Malware

What is “Win32/Delf.BMH”?

Malware Removal

The Win32/Delf.BMH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Delf.BMH virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the AllaKore malware family

How to determine Win32/Delf.BMH?


File Info:

name: 5CA2BE98077BC0B48141.mlw
path: /opt/CAPEv2/storage/binaries/04206a2217be8d09e6dc6989d2a2b9aae8623f8fac962e5e07d9fa1a1577998b
crc32: 0A7FAEC0
md5: 5ca2be98077bc0b4814192c31f661b0a
sha1: 4e1dd2ad0f9474aef6e0b81272ae3fd07ecce535
sha256: 04206a2217be8d09e6dc6989d2a2b9aae8623f8fac962e5e07d9fa1a1577998b
sha512: caee917d05644bde5257890c277f8edcd16f809899caf8582bc981e411d70542faf875480a4dba0219d6f4a0c855e9626200e7e5888ec049b90280cff3e965b3
ssdeep: 49152:MnrK+menpSbqdyTk7fU35yvqEH5qrCfGETNTBYsYerjmEhQ7HxMyhw9zFVRNg/R9:MnrKlk835yvqAw+jmEQ7RMyhmXg/R9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T172567D127340E43AC06A1B374926D7D49B3BFE916F128E8737EC2F5E9F356802D26652
sha3_384: 7a55cfcb8f197be64c0d2c1bef86dbde5a2c49042b92792432a9e482b1e340b7cb24ca71807fe0b031bbe2e9a4491800
ep_bytes: 558bec83c4f053b878a17600e83b97c9
timestamp: 2021-12-02 06:12:23

Version Info:

CompanyName: MinoTec
FileVersion: 1.1.1.780
InternalName: MinoTec
ProductVersion: 1.1.1.756
Translation: 0x0409 0x04e4

Win32/Delf.BMH also known as:

LionicTrojan.Win32.Cyrus.m!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.47612010
FireEyeTrojan.GenericKD.47612010
CAT-QuickHealTrojan.Win32CiR
ALYacBackdoor.Agent.Cyrus
CylanceUnsafe
SangforBackdoor.Win32.Cyrus.gen
K7AntiVirusTrojan ( 005778c91 )
AlibabaBackdoor:Win32/Cyrus.62eb5007
K7GWTrojan ( 005778c91 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZelphiF.34114.@V0@aKVIuYhO
CyrenW32/Backdrx.SACW-3582
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Delf.BMH
TrendMicro-HouseCallTROJ_GEN.R002C0WL521
Paloaltogeneric.ml
ClamAVWin.Trojan.Zusy-9870698-0
KasperskyHEUR:Backdoor.Win32.Cyrus.gen
BitDefenderTrojan.GenericKD.47612010
AvastWin32:BackdoorX-gen [Trj]
TencentWin32.Trojan.Delf.Szbu
Ad-AwareTrojan.GenericKD.47612010
ZillyaTrojan.Delf.Win32.140644
TrendMicroTROJ_GEN.R002C0WL521
McAfee-GW-EditionBehavesLike.Win32.Dropper.th
EmsisoftTrojan.GenericKD.47612010 (B)
APEXMalicious
GDataTrojan.GenericKD.47612010
JiangminBackdoor.Cyrus.n
eGambitUnsafe.AI_Score_82%
AviraTR/Spy.Banker.Gen4
MAXmalware (ai score=86)
Antiy-AVLTrojan/Generic.ASMalwS.34F7343
GridinsoftRansom.Win32.Sabsik.sa
ViRobotTrojan.Win32.Z.Delf.6195712
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.Reputation.C4323297
McAfeeArtemis!5CA2BE98077B
VBA32Backdoor.Cyrus
MalwarebytesBackdoor.Agent
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Delf.BMH!tr
AVGWin32:BackdoorX-gen [Trj]
Cybereasonmalicious.8077bc
PandaTrj/GdSda.A

How to remove Win32/Delf.BMH?

Win32/Delf.BMH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment