Trojan

Trojan-Banker.Win32.Qbot.xcn (file analysis)

Malware Removal

The Trojan-Banker.Win32.Qbot.xcn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.Qbot.xcn virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • A named pipe was used for inter-process communication
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • A process created a hidden window
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • A system process is generating network traffic likely as a result of process injection
  • Installs itself for autorun at Windows startup
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

www.ip-adress.com

How to determine Trojan-Banker.Win32.Qbot.xcn?


File Info:

crc32: C480D326
md5: 2caaec66a525bf9859f2573299fd6a88
name: upload_file
sha1: 704dd2ae1e997b4ed4b520a5043ba71594dc4df6
sha256: 2e3a00fdaf5b3d39495ffdd553749c4c21a86bca2b3aeaadc8668be2760f2fcb
sha512: a7beff4006bbcb68dcb5825cb922c5a922ad487c050ef77076259615bca2babab9075e2476f5a7962483f95a1dc71b669e35f00b94f6ebfa5f1571ca1e59f8c8
ssdeep: 12288:EyP/ms6j2cyD9QoLfhLwVSZR0mji1AqTVc2xrW6WqrjlnxVQdY:EyP/mswQ37hL57u1AUVcarWdqrpnDQdY
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) Laplink Software, Inc. 2007
InternalName: LLUSBArrival.exe
FileVersion: 17.500.01700.0
CompanyName: Laplink Software, Inc.
Comments: Laplink Gold Component
ProductName: Laplink Gold
ProductVersion: 14.01.0017.00
FileDescription: Laplink USB Autoplay Handler
OriginalFilename: LLUSBArrival.exe
Translation: 0x0409 0x04e4

Trojan-Banker.Win32.Qbot.xcn also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKD.34268677
FireEyeGeneric.mg.2caaec66a525bf98
CAT-QuickHealTrojan.Qakbot
McAfeePacked-GCB!2CAAEC66A525
CylanceUnsafe
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.34268677
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.e1e997
Invinceaheuristic
SymantecPacked.Generic.459
APEXMalicious
AvastWin32:BankerX-gen [Trj]
GDataTrojan.GenericKD.34268677
KasperskyTrojan-Banker.Win32.Qbot.xcn
AlibabaTrojanBanker:Win32/GenKryptik.bb7cd9cb
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.34268677 (B)
F-SecureTrojan.TR/Kryptik.efkby
DrWebTrojan.Inject3.45605
TrendMicroTROJ_GEN.R002C0OH120
Trapminemalicious.high.ml.score
SophosMal/EncPk-APV
SentinelOneDFI – Malicious PE
JiangminTrojan.Banker.Qbot.te
AviraTR/Kryptik.efkby
Antiy-AVLGrayWare/Win32.Kryptik.ehls
ArcabitTrojan.Generic.D20AE605
ZoneAlarmTrojan-Banker.Win32.Qbot.xcn
MicrosoftTrojan:Win32/Qakbot.SD!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Qakbot.R346679
VBA32BScope.Trojan.Zenpak
ALYacTrojan.GenericKD.34268677
MAXmalware (ai score=86)
Ad-AwareTrojan.GenericKD.34268677
MalwarebytesTrojan.Dropper
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HFIE
TrendMicro-HouseCallTROJ_GEN.R002C0OH120
RisingTrojan.Kryptik!1.C9B1 (CLOUD)
eGambitPE.Heur.InvalidSig
FortinetW32/GenKryptik.EOHS!tr
BitDefenderThetaGen:NN.ZexaF.34144.Qy1@aCZu4oai
AVGWin32:BankerX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/Trojan.BO.b78

How to remove Trojan-Banker.Win32.Qbot.xcn?

Trojan-Banker.Win32.Qbot.xcn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment