Spy Trojan

Trojan-Spy.Win32.Keylogger.bfic (file analysis)

Malware Removal

The Trojan-Spy.Win32.Keylogger.bfic is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Keylogger.bfic virus can do?

  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Turkish
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

smtp.gmail.com
wpad.local-net

How to determine Trojan-Spy.Win32.Keylogger.bfic?


File Info:

name: D8DAD6D200B8ADB8EFBD.mlw
path: /opt/CAPEv2/storage/binaries/d6d2413f342a552641a8841dedcf1fdee46ccbcd18978619007c55b5c5d6e65a
crc32: 248F139A
md5: d8dad6d200b8adb8efbd29c6c8cd8158
sha1: f862fb8273bbb0374ddb45853a311f33209365ff
sha256: d6d2413f342a552641a8841dedcf1fdee46ccbcd18978619007c55b5c5d6e65a
sha512: bd2d1137a48ac1091921ac6cdc58d8cace3932303c2d3a7080fd40e06eed6dcea57c79ad299a977eca05a4b3016ccc52e93e249228945a0a3921ac07c8937538
ssdeep: 12288:FBYGrmSl2x//g86LxxSRUeSXH1KuA4W18wj0Fj:XBr72xXk1KUZFKR4W18C0l
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T188D44B62F2E0493FF1A6963D9D6792545839BD003E34F9C62BE83D4C4F3B643246629B
sha3_384: 46672b68441073224bcb9ac7a5dd648fa3dde7d84c20adf0484dcfc156c302f5493a13541aa95565e4a5870a704f6e83
ep_bytes: 558bec83c4f0b820394700e8fc21f9ff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Trojan-Spy.Win32.Keylogger.bfic also known as:

LionicTrojan.Multi.Generic.4!c
McAfeeArtemis!D8DAD6D200B8
CylanceUnsafe
SangforSpyware.Win32.Keylogger.bfic
AlibabaTrojanSpy:Win32/Keylogger.9732831d
Cybereasonmalicious.273bbb
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Spy.Win32.Keylogger.bfic
NANO-AntivirusTrojan.Win32.Keylogger.exqcbc
TencentWin32.Trojan-spy.Keylogger.Wuhe
ComodoMalware@#2hof6pr5g5xp8
McAfee-GW-EditionBehavesLike.Win32.Worm.jh
FireEyeGeneric.mg.d8dad6d200b8adb8
IkarusTrojan.Win32.Regrun
WebrootW32.Keylogger.bfic
Antiy-AVLTrojan/Generic.ASMalwS.F9C782
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
VBA32BScope.TrojanSpy.Skeeyah
TrendMicro-HouseCallTROJ_GEN.R002H07IN21
RisingTrojan.Generic@ML.86 (RDMK:aMuBaM4dGgF30VTSuOdgng)
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_97%
FortinetW32/PossibleThreat
BitDefenderThetaGen:NN.ZelphiF.34294.MGW@a4kDGShG
PandaTrj/GdSda.A
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan-Spy.Win32.Keylogger.bfic?

Trojan-Spy.Win32.Keylogger.bfic removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment