Trojan

About “Trojan-Banker.Win32.BestaFera.axtm” infection

Malware Removal

The Trojan-Banker.Win32.BestaFera.axtm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.BestaFera.axtm virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Looks up the external IP address
  • Authenticode signature is invalid
  • Attempts to identify installed AV products by installation directory
  • Attempts to modify proxy settings

Related domains:

ip-api.com
wpad.local-net
www.mediafire.com
jridicaopyxxxqrcgold.com

How to determine Trojan-Banker.Win32.BestaFera.axtm?


File Info:

name: 9DEAB5B42AC854F47522.mlw
path: /opt/CAPEv2/storage/binaries/a502d8c56d920bbb66fc1c51fedd8cc5a2440bf561a6096c67f89f4ad2ca12d3
crc32: 141C2997
md5: 9deab5b42ac854f47522dd8eebc934fd
sha1: 1d4d8ccb84da18fe211fabc9470fefabe0d759ec
sha256: a502d8c56d920bbb66fc1c51fedd8cc5a2440bf561a6096c67f89f4ad2ca12d3
sha512: b732bb59906a85f48fa74910bb7795ded22a95abf08cd605ed46a5524775a32818207677ff8a8b27a48828ee9c569a0d911ba88ce1ba90d83994b4b013aba45b
ssdeep: 24576:fLYcVvQvOYO5BQEZQ/tjBZbAQv6wUk3Egf:jRQv0HLZQd/bA4x3Egf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14825231E4B5B9F15E4C49831CDC282CAF3C3FE181E439B5642635D4E92B9149BECAA4F
sha3_384: 5c33b8b126683bf3a765de4334b0445e59fc994198be0447075c8a6ff794dca02c2bc8e2d80d62e23125eaebe8672c3c
ep_bytes: b8084c8b005064ff3500000000648925
timestamp: 2021-11-23 11:46:03

Version Info:

0: [No Data]

Trojan-Banker.Win32.BestaFera.axtm also known as:

LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.GenericKD.38107579
FireEyeGeneric.mg.9deab5b42ac854f4
McAfeeArtemis!9DEAB5B42AC8
CylanceUnsafe
ZillyaTrojan.BestaFera.Win32.10357
K7AntiVirusTrojan-Downloader ( 0058a4281 )
AlibabaTrojanBanker:Win32/BestaFera.77d5d392
K7GWTrojan-Downloader ( 0058a4281 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.34084.!iWaaqF0X!m
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDownloader.Delf.DJA
TrendMicro-HouseCallTROJ_GEN.R002C0WKQ21
Paloaltogeneric.ml
KasperskyTrojan-Banker.Win32.BestaFera.axtm
BitDefenderTrojan.GenericKD.38107579
TencentWin32.Trojan-banker.Bestafera.Hytu
Ad-AwareTrojan.GenericKD.38107579
SophosMal/Generic-R + Troj/DwnLd-UF
TrendMicroTROJ_GEN.R002C0WKQ21
McAfee-GW-EditionBehavesLike.Win32.Skintrim.fc
EmsisoftTrojan.GenericKD.38107579 (B)
IkarusTrojan-Downloader.Win32.Delf
GDataTrojan.GenericKD.38107579
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1112431
MAXmalware (ai score=87)
Antiy-AVLTrojan/Generic.ASMalwS.34D86B2
GridinsoftRansom.Win32.Sabsik.sa
ViRobotTrojan.Win32.Z.Delf.1028608
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
VBA32Trojan.Sabsik.FL
ALYacTrojan.GenericKD.38107579
PandaTrj/CI.A
APEXMalicious
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Delf.DFQ!tr.dldr
AVGWin32:Trojan-gen
Cybereasonmalicious.b84da1
AvastWin32:Trojan-gen

How to remove Trojan-Banker.Win32.BestaFera.axtm?

Trojan-Banker.Win32.BestaFera.axtm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment