Trojan

About “TrojanDropper:Win32/Delf.BL!MTB” infection

Malware Removal

The TrojanDropper:Win32/Delf.BL!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDropper:Win32/Delf.BL!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Loads a driver
  • Starts servers listening on 0.0.0.0:54620
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Attempts to modify Internet Explorer’s start page
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Likely virus infection of existing system binary
  • Creates a copy of itself
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
udo.jxwan.com
dld.jxwan.com
tj.jipinwan.com

How to determine TrojanDropper:Win32/Delf.BL!MTB?


File Info:

crc32: EBB84353
md5: b2be623ecce45dc62db64cd3829e05e4
name: client12766.exe
sha1: e840cb704e64990ff30bf3a5e3623399c9825e52
sha256: 29f9e91611aaa4f4336ab043aa0e57a4faa76010aee7046be88179847ca78ef1
sha512: c39a4fbf9deffb785993c0829119cba8b206a7163ffa00a5d9fb46d22d334498bd78ced506c0dbcac6c6877240b9e24b3c6a850ad30fc14b3748abd9fa9794d0
ssdeep: 49152:mDutMLThZl0EHgj1eLcSPkaKBuOixMtRsrP:YLVZy78kasRixYRo
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

TrojanDropper:Win32/Delf.BL!MTB also known as:

BkavHW32.Packed.
DrWebTrojan.DownLoader26.56346
MicroWorld-eScanGen:Variant.Symmi.87187
FireEyeGeneric.mg.b2be623ecce45dc6
McAfeeArtemis!B2BE623ECCE4
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 004f34121 )
BitDefenderGen:Variant.Symmi.87187
K7GWTrojan ( 004f34121 )
Cybereasonmalicious.ecce45
BitDefenderThetaGen:NN.ZexaF.34130.4PW@aSZuqjhb
F-ProtW32/S-d7209103!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
GDataGen:Variant.Symmi.87187
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Generic.84f9bb5a
NANO-AntivirusTrojan.Win32.Delf.fhcbja
AegisLabTrojan.Win32.Generic.4!c
RisingTrojan.Delf!8.67 (CLOUD)
Endgamemalicious (high confidence)
SophosMal/Generic-S
ComodoMalware@#32nadvmzui6iw
F-SecureHeuristic.HEUR/AGEN.1103189
ZillyaTrojan.Generic.Win32.454621
Invinceaheuristic
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Symmi.87187 (B)
IkarusTrojan.Win32.Regrun
CyrenW32/S-d7209103!Eldorado
JiangminTrojan.Generic.couxw
MaxSecureTrojan.Malware.7164915.susgen
AviraHEUR/AGEN.1103189
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.AGeneric
MicrosoftTrojanDropper:Win32/Delf.BL!MTB
ArcabitTrojan.Symmi.D15493
ZoneAlarmHEUR:Trojan.Win32.Generic
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R266755
Acronissuspicious
VBA32BScope.Trojan.Downloader
ALYacGen:Variant.Symmi.87187
Ad-AwareGen:Variant.Symmi.87187
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Delf.UEQ
TencentWin32.Trojan.Generic.Pfji
YandexTrojan.Agent!1hgwfa1v3FM
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_100%
FortinetW32/Delf.TJJ!tr
AVGFileRepMetagen [Malware]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Generic/HEUR/QVM16.0.0288.Malware.Gen

How to remove TrojanDropper:Win32/Delf.BL!MTB?

TrojanDropper:Win32/Delf.BL!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment