Trojan

Trojan-Downloader.Win32.Bitser.ejn (file analysis)

Malware Removal

The Trojan-Downloader.Win32.Bitser.ejn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Bitser.ejn virus can do?

  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Deletes executed files from disk
  • Attempts to modify Windows Defender using PowerShell
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan-Downloader.Win32.Bitser.ejn?


File Info:

name: BD5A3AEDB05B9C65F537.mlw
path: /opt/CAPEv2/storage/binaries/471cc9214505430333a7a455983b7ba495232a29daff71e136cf2db121af4e80
crc32: BD0D92EC
md5: bd5a3aedb05b9c65f537bb330707af90
sha1: 51d8ea5c8603ef9ae3a1feb0a476579109fc45df
sha256: 471cc9214505430333a7a455983b7ba495232a29daff71e136cf2db121af4e80
sha512: 6d0e4fe8385a6db42ead36bad54f61c79d4fceee7adac5266d721cd51f49da9c2e313dec64f95342f9db2af7f9e4e412de6803bd4dd2fd2e773ff17abb9b92e8
ssdeep: 1536:77fbN3eEDhDPA/pICdUkbBtW7upvaLU0bI5taxKo0IOlnToIfcw8:X7DhdC6kzWypvaQ0FxyNTBfcd
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1CC937D41F3E202F7E6F2053100A6726F973662389764E8DBC74C2E529913AD5A63D3F9
sha3_384: 335c89715bcb68766a6f4e796bc47c3f2bd29356d70a80f26febec4cdd75035a481ffb745cfda0e27e879068befca192
ep_bytes: 68ac00000068000000006868804100e8
timestamp: 2019-07-30 08:52:45

Version Info:

0: [No Data]

Trojan-Downloader.Win32.Bitser.ejn also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Encoder.trrL
CAT-QuickHealTrojan.GenericPMF.S17672155
McAfeeArtemis!BD5A3AEDB05B
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 00584baa1 )
AlibabaTrojanDownloader:Win32/Bitser.81b2b6f8
K7GWRiskware ( 00584baa1 )
Cybereasonmalicious.db05b9
CyrenW32/Kryptik.AYO.gen!Eldorado
Elasticmalicious (high confidence)
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan-Downloader.Win32.Bitser.ejn
TencentWin32.Trojan-Downloader.Bitser.Bnhl
McAfee-GW-EditionBehavesLike.Win32.Generic.mh
FireEyeGeneric.mg.bd5a3aedb05b9c65
SophosGeneric PUA FB (PUA)
SentinelOneStatic AI – Malicious PE
AviraTR/Dldr.Bitser.jtxiz
Antiy-AVLTrojan/Generic.ASMalwS.5174
MicrosoftProgram:Win32/Wacapew.C!ml
GDataWin32.Trojan.PSE.YXY4X0
GoogleDetected
AhnLab-V3Trojan/Win.Generic.C5216474
TACHYONRansom/W32.Encoder.91648
MalwarebytesTrojan.PowerShell
TrendMicro-HouseCallTROJ_GEN.R002H0CGU22
RisingTrojan.Generic@AI.99 (RDML:PAoduq02AIYCY4BbhHOcDQ)
IkarusTrojan.Win32.Occamy
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.AYO!tr
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan-Downloader.Win32.Bitser.ejn?

Trojan-Downloader.Win32.Bitser.ejn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment