Trojan

Trojan-Banker.Win32.Danabot.jtp removal guide

Malware Removal

The Trojan-Banker.Win32.Danabot.jtp is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.Danabot.jtp virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan-Banker.Win32.Danabot.jtp?


File Info:

name: DE8B54A938AC18F15CAD.mlw
path: /opt/CAPEv2/storage/binaries/2a3acdcd76575762b18c18c644a745125f55ce121f742d2aad962521bc7f25fd
crc32: 9E6BBCE1
md5: de8b54a938ac18f15cad804d79a0e19d
sha1: b6004c62e2d9dbad9cfd5f7e18647ac983788766
sha256: 2a3acdcd76575762b18c18c644a745125f55ce121f742d2aad962521bc7f25fd
sha512: 7b64a99baafc8e692a47b9856f96b6bafa3cae22bd293c0e8faf148bdfe3f1401d5c316017b5c2f778d02ebc87edd2474e525b225ddc00685bb14da4c484e776
ssdeep: 49152:ZgZziYTt//YDt2Z/fZMdzUAOC5n+LlrxFTGWgKq:Z0ziYTKh2Z/f6AAOGarxFTG/v
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T17FC54C2033B69812F273133598F3D0E09ED8BD6299B4AD4B70C23B5F049F6D29A5975E
sha3_384: e4ddaabadcbd125aa5766d4ca5b576fa684ab97fe0827688b721d63649def6925dde628ebb9e4556cbee9f9b3b2106ad
ep_bytes: 558bec837d0c017505e871030000ff75
timestamp: 2020-10-15 17:13:25

Version Info:

CompanyName: History oil
FileDescription: Containnumeral Beatran
FileVersion: 2.6.0.569
InternalName: Containnumeral Beatran
OriginalFilename: Dog.dll
LegalCopyright: Copyright © 1997-2018 History oil, Inc
ProductName: History oil
Sun: Supplyproper
ProductVersion: 2.6.0.569
Translation: 0x0409 0x04b0

Trojan-Banker.Win32.Danabot.jtp also known as:

LionicTrojan.Win32.Danabot.7!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.GenericPMF.S24341678
ALYacSpyware.Danabot.A
CylanceUnsafe
ZillyaTrojan.Upatre.Win32.3764
SangforTrojan.Linux.UAParser.uzhi
K7AntiVirusTrojan ( 005899091 )
AlibabaTrojanBanker:Win32/Danabot.326a740e
K7GWTrojan ( 005899091 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Danabot.AO.gen!Eldorado
SymantecTrojan.Danabot
ESET-NOD32a variant of Generik.IMKXXZM
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Banker.Win32.Danabot.jtp
BitDefenderTrojan.GenericKD.47234476
ViRobotTrojan.Win32.Agent.2588672
MicroWorld-eScanTrojan.GenericKD.47234476
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.10cf7923
Ad-AwareTrojan.GenericKD.47234476
SophosMal/EncPk-AQC
ComodoMalware@#1rj6fx0kabjif
DrWebTrojan.Siggen15.31149
TrendMicroTrojanSpy.Win32.DANABOT.MR
McAfee-GW-EditionGenericRXQN-FX!DE8B54A938AC
FireEyeTrojan.GenericKD.47234476
EmsisoftTrojan.GenericKD.47234476 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.11JGA2V
JiangminTrojan.Banker.Danabot.eim
WebrootW32.Trojan.Danabot
AviraHEUR/AGEN.1145951
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.34C1634
KingsoftWin32.Troj.Banker.(kcloud)
GridinsoftTrojan.Win32.Banker.oa!s1
ArcabitTrojan.Generic.D2D0BDAC
MicrosoftTrojan:Win32/Danabot
AhnLab-V3Trojan/Win.Tnega.C4723159
McAfeeGenericRXQN-FX!DE8B54A938AC
TACHYONBanker/W32.DanaBot.2588672
VBA32Backdoor.Agent
MalwarebytesTrojan.Banker
TrendMicro-HouseCallTrojanSpy.Win32.DANABOT.MR
YandexTrojan.PWS.Cridex!m/65ZdW/YSs
IkarusTrojan.Win32.Krypt
MaxSecureTrojan.Malware.73836504.susgen
FortinetW32/GenKryptik.FLRE!tr
AVGWin32:Trojan-gen
PandaTrj/Agent.AAL

How to remove Trojan-Banker.Win32.Danabot.jtp?

Trojan-Banker.Win32.Danabot.jtp removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment