Trojan

Trojan-Banker.Win32.Danabot.hkm malicious file

Malware Removal

The Trojan-Banker.Win32.Danabot.hkm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.Danabot.hkm virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Slovenian
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan-Banker.Win32.Danabot.hkm?


File Info:

crc32: 1EA183DF
md5: cc71bdb3d4b7d7ee07e7a930604ec05e
name: filez.exe
sha1: bc9df0208c08ace9a910fbe8507bba1ab1588b5d
sha256: ed22f2dca8b71427cc4b0f0124fb4bcbe7790e83a3617a596befc79e5040c92a
sha512: 0939eab2fbf98d2b5186ecfba3297debbcf37a57ac0dc319078d7a36fa73f6b6e81b357c8f8dc816974327051c7d36fda7bc4b217edd563f0ce923772eb347e7
ssdeep: 49152:k+kRuCr1DJGN8S0iSYr4At405p8mNiGYT5/BKmB0r+QEQhbnGp3o4aEWqFkoLOf:koCrlJu8S0iPsAt4ap8SUZ0+QBhbnGC
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

InternalNamed: eczvkphvesv.ixe
FileVersionOld: 1.2.0.1
ProductVersion: 1.0.4.1
Copyrighd: Copyrighd (C) 2020, odfgbjv
Translation: 0x0842 0x04c4

Trojan-Banker.Win32.Danabot.hkm also known as:

BkavHW32.Packed.
MicroWorld-eScanTrojan.GenericKD.34053998
FireEyeGeneric.mg.cc71bdb3d4b7d7ee
ALYacSpyware.Danabot.A
SangforMalware
K7AntiVirusTrojan ( 0056689f1 )
BitDefenderTrojan.GenericKD.34053998
K7GWTrojan ( 0056689f1 )
CrowdStrikewin/malicious_confidence_80% (W)
ArcabitTrojan.Generic.D2079F6E
Invinceaheuristic
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HEFU
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Banker.Win32.Danabot.hkm
RisingTrojan.DanaBot!8.FCEF (CLOUD)
Ad-AwareTrojan.GenericKD.34053998
EmsisoftTrojan.GenericKD.34053998 (B)
ComodoMalware@#3qa81kqrgf4td
F-SecureTrojan.TR/AD.DanaBot.sejzi
TrendMicroTrojanSpy.Win32.DANABOT.THFBABO
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
FortinetW32/GenKryptik.DVWO!tr
SophosMal/Generic-S
IkarusTrojan-Downloader.Win32.Glupteba
AviraTR/AD.DanaBot.sejzi
MAXmalware (ai score=80)
Endgamemalicious (high confidence)
MicrosoftTrojan:Win32/DanaBot.GK!MTB
ZoneAlarmTrojan-Banker.Win32.Danabot.hkm
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.Wacatac.R341211
Acronissuspicious
McAfeeArtemis!CC71BDB3D4B7
MalwarebytesSpyware.RaccoonStealer
TrendMicro-HouseCallTrojanSpy.Win32.DANABOT.THFBABO
SentinelOneDFI – Suspicious PE
GDataTrojan.GenericKD.34053998
AVGWin32:TrojanX-gen [Trj]
AvastWin32:TrojanX-gen [Trj]
Qihoo-360HEUR/QVM10.1.1376.Malware.Gen

How to remove Trojan-Banker.Win32.Danabot.hkm?

Trojan-Banker.Win32.Danabot.hkm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment