Produces outbound traffic.
Creates a startup registry entry.
Contains characteristics of an identified security risk.


Technical Details:

Possible Security Risk

Security RiskDescription
Backdoor.Bifrose Backdoor.Bifrose is a backdoor trojan that attempts to propagate by exploiting local network shares. It will also attempt to join a predefined IRC server and channel in order to participate in DDoS attacks.

Threat CategoryDescription
A malicious backdoor trojan that runs in the background and allows remote access to the compromised system
A malicious trojan horse or bot that may represent security risk for the compromised system and/or its network environment


File System Modifications

#Filename(s)File SizeFile HashAlias
1 %Temp%\06.tmp 391,980 bytes MD5: 0x6586651CC7B6588DE7BDD38EAD464F22
SHA-1: 0x27D21F935F7940939FE91D03A52298C2606D948E
Backdoor.Win32.Bifrose.fxv [Kaspersky Lab]
Trojan.Win32.Refroso [Ikarus]
2 %Temp%\MSI1.tmp 571,904 bytes MD5: 0x172E2462B13B295A1688701956DDC878
SHA-1: 0xC1909F4798759A9B758D28FBBA7318F97BFF5E14
Backdoor.Win32.Bifrose.egjb [Kaspersky Lab]
Win32.Malware [Ikarus]
3 %Programs%\Startup%\server.exe
110,461 bytes MD5: 0x9BE895219570D564B063748496DF687E
SHA-1: 0x42AA54D7EAB37542770D23EC599337FF127409E3
W32.Sality.AE [Symantec]
Backdoor.Win32.Bifrose.fxv [Kaspersky Lab]
BackDoor-CEP.gen.g [McAfee]
Mal/Sality-D [Sophos]
Virus:Win32/Sality.AT [Microsoft]
Backdoor.Win32.Bifrose [Ikarus]
Win-Trojan/Midgare.30208 [AhnLab]
4 %ProgramFiles%\Company\NewProduct\Uninstall.exe 64,365 bytes MD5: 0x2597B0A9126D209FB640D90801CAA4BF
SHA-1: 0xF7E725A00D7BA68E5F67EAC63A83D09E37ECC831
(not available)
5 %ProgramFiles%\Company\NewProduct\Uninstall.ini 1,487 bytes MD5: 0x927FA5B06C90DADCF0D559CB2C1DECAB
SHA-1: 0x83BAD29587BB79D60E29AE8202FC9C821B1D5B12
(not available)
6 c:\Setup.exe 287,691 bytes MD5: 0xA394877A49EA1BE45553FD1CDD17CE22
SHA-1: 0x2D895B9EA8A2EB7F828CC0E76DB1899A36F9D131
Backdoor.Win32.Bifrose.fxv [Kaspersky Lab]
Trojan.Win32.Refroso [Ikarus]
7 [file and pathname of the sample #1] 647,168 bytes MD5: 0xA5A6EDE665F64D5758A30DCE5A9BAD92
SHA-1: 0xA6B05E2FCD46ACBAA0A6DFB9ED20408F6E2C199F
Trojan.Gen [Symantec]
BackDoor-CEP!bdw [McAfee]


Memory Modifications

Process NameProcess FilenameMain Module Size
Setup.exec:\setup.exe139,264 bytes
server.exe%Programs%\Startup%\server.exe114,688 bytes
[filename of the sample #1][file and pathname of the sample #1]655,360 bytes
06.tmp%Temp%\06.tmp237,568 bytes
server.exe%ProgramFiles%\bifrost\server.exe114,688 bytes

Service NameDisplay NameNew StatusService Filename
MSIServerWindows Installer"Running"%System%\msiexec.exe /V


Registry Modifications


Other details

Russian Federation

Remote HostPort Number


Outbound traffic (potentially malicious)



