Trojan

Trojan-Dropper.Win32.Agent.bjsdlc (file analysis)

Malware Removal

The Trojan-Dropper.Win32.Agent.bjsdlc is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Dropper.Win32.Agent.bjsdlc virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering
  • Anomalous binary characteristics

How to determine Trojan-Dropper.Win32.Agent.bjsdlc?


File Info:

name: DB283F5381CF52788D0A.mlw
path: /opt/CAPEv2/storage/binaries/7126080c9a7d463fcb48f8656e6e0c3a3f35754d679236bb15c076131ad339ed
crc32: 8910BF28
md5: db283f5381cf52788d0aea822fefa86d
sha1: 327802c411d8f342cedae7fd6fed0aedee9f1f2b
sha256: 7126080c9a7d463fcb48f8656e6e0c3a3f35754d679236bb15c076131ad339ed
sha512: e90a62a82646e69011fd2327216fb9a7ea7f34f7dbb7eea18537e96c4c1d4361b862a2e21018b7ffef4f1880d3d1b68d6c7d0f6af82d228c8fc38521765ad9af
ssdeep: 3072:xrVLMrTdJoFpFYR85c1EOUl/ldTxZKR2Gxu17LtU2+qj14ztXdvzw+P9TS6ztrOI:xhOUDk1q/lJxZOPxqLy2NazNdvzw+VTL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10D041294AE69DFD3D22A42B1D76C9B35FD787D3CE4E4584AB4DD2823AFB8C674001118
sha3_384: 22fb30f6c3330c2997a5e81e738975f442558536d543fd32c3d07eda33208cf9583fea4fecee34620c39d43abfdd2af1
ep_bytes: 60be00f044008dbe0020fbffc7878c27
timestamp: 1992-06-19 22:22:17

Version Info:

FileVersion: 1.0.0.0
ProductVersion: 1.0.0.0
Translation: 0x0409 0x04e4

Trojan-Dropper.Win32.Agent.bjsdlc also known as:

LionicTrojan.Win32.Agent.b!c
Elasticmalicious (high confidence)
FireEyeGeneric.mg.db283f5381cf5278
McAfeeArtemis!DB283F5381CF
CylanceUnsafe
ZillyaDropper.Agent.Win32.246543
SangforTrojan.Win32.Agent.bjsdlc
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.411d8f
BitDefenderThetaGen:NN.ZelphiCO.34212.lmKfa85H6obi
SymantecML.Attribute.HighConfidence
CynetMalicious (score: 100)
KasperskyTrojan-Dropper.Win32.Agent.bjsdlc
NANO-AntivirusTrojan.Win32.Agent.ekeics
ViRobotTrojan.Win32.Z.Agent.186368.EF
TencentWin32.Trojan-dropper.Agent.Wrgi
SophosGeneric ML PUA (PUA)
ComodoTrojWare.Win32.TrojanDownloader.banload.ek3@1b8yo8
VIPRETrojan.Win32.Generic!BT
JiangminTrojanDropper.Agent.cgil
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Zpevdo.B
VBA32BScope.Trojan.Wacatac
APEXMalicious
RisingDropper.Agent!8.2F (CLOUD)
YandexTrojan.GenAsa!NcBU67kgezM
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.99576182.susgen
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Trojan-Dropper.Win32.Agent.bjsdlc?

Trojan-Dropper.Win32.Agent.bjsdlc removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment