Malware

What is “Trickbot.Mikey.46 (B)”?

Malware Removal

The Trickbot.Mikey.46 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trickbot.Mikey.46 (B) virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Attempts to create or modify system certificates

Related domains:

api.ip.sb
158.102.105.176.zen.spamhaus.org
158.102.105.176.cbl.abuseat.org
158.102.105.176.b.barracudacentral.org
158.102.105.176.dnsbl-1.uceprotect.net
158.102.105.176.spam.dnsbl.sorbs.net

How to determine Trickbot.Mikey.46 (B)?


File Info:

crc32: 028FA5EB
md5: 0b449f440509509121cc6dc15b663867
name: 0B449F440509509121CC6DC15B663867.mlw
sha1: 282c578d76a371be772339bc9ef7d18c6e2b0032
sha256: c5529c964e7362a3ae3ffd0230d73253a491a38f70d2e88cc42abe8a246075b1
sha512: f78706b55703968e18360d09e6f928ba3b8296d129eb5c52e78330ef5eefaaa044c75c98c023e7c7fd914f1ea6659cbdf2ab40a53623de2e6ba17c0e082a3d68
ssdeep: 12288:3zgiXyC0EB3NGJwW888888888888888888888H0u7Kd6jIq+5ZWZXdSisd:UiXyC0m3Kl888888888888888888888u
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 1997
InternalName: NETTOOLS
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: NETTOOLS Application
ProductVersion: 1, 0, 0, 1
FileDescription: NETTOOLS MFC Application
OriginalFilename: NETTOOLS.EXE
Translation: 0x0409 0x04b0

Trickbot.Mikey.46 (B) also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.KillProc2.16485
CynetMalicious (score: 100)
CrowdStrikewin/malicious_confidence_100% (D)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.FIYH
APEXMalicious
AvastWin32:BankerX-gen [Trj]
KasperskyHEUR:Trojan.Win32.Trickpak.gen
BitDefenderTrojan.GenericKDZ.77048
MicroWorld-eScanTrojan.GenericKDZ.77048
Ad-AwareTrojan.GenericKDZ.77048
SophosML/PE-A
McAfee-GW-EditionBehavesLike.Win32.Dropper.bh
FireEyeGeneric.mg.0b449f4405095091
EmsisoftGen:Variant.Trickbot.Mikey.46 (B)
SentinelOneStatic AI – Suspicious PE
GDataTrojan.GenericKDZ.77048
McAfeeGenericRXAA-AA!0B449F440509
MAXmalware (ai score=84)
RisingTrojan.Generic@ML.85 (RDML:1Vutsq3HjcPyjACFpAbRVA)
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:BankerX-gen [Trj]
Qihoo-360HEUR/QVM07.1.43BF.Malware.Gen

How to remove Trickbot.Mikey.46 (B)?

Trickbot.Mikey.46 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment