Trojan

Trojan-Downloader.Win32.Deyma.bpg (file analysis)

Malware Removal

The Trojan-Downloader.Win32.Deyma.bpg is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Deyma.bpg virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • A process attempted to delay the analysis task by a long amount of time.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to identify installed AV products by installation directory
  • Creates a copy of itself
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

redirector.gvt1.com
r4—sn-4g5e6nl6.gvt1.com

How to determine Trojan-Downloader.Win32.Deyma.bpg?


File Info:

crc32: 13660E4F
md5: 8d7d5bed0902087b8222b7527941d3c4
name: upload_file
sha1: 055c9502a117ca422c30ec6a942cf66e59c3c8b8
sha256: d073c4bbec9e6ce9de4260a00a677e1f132c82e5b0e197d2abd2f82a599a09f6
sha512: 89ef3bc715866950dd1334e6f37648c24774cbc5324a002a1b1ec76854e9bdff27da01ec33453b6b224b3b2a6643a6b8c6143ff44b8cb6e7a7b8f87af3499bbc
ssdeep: 3072:jDwSN/f42zfEYOpnhenpYUvMevbT60Z15RLz5RLz5RLz5RLz5RLz5RLz5RLz5RL3:g8wwYEnZWwmXQJXY+
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2009-11, 2015 Dave Brotherstone
InternalName: gpup
FileVersion: 1.3.5.0
Comments: A generic(ish) plugin ipdater, built initially for Notepad++
ProductName: gpup
ProductVersion: 1.3.5.0
FileDescription: gpup
OriginalFilename: gpup.exe
Translation: 0x0809 0x04b0

Trojan-Downloader.Win32.Deyma.bpg also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKD.34268863
FireEyeGeneric.mg.8d7d5bed0902087b
Qihoo-360Win32/Trojan.Downloader.731
McAfeeGenericRXLO-MH!8D7D5BED0902
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 005652be1 )
BitDefenderTrojan.GenericKD.34268863
K7GWTrojan ( 005652be1 )
CrowdStrikewin/malicious_confidence_90% (W)
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaF.34152.1u1@aaNjepmi
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HFHM
APEXMalicious
AvastWin32:DangerousSig [Trj]
GDataTrojan.GenericKD.34268863
KasperskyTrojan-Downloader.Win32.Deyma.bpg
AlibabaTrojanDownloader:Win32/Deyma.4be54025
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.34268863 (B)
F-SecureTrojan.TR/Crypt.Agent.jjdmc
DrWebTrojan.PWS.Siggen2.51569
TrendMicroTROJ_GEN.R002C0RH320
SophosMal/EncPk-APV
IkarusTrojan.Win32.Crypt
AviraTR/Crypt.Agent.jjdmc
MAXmalware (ai score=88)
Antiy-AVLTrojan[PSW]/Win32.Racealer
MicrosoftTrojan:Win32/Ymacco.AAD0
ArcabitTrojan.Generic.D20AE6BF
ZoneAlarmTrojan-Downloader.Win32.Deyma.bpg
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.34268863
VBA32BScope.Trojan.Inject
MalwarebytesTrojan.MalPack
TrendMicro-HouseCallTROJ_GEN.R002C0RH320
RisingTrojan.Kryptik!1.C9B6 (CLASSIC)
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_95%
FortinetW32/GenKryptik.EOOB!tr
Ad-AwareTrojan.GenericKD.34268863
AVGWin32:DangerousSig [Trj]
Cybereasonmalicious.2a117c
PandaTrj/GdSda.A

How to remove Trojan-Downloader.Win32.Deyma.bpg?

Trojan-Downloader.Win32.Deyma.bpg removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment