Trojan

Trojan:Win32/Bluteal!bit removal instruction

Malware Removal

The Trojan:Win32/Bluteal!bit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Bluteal!bit virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Arabic (Egypt)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Sniffs keystrokes
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • CAPE detected the Remcos malware family
  • Creates a copy of itself
  • Creates known Remcos directories and/or files
  • Creates known Remcos mutexes
  • Creates known Remcos registry keys
  • Anomalous binary characteristics

How to determine Trojan:Win32/Bluteal!bit?


File Info:

name: F85D5F9853C3AF0F59B4.mlw
path: /opt/CAPEv2/storage/binaries/950129a8016f662511003ede67a6088c1270ccb2ddc75349ce13702539267762
crc32: 2DB4E3AE
md5: f85d5f9853c3af0f59b442bea4d676e6
sha1: a3441699d179d5eefc2e93daa647e1e21c4e6ddd
sha256: 950129a8016f662511003ede67a6088c1270ccb2ddc75349ce13702539267762
sha512: 8bbaccd1ca3175960cdc8aa5b9529382fcc1e389ba4079608559a5700405919358c1cb8bacd0ea1659117fcec6d25c16f0e495cab0f0333192f5e6dd32450ab3
ssdeep: 12288:WVBFXoXKwNE3MkAuOiNYfdFzYM5pA69oK8ogfaKD:WJXoXKwNhDuOiNA/Np78oSaq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T166E4024BE8522CE7DCE436FA24619290DBA14D028C2D07D727D63DE6FA33542FB0B645
sha3_384: 9819b7f3e9bababe670e10381afc792936f487ec4210cf360212b67826aacae6724570db9a22b26067962f24dd51682b
ep_bytes: 60e80000000058055a0b00008b3003f0
timestamp: 1992-06-19 22:22:17

Version Info:

ProductName: WinRAR
CompanyName: Alexander Roshal
FileDescription: Command line RAR
FileVersion: 5.31.0
ProductVersion: 5.31.0
InternalName: Command line RAR
LegalCopyright: Copyright © Alexander Roshal 1993-2016
Translation: 0x0409 0x04e4

Trojan:Win32/Bluteal!bit also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Remcos.4!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.23680
MicroWorld-eScanTrojan.GenericKD.31621942
FireEyeGeneric.mg.f85d5f9853c3af0f
ALYacTrojan.GenericKD.31621942
CylanceUnsafe
ZillyaTrojan.Rescoms.Win32.26
SangforTrojan.Win32.Rescoms.B
K7AntiVirusTrojan ( 0053ac2c1 )
AlibabaTrojan:Win32/DelfInject.ali2000015
K7GWTrojan ( 0053ac2c1 )
Cybereasonmalicious.853c3a
BitDefenderThetaGen:NN.ZelphiF.34182.PmuaaOtQZohi
CyrenW32/Risk.CUIV-3194
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Rescoms.B
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Remcos.bgx
BitDefenderTrojan.GenericKD.31621942
NANO-AntivirusTrojan.Win32.Stealer.fmppvd
AvastWin32:Malware-gen
TencentWin32.Backdoor.Remcos.Auto
EmsisoftTrojan.GenericKD.31621942 (B)
ComodoMalware@#220718abp1wob
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
SophosMal/Generic-S + Mal/Generic-L
IkarusTrojan.Inject
JiangminTrojan.PSW.Azorult.hej
eGambitUnsafe.AI_Score_95%
AviraTR/Rescoms.tivyv
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.2A7789B
MicrosoftTrojan:Win32/Bluteal!bit
ZoneAlarmBackdoor.Win32.Remcos.bgx
GDataWin32.Backdoor.Remcos.LHO1WN
AhnLab-V3Trojan/Win32.Kryptik.C2990604
McAfeeGeneric.buk
TACHYONBackdoor/W32.Remcos.678912
VBA32BScope.TrojanDownloader.Banload
MalwarebytesMalware.Heuristic.1003
APEXMalicious
RisingBackdoor.Remcos!8.B89E (CLOUD)
YandexTrojan.GenAsa!h7ATYxrj5pg
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.74111127.susgen
FortinetW32/Remcos.B!tr.bdr
WebrootW32.Trojan.Gen
AVGWin32:Malware-gen
PandaTrj/WLT.E
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Bluteal!bit?

Trojan:Win32/Bluteal!bit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment