Malware

Binder.1 (file analysis)

Malware Removal

The Binder.1 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What Binder.1 virus can do?

  • Executable code extraction
  • Possible date expiration check, exits too soon after checking local time
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Binder.1?


File Info:

crc32: A2338FDC
md5: 2139739d1788893d1b0a10a708c2022a
name: cadet.jpg
sha1: d38e9afc7a08751c2492cc9412672ccbd2538d3b
sha256: 2f2d43ee943c5a3fe5e2159d0ea585709d7a538ad77014e01a75c34dc2b4f31a
sha512: d06651791396006c69b0703e9cfc7718e536dd111d877a43f145981543e74639da45a33fe5c469c3462f88f9eb3878828ec9a630c29f41c5d1dd99ed8f94fb31
ssdeep: 12288:E4kda1VQObbNymOJfmBeE5KIrIo+/mv8sy1dOnKAbGB92PnvWZ:Eddg3NDOgeHi7YmJXFsoPvWZ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Binder.1 also known as:

BkavW32.GenericBinderLnr.Trojan
MicroWorld-eScanGen:Variant.Binder.1
FireEyeGeneric.mg.2139739d1788893d
CAT-QuickHealVirTool.Vbinder.CO5
ALYacGen:Variant.Binder.1
MalwarebytesHackTool.Binder
SUPERAntiSpywareTrojan.Agent/Gen-Binder
K7AntiVirusTrojan ( 004babd11 )
AlibabaBackdoor:Win32/Binder.cb9637ee
K7GWTrojan ( 004babd11 )
Cybereasonmalicious.d17888
ArcabitTrojan.Binder.1
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaF.32250.0uW@a4bP8cnG
CyrenW32/Backdoor.FVDJ-1096
SymantecSMG.Heur!gen
TotalDefenseWin32/Tnega.AGBZ
BaiduWin32.Trojan-Dropper.Binder.m
APEXMalicious
ClamAVWin.Trojan.Binder-6
KasperskyHackTool.Win32.Binder.bs
BitDefenderGen:Variant.Binder.1
ViRobotTrojan.Win32.A.Swisyn.49120
Ad-AwareGen:Variant.Binder.1
EmsisoftGen:Variant.Binder.1 (B)
ComodoTrojWare.Win32.TrojanDropper.Binder.cls@4m6ovz
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.MulDrop2.39589
VIPRETrojan-Dropper.Win32.Binder.bs (v)
TrendMicroTROJ_BINDER_FC1700C9.UVPA
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
Trapminemalicious.high.ml.score
CMCHackTool.Win32.Binder!O
SophosMal/Generic-S
SentinelOneDFI – Malicious PE
F-ProtW32/Backdoor2.HKXU
JiangminHackTool.Binder.bh
AviraTR/Dropper.Gen
MAXmalware (ai score=82)
Antiy-AVLTrojan[PSW]/MSIL.Agensla
MicrosoftBackdoor:MSIL/Remcos!MTB
Endgamemalicious (high confidence)
AegisLabHacktool.Win32.Binder.lo77
ZoneAlarmHackTool.Win32.Binder.bs
GDataWin32.Trojan.Binder.A
AhnLab-V3HackTool/Win32.Vbinder.R12127
Acronissuspicious
McAfeeTrojan-FDDZ!2139739D1788
VBA32Binder.Celesty
CylanceUnsafe
ESET-NOD32Win32/TrojanDropper.Binder.NBH
TrendMicro-HouseCallTROJ_BINDER_FC1700C9.UVPA
RisingDropper.Binder!1.AEB1 (CLASSIC)
YandexHackTool.Binder!IMtdREcP3/k
IkarusTrojan.Win32.Dorv
FortinetW32/Dropper.NBH!tr
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.Hacktool.4af

How to remove Binder.1?

Binder.1 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment