Malware

About “Python/ClipBanker.AV” infection

Malware Removal

The Python/ClipBanker.AV is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Python/ClipBanker.AV virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • A named pipe was used for inter-process communication
  • Starts servers listening on 127.0.0.1:0
  • Enumerates running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (inter-process)
  • A possible heap spray exploit has been detected
  • Collects and encrypts information about the computer likely to send to C2 server
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering
  • Anomalous binary characteristics

How to determine Python/ClipBanker.AV?


File Info:

name: B949B2E7C41D52D55480.mlw
path: /opt/CAPEv2/storage/binaries/a6efad077dd4ad0585bdab4d189e3b3c6e1a95ea4afe7cad4a42854dcd069020
crc32: 2BBD3AB0
md5: b949b2e7c41d52d5548081e2d6633769
sha1: 508fa5e1dc42dc8f59fc0b69d7be5ee5975ee554
sha256: a6efad077dd4ad0585bdab4d189e3b3c6e1a95ea4afe7cad4a42854dcd069020
sha512: 9d0ddade67e8c29db199abd3c48d222d361ed2ee25ebcc6ebe0e3102ca72bbc448d1d1852175d4d134943726fbfd65a40d634b003edf9a0e5ca7ff3b7c880fe5
ssdeep: 98304:a61oxVCczhpdN3g4MfHUl+aZSTXP8OaDxISmf6MjxkiS5aFA27uGsfSRUZGVMbfr:a61+Jp3wZTLEOalIPVvS5ZVGOwVMTr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10656E020B502D135EEEA04F692B89AF25D788D18772B61D3A5E878C8C5734F2363D35E
sha3_384: 63c7d49e825d56fade8a86edc74a1a29293caacc04144c10d80d5d5feecd992301b81e4e31b4ca250b12a10e67f46ffa
ep_bytes: e872030000e936fdffff8bff558bec8b
timestamp: 2018-01-21 14:45:53

Version Info:

0: [No Data]

Python/ClipBanker.AV also known as:

LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.GenericKD.46507826
McAfeeArtemis!B949B2E7C41D
CylanceUnsafe
SangforSuspicious.Win32.Cassini_a471b14b.ibt
AlibabaTrojan:Application/ClipBanker.61d6c50a
SymantecJS.Downloader
ESET-NOD32Python/ClipBanker.AV
APEXMalicious
BitDefenderTrojan.GenericKD.46507826
Ad-AwareTrojan.GenericKD.46507826
EmsisoftTrojan.GenericKD.46507826 (B)
F-SecureTrojan.TR/Redcap.zwtrg
McAfee-GW-EditionArtemis
FireEyeTrojan.GenericKD.46507826
GDataTrojan.GenericKD.46507826
AviraTR/Redcap.zwtrg
ArcabitTrojan.Generic.D2C5A732
MicrosoftTrojan:Win32/Tnega!ml
CynetMalicious (score: 99)
ALYacTrojan.GenericKD.46507826
MAXmalware (ai score=84)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetPython/ClipBanker.B!tr
AVGWin32:Malware-gen
Cybereasonmalicious.1dc42d
AvastWin32:Malware-gen

How to remove Python/ClipBanker.AV?

Python/ClipBanker.AV removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment