Trojan

Trojan-Downloader.Win32.Bitser.cst malicious file

Malware Removal

The Trojan-Downloader.Win32.Bitser.cst is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Bitser.cst virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Creates a hidden or system file

How to determine Trojan-Downloader.Win32.Bitser.cst?


File Info:

name: 92963FC989E80A074EA9.mlw
path: /opt/CAPEv2/storage/binaries/09718328ef7afcd7ce764d2b3878a8237a13c347c2c5e4de320b165b9b8c1248
crc32: A5583ED2
md5: 92963fc989e80a074ea909af8c758ea5
sha1: c7761f29a3f42128ed3e1523ca84e194036621ce
sha256: 09718328ef7afcd7ce764d2b3878a8237a13c347c2c5e4de320b165b9b8c1248
sha512: 62edfa3a1f97afd37fd3a2993861c3e6f56d49105295bbb7eed35fa084cb044650d94c982fe568313d1497e320c99d667eb20cf3d7f36ff1eaf13141c23347d3
ssdeep: 24576:vevufIGzcvIsSL85c6qwJkI1tqzwPU+OuwL/:vevuXmRSL8Fz18zA+1/
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1B8754911B7909129F8F302FB59FE20AC942CFAE0076C90C752C56AEE9669BF17D31653
sha3_384: 9aebf94163abceb1254c24c207e72d8b9e6a0bd729581b6f02d246d880887fdce5301faa8eabd0adfb17e80cf24a1129
ep_bytes: e94b070400e9269a0200e9f1db0a00e9
timestamp: 2021-12-08 02:20:56

Version Info:

0: [No Data]

Trojan-Downloader.Win32.Bitser.cst also known as:

LionicTrojan.Win32.Bitser.a!c
MicroWorld-eScanTrojan.GenericKD.38242563
FireEyeTrojan.GenericKD.38242563
ALYacTrojan.GenericKD.38242563
CylanceUnsafe
ZillyaDownloader.Bitser.Win32.3377
AlibabaTrojanDownloader:Win32/Bitser.80a3e53e
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyTrojan-Downloader.Win32.Bitser.cst
BitDefenderTrojan.GenericKD.38242563
AvastWin32:DropperX-gen [Drp]
TencentWin32.Trojan-downloader.Bitser.Hssc
Ad-AwareTrojan.GenericKD.38242563
SophosMal/Generic-S
TrendMicroTROJ_GEN.R002C0WLD21
McAfee-GW-EditionBehavesLike.Win32.Generic.tm
EmsisoftTrojan.GenericKD.38242563 (B)
GDataTrojan.GenericKD.38242563
JiangminTrojanDownloader.Bitser.aj
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Generic.D2478903
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.FU.R458568
McAfeeGenericRXRC-FU!92963FC989E8
MAXmalware (ai score=82)
VBA32TrojanDownloader.Bitser
TrendMicro-HouseCallTROJ_GEN.R002C0WLD21
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
AVGWin32:DropperX-gen [Drp]
PandaTrj/GdSda.A

How to remove Trojan-Downloader.Win32.Bitser.cst?

Trojan-Downloader.Win32.Bitser.cst removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment