Trojan

Trojan.Agent.BLFP malicious file

Malware Removal

The Trojan.Agent.BLFP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.BLFP virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Attempts to connect to a dead IP:Port (5 unique times)
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)

How to determine Trojan.Agent.BLFP?


File Info:

name: D07899700B7A5212A7F3.mlw
path: /opt/CAPEv2/storage/binaries/13be7212cc27f7d5e368fd8b2dfacf62814203dd5834281d0b4faa46873dbdb9
crc32: 5847DC27
md5: d07899700b7a5212a7f3965cb30fd39b
sha1: 0c9bf5575b6ccd283a57c778dc892b6c28222c1a
sha256: 13be7212cc27f7d5e368fd8b2dfacf62814203dd5834281d0b4faa46873dbdb9
sha512: 35bef3da1466040f6e7a5a6d974800b41c7c56208b0ca84daeb0ab7a250b476975b662c02b5d3c59b7eb015e0b970ffe92d4d3cfbf1dd277f918ce73c705a6af
ssdeep: 1536:LUHuEhVlU0ZwrUtYCeFFalShprm6NGSfDiBtL6:LUHuEhXHZwrwHKFalYr96BJ6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11D63D0EA0D540617C18987340AABDBB623F19C70AB17C98F367ACD8D9D366DC582B50F
sha3_384: 6ba648089dc0c56ed228a470d488ec2acdf2cb667d2abd35cc3169c157babf6f42bff5c0a2f10ec79cdeb6533d029696
ep_bytes: 558bec6aff68d026400068a21d400064
timestamp: 2015-07-07 18:27:33

Version Info:

0: [No Data]

Trojan.Agent.BLFP also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Agent.mC6T
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.BLFP
FireEyeGeneric.mg.d07899700b7a5212
CAT-QuickHealTrojanPWS.Zbot.A4
McAfeePacked-FB!D07899700B7A
CylanceUnsafe
ZillyaTrojan.Agent.Win32.565631
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004c7e1e1 )
AlibabaTrojan:Win32/CeeInject.007a151f
K7GWTrojan ( 004c7e1e1 )
Cybereasonmalicious.00b7a5
VirITTrojan.Win32.Inject2.CNOA
SymantecTrojan.Gen
ESET-NOD32a variant of Win32/Injector.CFGO
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Blkx-6951312-0
KasperskyTrojan.Win32.Agent.ifuv
BitDefenderTrojan.Agent.BLFP
NANO-AntivirusTrojan.Win32.Encoder.dueolv
SUPERAntiSpywareTrojan.Agent/Gen-Malagent
AvastSf:Agent-BA [Trj]
TencentMalware.Win32.Gencirc.10c79f00
Ad-AwareTrojan.Agent.BLFP
SophosMal/Generic-R + Mal/Zbot-UE
ComodoTrojWare.Win32.VirTool.CeeInject.KGR@5t0fp3
DrWebTrojan.Encoder.1344
VIPREWin32.Malware!Drop
TrendMicroBKDR_KELIHOS.SMNA
McAfee-GW-EditionPacked-FB!D07899700B7A
EmsisoftTrojan.Agent.BLFP (B)
GDataTrojan.Agent.BLFP
JiangminTrojan/Agent.ijuv
WebrootW32.Injector.Gen
AviraTR/Inject.sbbeinv
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASBOL.253A
MicrosoftVirTool:Win32/CeeInject.GK
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.CTBLocker.R158760
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34212.eqZ@ae!j!ln
ALYacTrojan.Agent.BLFP
TACHYONTrojan/W32.Agent.70330.F
VBA32OScope.Malware-Cryptor.Hlux
MalwarebytesMalware.AI.798183777
TrendMicro-HouseCallBKDR_KELIHOS.SMNA
RisingTrojan.Injector!8.C4 (CLOUD)
SentinelOneStatic AI – Malicious PE
FortinetW32/Injector.CFFW!tr
AVGSf:Agent-BA [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Agent.BLFP?

Trojan.Agent.BLFP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment