Threat Database Trojans Trojan.Bifrose

Trojan.Bifrose

By CagedTech in Trojans

Aliases

15 security vendors flagged this file as malicious.

Antivirus Vendor Detection
Fortinet W32/Bifrose.CRTT!tr.bdr
Microsoft Trojan:Win32/Dynamer!dtc
Sophos Mal/Generic-L
McAfee-GW-Edition Heuristic.LooksLike.Win32.Suspicious.F!81
AntiVir TR/Spy.863158
Comodo Backdoor.Win32.Bifrose.~1
Kaspersky Backdoor.Win32.Bifrose.crtt
Avast Win32:Bifrose-EOS [Trj]
Symantec Trojan Horse
F-Prot W32/MalwareF.ADIUP
K7AntiVirus Riskware ( aaf557ea0 )
McAfee Generic.dx!01BA33CCE793
Panda Bck/Bifrost.gen
AVG Generic_r.UO
Ikarus Trojan-Spy.Win32.Logsnif

File System Details

Trojan.Bifrose may create the following file(s):
# File Name MD5 Detections
1. SXDesk.exe 6f772b8c6a68c9f2c654d1703ee93e6e 0
2. CLADD 74bc3cd3057ed13c67bac39efefdcf28 0
3. serve.exe 484d8a89012e7c1a5dcff3cacd53b90e 0
4. explorer.exe 511f563297d08915b15f03eb163031a7 0
More files

Analysis Report

General information

Family Name: Backdoor.Bifrose
Signature status: No Signature

Known Samples

MD5: 8b6450f6d43a9e848f6d33b06b3411c3
SHA1: 1f677ad0abcfe8f0c4c694c7732c7f95a94d08f6
SHA256: 8150596BCBBE51058C6988D0278A1AB14DC14F02700639E771D420726A81BA9A
File Size: 3.17 MB, 3166208 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have relocations information
  • File doesn't have security information
  • File has exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments Modified by an unpaid evaluation copy of Resource Tuner 2 (www.heaventools.com)
Company Name Hanbitsoft corp.
File Description Tantra Client
File Version 6, 9, 0, 6
Internal Name HTLaunch
Legal Copyright Copyright (c) - 2003 Hanbitsoft corp.
Original Filename HTLaunch.exe
Product Name Tantra Client
Product Version 1, 0, 0, 1

File Traits

  • 00 section
  • 2+ executable sections
  • HighEntropy
  • RT
  • x86

Block Information

Total Blocks: 4
Potentially Malicious Blocks: 0
Whitelisted Blocks: 3
Unknown Blocks: 1

Visual Map

0 0 0 ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • BadJoke.LMG

Windows API Usage

Category API
Other Suspicious
  • SetWindowsHookEx
User Data Access
  • GetComputerName
  • GetUserName
  • GetUserObjectInformation

Trending

Most Viewed

Loading...