Trojan

BScope.TrojanPSW.Tepfer (file analysis)

Malware Removal

The BScope.TrojanPSW.Tepfer is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.TrojanPSW.Tepfer virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Russian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Detects Bochs through the presence of a registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempted to write directly to a physical drive
  • Accessed credential storage registry keys
  • Collects information to fingerprint the system

How to determine BScope.TrojanPSW.Tepfer?


File Info:

name: 54DDE2CEEDE545C497BA.mlw
path: /opt/CAPEv2/storage/binaries/8f9d03aae1dea204c3b7cadf9ce92992fbc795585c714057fc1244ca68db7884
crc32: 8FEA09EC
md5: 54dde2ceede545c497ba274c20399c6d
sha1: ff6c260b827824ab6d368d12325bb6d6a8633a58
sha256: 8f9d03aae1dea204c3b7cadf9ce92992fbc795585c714057fc1244ca68db7884
sha512: 00f533cbf7948e2c0f65743d494f3876e98b719236591ac4643f97a48c2d37994bb88bb5e705514f48f5b3f31188a23e21d480ccf3a940954d863d258285816d
ssdeep: 49152:1lK++S48TG1GzsWaV3qC1kmWlJnQzlwy+PeUa2nixPkx4ANw4J6Let6jp8//Hqo3:1MLJOsNwC277nZJbxPwp8/Px3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1840633227664D53BDEC3B5BCC81DD63B692EE232A9B4D5F2B116A21D1CC7205325B388
sha3_384: eba20460630dc118ac3d8784fa6681ee75cb668e10cf70691b1f4bef9b24fa955a26d5b5fd629c1203ce107d2ab75306
ep_bytes: e8f82a0000e978feffff8bff558bec81
timestamp: 2018-07-21 15:59:28

Version Info:

FileVersion: 28.0.1.46
InternalName2: binokebina.exe
Copyright: Xabitozefesaji. Pesamuhawumeb dayihariduca. Pobodiyayuta wicavakepiyepe femotofuv
Translation: 0x0419 0x0548

BScope.TrojanPSW.Tepfer also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.BrsecmonE.1
FireEyeGeneric.mg.54dde2ceede545c4
McAfeePacked-FZV!54DDE2CEEDE5
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.1866658
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaBackdoor:Win32/Tofsee.aa331a43
K7GWTrojan ( 0055b7281 )
K7AntiVirusTrojan ( 003c36381 )
CyrenW32/Agent.BIQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GYSB
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.CobaltStrike-7458605-0
KasperskyHEUR:Backdoor.Win32.Tofsee.pef
BitDefenderTrojan.BrsecmonE.1
NANO-AntivirusTrojan.Win32.Bandit.ghtdwm
AvastWin32:CoinminerX-gen [Trj]
TencentWin32.Trojan-downloader.Bandit.Sxez
Ad-AwareTrojan.BrsecmonE.1
EmsisoftTrojan.Crypt (A)
ComodoTrojWare.Win32.Azorult.ZH@8ru48s
DrWebTrojan.Packed2.42165
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
SophosMal/Generic-S + Mal/GandCrab-G
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Tofsee.bdf
WebrootW32.Trojan.Gen
AviraTR/AD.GoCloudnet.fqqt
Antiy-AVLTrojan/Generic.ASMalwS.2CFD6F0
MicrosoftTrojan:Win32/Predator.PVD!MTB
GDataTrojan.BrsecmonE.1
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C3565558
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34294.TB0@aOoBGMc
ALYacTrojan.BrsecmonE.1
MAXmalware (ai score=88)
VBA32BScope.TrojanPSW.Tepfer
MalwarebytesTrojan.MalPack.GS
RisingTrojan.Generic@ML.100 (RDML:V+B6zto79n2MS++Iq46NQg)
IkarusTrojan.Win32.GandCrypt
MaxSecureTrojan.Malware.74695256.susgen
FortinetW32/Kryptik.GWZX!tr
AVGWin32:CoinminerX-gen [Trj]
Cybereasonmalicious.eede54
PandaTrj/GdSda.A

How to remove BScope.TrojanPSW.Tepfer?

BScope.TrojanPSW.Tepfer removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment