
FireEyeGeneric.mg.bc6244c6adddc594
McAfeeFareit-FFO!BC6244C6ADDD
CylanceUnsafe
ZillyaTrojan.Injector.Win32.581284
SangforMalware
K7AntiVirusTrojan ( 0056fb0f1 )
BitDefenderGen:Heur.PonyStealer.wm0@cWtFIAli
K7GWTrojan ( 0056fb0f1 )
CrowdStrikewin/malicious_confidence_90% (D)
BitDefenderThetaGen:NN.ZevbaF.34804.wm0@aWtFIAli
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.VBKryjetor.atin
NANO-AntivirusTrojan.Win32.VBKryjetor.evtumi
RisingMalware.Undefined!8.C (CLOUD)
Ad-AwareGen:Heur.PonyStealer.wm0@cWtFIAli
SophosMal/Generic-S
ComodoMalware@#2ggrvtvouhnhd
F-SecureHeuristic.HEUR/AGEN.1112829
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojanSpy.Win32.FAREIT.SMAL02.hp
McAfee-GW-EditionFareit-FFO!BC6244C6ADDD
EmsisoftGen:Heur.PonyStealer.wm0@cWtFIAli (B)
IkarusTrojan.Win32.Injector
AviraHEUR/AGEN.1112829
Antiy-AVLTrojan/Win32.SGeneric
MicrosoftBackdoor:Win32/Konus!rfn
ArcabitTrojan.PonyStealer.E8D88E
ZoneAlarmTrojan.Win32.VBKryjetor.atin
GDataGen:Heur.PonyStealer.wm0@cWtFIAli
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/VBKrypt.RP.X1764
VBA32Trojan.VBKryjetor
ALYacGen:Heur.PonyStealer.wm0@cWtFIAli
MAXmalware (ai score=97)
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Injector.DAMK
TrendMicro-HouseCallTrojanSpy.Win32.FAREIT.SMAL02.hp
TencentWin32.Trojan.Vbkryjetor.Phgc
YandexTrojan.GenAsa!1zQG0PwobEI
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetW32/Injector.DCVT!tr
AVGWin32:Malware-gen
AvastWin32:Malware-gen

How to remove Backdoor:Win32/Konus!rfn?

Backdoor:Win32/Konus!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment