Backdoor

UDS:Backdoor.Win32.Tofsee information

Malware Removal

The UDS:Backdoor.Win32.Tofsee is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:Backdoor.Win32.Tofsee virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (21 unique times)
  • Starts servers listening on 0.0.0.0:9300
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Faeroese
  • Uses Windows utilities for basic functionality
  • Enumerates services, possibly for anti-virtualization
  • Deletes its original binary from disk
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Makes SMTP requests, possibly sending spam or exfiltrating data.
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Anomalous binary characteristics

Related domains:

microsoft-com.mail.protection.outlook.com
lazystax.ru
mxs.mail.ru
www.instagram.com
work.a-poster.info
158.102.105.176.dnsbl.sorbs.net
158.102.105.176.bl.spamcop.net
158.102.105.176.zen.spamhaus.org
158.102.105.176.sbl-xbl.spamhaus.org
158.102.105.176.cbl.abuseat.org
www.google.no
mail.escrevedeira.com.br

How to determine UDS:Backdoor.Win32.Tofsee?


File Info:

crc32: 9586F54A
md5: 8714222d835b62d4490fde8b496f230d
name: 8714222D835B62D4490FDE8B496F230D.mlw
sha1: a1717671be2a6ee3c96e26a96fd60741dbf9a029
sha256: 310e76e72887143af93f101da5cb90174f8b5fa9507177f6e6ce4087349b909d
sha512: 882147dd8feaa0dcb503f09693203ea9e883d3f65db68e4e0b6c02fa0126f25f6c0e39e75f1f8a1c7e725b43b970be62ba8c9c974b8869e46a1d53c293ddbc7b
ssdeep: 6144:1Ra3f9qhLIvdbCwLefYIJwH1DlmOil0iXsTRV:18v9qhLIvdefYPVZBYXsL
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

FileVersus: 1.0.85.28
ProductVersus: 1.0.85.28
Translations: 0x0185 0x015e

UDS:Backdoor.Win32.Tofsee also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
McAfeeArtemis!8714222D835B
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
Cybereasonmalicious.1be2a6
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HKZR
APEXMalicious
AvastWin32:RansomX-gen [Ransom]
CynetMalicious (score: 100)
KasperskyUDS:Backdoor.Win32.Tofsee.gen
SophosML/PE-A + Mal/GandCrypt-B
BitDefenderThetaGen:NN.ZexaF.34690.tuW@a4xznPjG
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.fh
FireEyeGeneric.mg.8714222d835b62d4
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_91%
MicrosoftTrojan:Win32/Glupteba!ml
AhnLab-V3Trojan/Win.Glupteba.R421832
Acronissuspicious
VBA32BScope.Trojan.Wacatac
RisingMalware.Heuristic!ET#75% (RDMK:cmRtazrr+JfPyMQNGNYFHIwh6vCf)
IkarusTrojan.Win32.FakeAV
AVGWin32:RansomX-gen [Ransom]
Paloaltogeneric.ml

How to remove UDS:Backdoor.Win32.Tofsee?

UDS:Backdoor.Win32.Tofsee removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment