Trojan

Trojan-Downloader.Win32.Bitser.cdt information

Malware Removal

The Trojan-Downloader.Win32.Bitser.cdt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Bitser.cdt virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Checks adapter addresses which can be used to detect virtual network interfaces
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location
  • Creates a hidden or system file
  • Appears to use command line obfuscation
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan-Downloader.Win32.Bitser.cdt?


File Info:

name: 188C206171F3F588952C.mlw
path: /opt/CAPEv2/storage/binaries/ffd1b1dff068576976136a9ee8b37071051ed3d421ee1ea3296a8f81a3512a42
crc32: 4546D7A3
md5: 188c206171f3f588952c8f1bc5dfd22f
sha1: 1e2ca3d13da6c7a0ab8ce8f583bb74e4955392aa
sha256: ffd1b1dff068576976136a9ee8b37071051ed3d421ee1ea3296a8f81a3512a42
sha512: dedb9aaa72be5378c1e80e5de9ee728f0a7be2b5a61ea91c96636300b54c2d59baf1f2dc69deab56c160aaa32b68f4d205e55ed57486510ec8136122116810ee
ssdeep: 6144:BZABbWqsE/Ao+mv8Qv0LVmwq4FU0fNoy67gBZoohw3PpgoQ3J:fANwRo+mv8QD4+0V167g7eRmZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A764BF35B382817AD0620935884BD376F53AFA045B7D68CFB3DD1E2C8D2335A1A653DA
sha3_384: bf97daa06c1deac3b097927aa989bde5fcedc3972895f5e702a2ef7af564de2f5001e34bb84bc310442c92331715909d
ep_bytes: 558bec83c4f0b888534200e824f2fdff
timestamp: 1992-06-19 22:22:17

Version Info:

Comments:
CompanyName: Defender Killer
FileDescription: Defender Killer 0001 Installation
FileVersion: 0001
LegalCopyright: Defender Killer
Translation: 0x0409 0x04e4

Trojan-Downloader.Win32.Bitser.cdt also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.188c206171f3f588
McAfeeArtemis!188C206171F3
CylanceUnsafe
VIPRETrojan.GenericKD.47308777
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDownloader:Win32/Bitser.bf4c1bf1
K7GWTrojan ( 0051918e1 )
K7AntiVirusTrojan ( 0051918e1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.KWUDAOB
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Downloader.Win32.Bitser.cdt
BitDefenderTrojan.GenericKD.47308777
MicroWorld-eScanTrojan.GenericKD.47308777
Ad-AwareTrojan.GenericKD.47308777
EmsisoftTrojan.GenericKD.47308777 (B)
DrWebTrojan.Siggen15.36347
McAfee-GW-EditionBehavesLike.Win32.Dropper.fc
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
IkarusTrojan.SuspectCRC
GDataTrojan.GenericKD.47308777
AviraTR/Dldr.Bitser.nsanv
Antiy-AVLTrojan/Generic.ASMalwS.524B
ArcabitTrojan.Generic.D2D1DFE9
ZoneAlarmTrojan-Downloader.Win32.Bitser.cdt
MicrosoftTrojan:Win32/Wacatac.B!ml
VBA32TrojanDownloader.Bitser
ALYacTrojan.GenericKD.47308777
MAXmalware (ai score=88)
YandexTrojan.DL.Bitser!862NAoblUU4
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan-Ransom.Win32.Crypmod.zfq
FortinetPossibleThreat.MU
AVGFileRepMalware [Trj]
AvastFileRepMalware [Trj]

How to remove Trojan-Downloader.Win32.Bitser.cdt?

Trojan-Downloader.Win32.Bitser.cdt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment