Trojan

Trojan-Banker.Win32.Shifu (file analysis)

Malware Removal

The Trojan-Banker.Win32.Shifu is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.Shifu virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk
  • Anomalous binary characteristics

How to determine Trojan-Banker.Win32.Shifu?


File Info:

name: 739617CA8897A7D592A2.mlw
path: /opt/CAPEv2/storage/binaries/9a1a8a44b9510fbac0a5f2ba8b41e95ba363c25262f11e7dae71eec5dfeba187
crc32: E2D3E649
md5: 739617ca8897a7d592a272dd5e5b522b
sha1: 10758154cbaca7eff936e53f20eef798d7571f44
sha256: 9a1a8a44b9510fbac0a5f2ba8b41e95ba363c25262f11e7dae71eec5dfeba187
sha512: a2dbc570e75167c9c565dc147ddb965795a58d01c8cf97b71a1c12819573dcfcda71dd73a01aebfbbc2f7cbc4647475e5dc316408f98d9f2edd4cd36a3abff81
ssdeep: 6144:Vck18MipfIUaQYu8tbS6JBaxFW8jb/HFbdsifRe9+kH:VX8Djadu8JMxrlbBG/H
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12DC4D01075D1C073E95651BD8D06CE39A72774886F266AC3BBDCDA8F1B222E39B36701
sha3_384: 18fff33c140f5e183a0a96c7e7cf3bc0673e5a865f35ca9b22ed66105e1a1ca729497c0c12744964fa9b723c8f8a6d8e
ep_bytes: e822690000e917feffff8b44240433c9
timestamp: 2015-09-01 11:09:14

Version Info:

0: [No Data]

Trojan-Banker.Win32.Shifu also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.544421
FireEyeGeneric.mg.739617ca8897a7d5
CAT-QuickHealWorm.GamaruePMF.S30142563
SkyhighBehavesLike.Win32.Generic.ht
ALYacGen:Variant.Zusy.544421
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusSpyware ( 0057101a1 )
K7GWSpyware ( 0057101a1 )
CrowdStrikewin/malicious_confidence_100% (D)
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Spy.Shiz.NCR
APEXMalicious
ClamAVWin.Trojan.Generic-9831366-0
KasperskyHEUR:Trojan-Banker.Win32.Shifu.gen
BitDefenderGen:Variant.Zusy.544421
NANO-AntivirusTrojan.Win32.Banker1.fkcapg
AvastWin32:BankerX-gen [Trj]
TencentTrojan.Win32.Spy.ta
SophosTroj/Shiz-BS
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.PWS.Panda.13690
VIPREGen:Variant.Zusy.544421
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Zusy.544421 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.cuvox
GoogleDetected
AviraTR/Crypt.XPACK.Gen
VaristW32/Shifu.F.gen!Eldorado
Antiy-AVLTrojan[Banker]/Win32.Shifu
Kingsoftmalware.kb.a.998
MicrosoftWorm:Win32/Gamarue!rfn
XcitiumWorm.Win32.Gamarue.IC@7xv6jz
ArcabitTrojan.Zusy.D84EA5
ZoneAlarmHEUR:Trojan-Banker.Win32.Shifu.gen
GDataWin32.Trojan.PSE.3936XT
CynetMalicious (score: 100)
AhnLab-V3Worm/Win.BE.R641862
Acronissuspicious
McAfeeArtemis!739617CA8897
MAXmalware (ai score=86)
VBA32TrojanBanker.Shifu
Cylanceunsafe
RisingWorm.Gamarue!8.13B (TFE:5:BXtcUbWu9KR)
YandexTrojan.GenAsa!l0ZciBI6TfI
IkarusTrojan.Win32.Shifu
FortinetW32/Kryptik.DZLG!tr
BitDefenderThetaGen:NN.ZexaF.36802.HyZ@a4d7tec
AVGWin32:BankerX-gen [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan[stealer]:Win/Shiz.NWY

How to remove Trojan-Banker.Win32.Shifu?

Trojan-Banker.Win32.Shifu removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment