Trojan

About “Trojan.DanaBot” infection

Malware Removal

The Trojan.DanaBot is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.DanaBot virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Detected script timer window indicative of sleep style evasion
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Creates a hidden or system file
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.DanaBot?


File Info:

crc32: 9C58F244
md5: 20efcaba068e7a3cfbf8fca4b4badb61
name: regsrtjser346.exe
sha1: b318e14538859a905721a9c99a8de62db9dada19
sha256: 44c7ef261a066790a4ce332afc634fb5f89f3273c0c908ec02ab666088b27757
sha512: b3eb9db926465a891827f5aff9c96f041b8004b7ce18a4812ad214fecc482cb2988f86b27a689e668a2dc4b42b024c501b5910cd503bc8e81a9eafc81bfde629
ssdeep: 24576:t20gPgFKB1IVZQLvA5QxAVBbIcXK8QrZRpnnSqQGOrQIfTEwy+3MJk2ugX5W:EKg1IVZQTrxAjIE9QpSqQVrfZ73MTugc
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.DanaBot also known as:

MicroWorld-eScanTrojan.GenericKD.33549650
Qihoo-360Win32/Trojan.BO.ba4
McAfeeArtemis!20EFCABA068E
AegisLabTrojan.Win32.Danabot.7!c
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.33549650
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.538859
SymantecTrojan.Gen.2
APEXMalicious
AvastFileRepMalware
KasperskyTrojan-Banker.Win32.Danabot.eib
Ad-AwareTrojan.GenericKD.33549650
EmsisoftTrojan.GenericKD.33549650 (B)
DrWebTrojan.Siggen9.21656
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Downloader.tc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.20efcaba068e7a3c
SophosMal/Generic-S
IkarusWin32.Outbreak
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1FFED52
ViRobotTrojan.Win32.Z.Agent.1212525
ZoneAlarmTrojan-Banker.Win32.Danabot.eib
MicrosoftTrojan:Win32/Wacatac.C!ml
MalwarebytesTrojan.DanaBot
MAXmalware (ai score=82)
GDataTrojan.GenericKD.33549650
AVGFileRepMalware
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan.DanaBot?

Trojan.DanaBot removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment