Malware

Barys.63210 (B) information

Malware Removal

The Barys.63210 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Barys.63210 (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • NtSetInformationThread: attempt to hide thread from debugger
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Starts servers listening on 127.0.0.1:0
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • A possible heap spray exploit has been detected
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering

Related domains:

example.org
ipv4only.arpa
detectportal.firefox.com
aus5.mozilla.org
zhibo.baidu581.com
content-signature-2.cdn.mozilla.net
firefox.settings.services.mozilla.com

How to determine Barys.63210 (B)?


File Info:

name: BD6CFE374486069B7672.mlw
path: /opt/CAPEv2/storage/binaries/7bed4f04f5971e085b950d2f0a739d331e06cdbf1473dd70b421e442a8c075de
crc32: EF8BBCB4
md5: bd6cfe374486069b7672da79fb766598
sha1: 24f1401ad2e130c03efce3a748e39113eef0de82
sha256: 7bed4f04f5971e085b950d2f0a739d331e06cdbf1473dd70b421e442a8c075de
sha512: 6da059c5ba7e30bb44161e13805e24ff1e6d1b65e5d2f444398fa2a4279f3eaee80f90bc11cf5baac0933f9071d2b544b71133f68c847e6201ae5c26269f2ae9
ssdeep: 768:cybq3GQ/WwC5SgumkgNz/4c5CE9duegHXwaebjBUvoMN45tsA8Rer/FkvW:bbq3GQkvR/Z/4cNuQZbCWERerN2W
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C5635A43F5E1C475F071ABB9AC24A5E4F67B3D713E28416823A85B8F4D262920C5E36A
sha3_384: 6af16ea2797a56f997d39c748058dc97f95e86f471933d40623945018d3290f1bf6a0eeac4f43d5eb6b08d13714d284a
ep_bytes: 558bec83c4f0b8549b4000e8a8aeffff
timestamp: 2011-02-25 05:35:47

Version Info:

0: [No Data]

Barys.63210 (B) also known as:

BkavW32.AIDetect.malware1
MicroWorld-eScanGen:Variant.Barys.63210
FireEyeGeneric.mg.bd6cfe374486069b
McAfeeGenericRXQQ-BK!BD6CFE374486
CylanceUnsafe
K7AntiVirusTrojan ( 005669031 )
K7GWTrojan ( 005669031 )
Cybereasonmalicious.744860
CyrenW32/Delf.QA.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
ClamAVWin.Malware.Delf-9773061-0
KasperskyHEUR:Trojan-Downloader.Win32.Agent.gen
BitDefenderGen:Variant.Barys.63210
AvastWin32:Evo-gen [Susp]
Ad-AwareGen:Variant.Barys.63210
SophosMal/Generic-S
ComodoTrojWare.Win32.Delf.DSAW@8qf1aa
ZillyaDownloader.Agent.Win32.454684
TrendMicroTROJ_GEN.R03BC0PKP21
McAfee-GW-EditionBehavesLike.Win32.HLLP.lm
EmsisoftGen:Variant.Barys.63210 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Barys.63210
JiangminTrojanDownloader.Agent.gaur
AviraTR/Patched.Ren.Gen
Antiy-AVLTrojan/Generic.ASMalwS.804DF
ArcabitTrojan.Barys.DF6EA
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R265776
Acronissuspicious
BitDefenderThetaAI:Packer.268AD2F919
ALYacGen:Variant.Barys.63210
MAXmalware (ai score=85)
VBA32TScope.Trojan.Delf
MalwarebytesMalware.AI.4237221986
TrendMicro-HouseCallTROJ_GEN.R03BC0PKP21
RisingTrojan.Delf!1.BA15 (CLASSIC)
IkarusWorm.Win32.Gamarue
FortinetW32/Delf.IARS!tr
AVGWin32:Evo-gen [Susp]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Barys.63210 (B)?

Barys.63210 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment