Backdoor

BScope.Backdoor.Cybergate (file analysis)

Malware Removal

The BScope.Backdoor.Cybergate is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.Backdoor.Cybergate virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (inter-process)
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering
  • Anomalous binary characteristics
  • Binary compilation timestomping detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine BScope.Backdoor.Cybergate?


File Info:

name: 8D67B930570D827914BC.mlw
path: /opt/CAPEv2/storage/binaries/34eb4edd64c7204dc07682d79b955fc73e4c0ad64c0d2ee36009288197755c27
crc32: 3D9F4444
md5: 8d67b930570d827914bc08c273a3b9f5
sha1: f7c6ee9579ec9a1da77da3ed3202744d3ba7460f
sha256: 34eb4edd64c7204dc07682d79b955fc73e4c0ad64c0d2ee36009288197755c27
sha512: 59cc81e6ffb4368bd8e7e94b6794be581e7c20712c33339f2ac8859b5b23bf54e972970a90ddd6588fd30b551572cc743a541e8fb2a3a722fc7956d84ab916e4
ssdeep: 3072:FVl/aNwXzLLmS/R8p/+ZPb1R32lQjXhwq+XnvQCK9lvGHTHlllinAppeVn6:hieXzLLR/Wp/gb1R3yiXhwq+3vQr6W
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19D14230782DDD41AE0DA7E702717A732254E1EB84FD1A43D1DE311D5CDA0F8EA0AE4A7
sha3_384: 720cf917dcbb8377676cc72c628504c525c8479d8e43d82f68c68953edb9186049e68cef39751dbad43b90596900b753
ep_bytes: b854c54e005064ff3500000000648925
timestamp: 2027-02-02 05:49:39

Version Info:

Translation: 0x0409 0x04b0
Comments: Version history is in Help section
CompanyName: Soeperman Enterprises Ltd.
FileDescription: HijackThis
LegalCopyright: Freeware
LegalTrademarks: ©
ProductName: HijackThis
FileVersion: 1.99.0001
ProductVersion: 1.99.0001
InternalName: HijackThis
OriginalFilename: HijackThis.exe

BScope.Backdoor.Cybergate also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
FireEyeGeneric.mg.8d67b930570d8279
Cylanceunsafe
K7AntiVirusTrojan ( 004bcce41 )
K7GWTrojan ( 004bcce41 )
Elasticmalicious (high confidence)
APEXMalicious
CynetMalicious (score: 100)
McAfee-GW-EditionGeneric Packed.by
Trapminemalicious.moderate.ml.score
SophosGeneric Reputation PUA (PUA)
SentinelOneStatic AI – Suspicious PE
Antiy-AVLGrayWare/Win32.Presenoker
XcitiumMalware@#2o4dvnkdfcfcf
MicrosoftPUA:Win32/Presenoker
McAfeeArtemis!8D67B930570D
VBA32BScope.Backdoor.Cybergate
TrendMicro-HouseCallTROJ_GEN.R002H06E623
RisingPUA.Presenoker!8.F608 (CLOUD)
MaxSecureTrojan.Malware.300983.susgen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_70% (W)

How to remove BScope.Backdoor.Cybergate?

BScope.Backdoor.Cybergate removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment