Malware

Python/Agent.BF information

Malware Removal

The Python/Agent.BF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Python/Agent.BF virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • CAPE detected the PyInstaller malware family
  • Anomalous binary characteristics

How to determine Python/Agent.BF?


File Info:

name: 9E100F2A4C919B2E6A06.mlw
path: /opt/CAPEv2/storage/binaries/616c6e4554317452aa8d6c74c7a99487f8d5eba0c4a3fe7c675423982b1593ef
crc32: 4339B5DF
md5: 9e100f2a4c919b2e6a0697558a6c0037
sha1: 83aa350dfa283d3f8076502d9ba5c1a8e290d1e9
sha256: 616c6e4554317452aa8d6c74c7a99487f8d5eba0c4a3fe7c675423982b1593ef
sha512: ffee75d8d3a57c8566fc3e694c056fd98c91f0caf3e06cf35a04c99781424e49391ef9aaef191d3339ff749e20bc8fc875acdfd52b98f23d750d320554e12317
ssdeep: 98304:/56HQcsibw8SPLeTtSQo5M8DERxrfExYzXYqzsJADToE:R6wcXMHLKy7txGYq4JADU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T107263377E0FDCCF8C52390F1A4FBF2BF9C92467D65A3442DE2692010F162295A28EE55
sha3_384: 3a535e51e8cfdf926883614fb4ebede8a25733c895f921c2a20d27f8e71f6721d67c1818aa5a3a81b9e87473c0fc9b43
ep_bytes: 83ec0cc70598d5410001000000e8be85
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Python/Agent.BF also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Heur.Veil.7
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
CrowdStrikewin/malicious_confidence_80% (D)
CyrenW32/S-4ca97ae3!Eldorado
SymantecHacktool.Veil
ESET-NOD32Python/Agent.BF
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Generic-6651517-0
KasperskyHEUR:Trojan.Win32.Pyme.d
BitDefenderGen:Heur.Veil.7
MicroWorld-eScanGen:Heur.Veil.7
Ad-AwareGen:Heur.Veil.7
SophosML/PE-A + ATK/Veil-AZ
McAfee-GW-EditionBehavesLike.Win32.TrojanVeil.rc
FireEyeGeneric.mg.9e100f2a4c919b2e
EmsisoftGen:Heur.Veil.7 (B)
GDataGen:Heur.Veil.7
AviraTR/Swrort.Gen7
ArcabitTrojan.Veil.7
MicrosoftBackdoor:Win32/Bladabindi!ml
McAfeeTrojan-Veil.gen.d
MAXmalware (ai score=83)
MalwarebytesMalware.AI.3011507796
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_91%
FortinetPython/Veil.7!tr
AVGWin32:Malware-gen
Cybereasonmalicious.a4c919
MaxSecureTrojan.Malware.121218.susgen

How to remove Python/Agent.BF?

Python/Agent.BF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment