Backdoor

BScope.Backdoor.DeathBot (file analysis)

Malware Removal

The BScope.Backdoor.DeathBot is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.Backdoor.DeathBot virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine BScope.Backdoor.DeathBot?


File Info:

name: DA36256590FC7AABCEDC.mlw
path: /opt/CAPEv2/storage/binaries/f444b3382ef3f5f6715656b9538ee03a4aa384b9b7fdfc97d66dd228b96f4e54
crc32: 720DC233
md5: da36256590fc7aabcedc5a9fa0e3813e
sha1: 43d71451baeb101ea536f6b62113eda2fa8afb48
sha256: f444b3382ef3f5f6715656b9538ee03a4aa384b9b7fdfc97d66dd228b96f4e54
sha512: 55e5c8613f8cd29ebb7be64232fb37c371846714a783e2b2e7d4d5b7bd1be81d28867189fa12b09341722c859ae65b68c5e42dd28a2faae67ebeed9427109781
ssdeep: 768:f125UgUz4q2b/j7WPtUYSnOQH+r7iyOM/+8stObqp:9/Ch7DvOQw7nO6HstOWp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BAD2E145F1CA5583E8AE11B11AA79F23ECCA24004F1CCBD96C31475E7CE6385FED4960
sha3_384: d531963e9829554b7a46507350bdd80d6d3bb39c3820214e6207c56d0e23e3073537909a56b0e003dcf7fda2b4295db0
ep_bytes: 60be009043008dbe0080fcff5783cdff
timestamp: 2012-05-07 15:09:23

Version Info:

Translation: 0x0804 0x04b0
Comments: QQ307677814
CompanyName: http://www.2345.com/?k282001
FileDescription: 测试版
ProductName: 抽奖系统
FileVersion: 1.00
ProductVersion: 1.00
InternalName: 测试版2.1
OriginalFilename: 测试版2.1.exe

BScope.Backdoor.DeathBot also known as:

BkavW32.Common.D6749079
LionicTrojan.Win32.Convagent.4!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.GenericKD.69448313
CAT-QuickHealTrojan.Riskware
SkyhighBehavesLike.Win32.IStartSurf.mc
McAfeeArtemis!DA36256590FC
MalwarebytesGeneric.Malware/Suspicious
VIPRETrojan.GenericKD.69448313
SangforTrojan.Win32.Agent.Vxdx
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.69448313
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.1baeb1
ArcabitTrojan.Generic.D423B279
APEXMalicious
RisingSpyware.Convagent!8.12330 (CLOUD)
SophosGeneric Reputation PUA (PUA)
Trapminemalicious.moderate.ml.score
FireEyeTrojan.GenericKD.69448313
EmsisoftTrojan.GenericKD.69448313 (B)
IkarusVirus.Win32.VB
MAXmalware (ai score=89)
GoogleDetected
Antiy-AVLTrojan[Spy]/Win32.Convagent
Kingsoftmalware.kb.b.839
GDataTrojan.GenericKD.69448313
ALYacTrojan.GenericKD.69448313
DeepInstinctMALICIOUS
VBA32BScope.Backdoor.DeathBot
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H09J123
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
CrowdStrikewin/malicious_confidence_70% (W)

How to remove BScope.Backdoor.DeathBot?

BScope.Backdoor.DeathBot removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment