Trojan

Trojan-Banker.Win32.IcedID.twor (file analysis)

Malware Removal

The Trojan-Banker.Win32.IcedID.twor is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.IcedID.twor virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (5 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Attempts to create or modify system certificates

Related domains:

help.twitter.com
www.intel.com
support.apple.com
support.oracle.com
ldrpolka.casa

How to determine Trojan-Banker.Win32.IcedID.twor?


File Info:

crc32: 9E22CF8E
md5: edc6de5b365a2fde3a7223e3e1274638
name: upload_file
sha1: ecf2075b7bf6ea69fd28e1365668c0feea17d99e
sha256: d44e1c48e8eb2a9409fd9de698993977cc82c4848237db14d8b11df4e4315fcd
sha512: c7d59987499d1f2206a1e072ab4e18d39c18a2118bcd1e4d56b203d01aa614137fadc4716a51d746d86052e1c0fd499e2135853ce04bdd4646b999941f279213
ssdeep: 6144:+bKcnPyDuH40Y2qcEEFofBGMP/dzPRYEkLRfEAOnEenndt0slNak:+OFCYxcpFwGMP/RR0LRc+en71lNak
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 Ring DressSoldier 1994-2012
CompanyName: Ring DressSoldier
ProductName: Game Was page
ProductVersion: 1.7.3.779
FileDescription: Game Was page
OriginalFilename: spell.dll
Translation: 0x0409 0x04e4

Trojan-Banker.Win32.IcedID.twor also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKDZ.69172
FireEyeTrojan.GenericKDZ.69172
ALYacTrojan.GenericKDZ.69172
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 0056bb951 )
BitDefenderTrojan.GenericKDZ.69172
K7GWTrojan ( 0056bb951 )
TrendMicroTROJ_GEN.R06BC0WH120
CyrenW32/S-493380ae!Eldorado
SymantecML.Attribute.HighConfidence
AvastWin32:Trojan-gen
KasperskyTrojan-Banker.Win32.IcedID.twor
AlibabaTrojanBanker:Win32/IcedID.c0408e59
NANO-AntivirusTrojan.Win32.IcedID.hpyjfo
AegisLabTrojan.Win32.IcedID.7!c
TencentMalware.Win32.Gencirc.10cde599
Ad-AwareTrojan.GenericKDZ.69172
SophosMal/Generic-S
F-SecureTrojan.TR/AD.PhotoDlder.vkmqv
DrWebTrojan.IcedID.30
ZillyaTrojan.IcedId.Win32.2192
EmsisoftTrojan.GenericKDZ.69172 (B)
IkarusTrojan.Win32.Krypt
F-ProtW32/S-493380ae!Eldorado
JiangminTrojan.Banker.IcedID.oa
AviraTR/AD.PhotoDlder.vkmqv
FortinetW32/GenKryptik.EPEM!tr
Antiy-AVLTrojan[Banker]/Win32.IcedID
ArcabitTrojan.Generic.D10E34
ZoneAlarmTrojan-Banker.Win32.IcedID.twor
MicrosoftTrojan:Win32/IcedId.DAY!MTB
AhnLab-V3Trojan/Win32.Kryptik.R346806
McAfeeGenericRXLO-JU!EDC6DE5B365A
MAXmalware (ai score=87)
VBA32BScope.TrojanBanker.Cridex
CylanceUnsafe
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/GenKryptik.EPME
TrendMicro-HouseCallTROJ_GEN.R06BC0WH120
RisingTrojan.Kryptik!1.C9E2 (CLOUD)
GDataTrojan.GenericKDZ.69172
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.5bf

How to remove Trojan-Banker.Win32.IcedID.twor?

Trojan-Banker.Win32.IcedID.twor removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment