Trojan

Trojan-Banker.Win32.Trickster.ioc malicious file

Malware Removal

The Trojan-Banker.Win32.Trickster.ioc is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Banker.Win32.Trickster.ioc virus can do?

  • Dynamic (imported) function loading detected
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan-Banker.Win32.Trickster.ioc?


File Info:

name: D2D4819840FA5C0B1E7B.mlw
path: /opt/CAPEv2/storage/binaries/f04e0de34325b90056c7b32e10fd00cca51de65cfdebda372619bfde05d27150
crc32: AFB044D2
md5: d2d4819840fa5c0b1e7b47640f8fc861
sha1: 9ebecffba21f7bcf2b9c02d7d77fbaf431769d18
sha256: f04e0de34325b90056c7b32e10fd00cca51de65cfdebda372619bfde05d27150
sha512: 9ffee83bfdc0a6a003e3a48bc4dae9c28e33fa23681e83421be3bbc0627392ddda941dfa9815111f5a7e10f8a1a855d320416525a88123d0f8ee8e16be74233f
ssdeep: 12288:nXP+K0d75VOo2b7bm2MqNAxjqXSMIUFp1EW/4Ch+uqUhVYBKm59:XP4d7yo2b7bxMx2ik1EWZh+ubhVu99
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C9C423A05BCBF729C9C96834F544343AB65C1381CCB8A8C755CD6C074AB94A746F2EFA
sha3_384: d796dca9f473152d4016d7a87713b2e278e54b050f69f3bcd1fccec28860af2af5f3a599cd2ba6a1bd53145f5c9019a9
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-06-20 01:00:15

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 1.0.0.0
InternalName: AmazonNumDexV2.exe
LegalCopyright:
OriginalFilename: AmazonNumDexV2.exe
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Trojan-Banker.Win32.Trickster.ioc also known as:

LionicTrojan.Win32.Trickster.7!c
Elasticmalicious (high confidence)
DrWebTrojan.MulDropNET.12
MicroWorld-eScanIL:Trojan.MSILZilla.1813
FireEyeGeneric.mg.d2d4819840fa5c0b
ALYacIL:Trojan.MSILZilla.1813
SangforTrojan.Win32.Trickster.ioc
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojanBanker:MSIL/Trickster.df602485
K7GWTrojan ( 00568bd81 )
K7AntiVirusTrojan ( 00568bd81 )
BitDefenderThetaGen:NN.ZemsilF.34182.Im0@auuZnuc
CyrenW32/MSIL_Kryptik.CQL.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/TrojanDropper.Agent.EVL
TrendMicro-HouseCallTROJ_GEN.R002C0DL621
Paloaltogeneric.ml
KasperskyTrojan-Banker.Win32.Trickster.ioc
BitDefenderIL:Trojan.MSILZilla.1813
AvastWin32:RATX-gen [Trj]
TencentWin32.Trojan-banker.Trickster.Wrzw
EmsisoftIL:Trojan.MSILZilla.1813 (B)
F-SecureHeuristic.HEUR/AGEN.1101060
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0DL621
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
SophosMal/Generic-S
IkarusTrojan-Dropper.MSIL.Agent
JiangminTrojan.Banker.Trickster.aagt
AviraHEUR/AGEN.1101060
Antiy-AVLTrojan[Banker]/Win32.Trickster
MicrosoftTrojan:MSIL/Nanocore.SDSD!MTB
ViRobotTrojan.Win32.Z.Razy.568320.B
ZoneAlarmTrojan-Banker.Win32.Trickster.ioc
GDataIL:Trojan.MSILZilla.1813
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.C4044716
McAfeePWS-FCUQ!D2D4819840FA
MAXmalware (ai score=84)
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.PCrypt.MSIL.Generic
APEXMalicious
RisingMalware.Obfus/MSIL@AI.100 (RDM.MSIL:Fuponil5W3+LCWe8Aq372w)
YandexTrojan.PWS.Trickster!/L3p2U0SK+U
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetMSIL/CoinMiner.ELXR!tr
AVGWin32:RATX-gen [Trj]
Cybereasonmalicious.840fa5
PandaTrj/CI.A
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan-Banker.Win32.Trickster.ioc?

Trojan-Banker.Win32.Trickster.ioc removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment