Trojan

What is “Trojan:Win32/DelfInject.BBHA!MTB”?

Malware Removal

The Trojan:Win32/DelfInject.BBHA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/DelfInject.BBHA!MTB virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Divehi
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Enumerates services, possibly for anti-virtualization
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Behavioural detection: Injection (inter-process)
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • CAPE detected the Tofsee malware family
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan:Win32/DelfInject.BBHA!MTB?


File Info:

name: 288988CAD77BBD0DC506.mlw
path: /opt/CAPEv2/storage/binaries/9ad46c2456fcacd2adb53dcbb4d58841d27e7175d651ecde51d5ac9d4cb92144
crc32: 8C6D45E9
md5: 288988cad77bbd0dc50612051578847a
sha1: f79ac22c95dfe14a1da2840093dc9a29819fd9e5
sha256: 9ad46c2456fcacd2adb53dcbb4d58841d27e7175d651ecde51d5ac9d4cb92144
sha512: 3e7cd593be30953452efd427b11f14c425e930b07e57184d6a6d89c2d99ade378ec62dc5ec45c85811cd99af082c31b9c367653bd1749562feab155a115770f4
ssdeep: 6144:0bM3G2Mccmu+00P7APnIIRFU/jKpi7glMMMMMMMMMMMMMMMMMMMMMMMMMMMMMMME:+Momt00P7APIIRFCKpi7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T145C69E3B2F3210B3DA6941BEBE5E7F25DB3EA675E70CA83F09A464E9740752444C0A17
sha3_384: ce73a2bb7aad747a45eed6d51af13b7425c177465c2afa85f46d6eb21df4177f47e61216a0e300aa9288621ff8c2f582
ep_bytes: 8bff558bece876600000e8110000005d
timestamp: 2020-12-25 06:04:22

Version Info:

Translations: 0x0025 0x0243

Trojan:Win32/DelfInject.BBHA!MTB also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Siggen16.12997
CynetMalicious (score: 100)
FireEyeGeneric.mg.288988cad77bbd0d
McAfeePacked-GEE!288988CAD77B
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.3655443
K7AntiVirusTrojan ( 0058c09a1 )
K7GWTrojan ( 0058c09a1 )
CrowdStrikewin/malicious_confidence_90% (D)
CyrenW32/Kryptik.FYI.gen!Eldorado
ESET-NOD32a variant of Win32/Kryptik.HNTA
APEXMalicious
ClamAVWin.Malware.Sabsik-9916500-0
KasperskyHEUR:Backdoor.Win32.Tofsee.gen
BitDefenderGen:Variant.Jaik.49909
MicroWorld-eScanGen:Variant.Jaik.49909
AvastWin32:CrypterX-gen [Trj]
Ad-AwareGen:Variant.Jaik.49909
SophosML/PE-A
BaiduWin32.Trojan.Kryptik.jm
McAfee-GW-EditionBehavesLike.Win32.Worm.wt
EmsisoftGen:Variant.Jaik.49909 (B)
IkarusTrojan.Win32
GDataWin32.Trojan.BSE.1R8QSDA
JiangminBackdoor.Tofsee.fhg
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.34F5209
ArcabitTrojan.Jaik.DC2F5
MicrosoftTrojan:Win32/DelfInject.BBHA!MTB
AhnLab-V3Infostealer/Win.SmokeLoader.R459746
Acronissuspicious
ALYacGen:Variant.Jaik.49909
MAXmalware (ai score=82)
VBA32BScope.Backdoor.Agent
MalwarebytesTrojan.MalPack.GS
RisingMalware.Obscure/Heur!1.9E03 (CLASSIC)
YandexTrojan.Kryptik!6eJQSOJIYgo
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_66%
FortinetW32/Kryptik.FSC!tr
AVGWin32:CrypterX-gen [Trj]
PandaTrj/GdSda.A

How to remove Trojan:Win32/DelfInject.BBHA!MTB?

Trojan:Win32/DelfInject.BBHA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment