Spy Trojan

Trojan.Spy.Banbra.W malicious file

Malware Removal

The Trojan.Spy.Banbra.W is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Spy.Banbra.W virus can do?

  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan.Spy.Banbra.W?


File Info:

name: 02183BE87261E2EE9FF8.mlw
path: /opt/CAPEv2/storage/binaries/072a0bcd209f2e99f07bcae2dcebe72cf8ca2a301750430dafb59afbef7467e0
crc32: A945F20E
md5: 02183be87261e2ee9ff833ac06bcb93c
sha1: 1a4bf1b75bd092780de72921f231cdc2b57ec437
sha256: 072a0bcd209f2e99f07bcae2dcebe72cf8ca2a301750430dafb59afbef7467e0
sha512: 7966885e7399c6b36035e59d3139b97ea992708129556b500879171979ca441565124f795b357f04de703e85d511e4de7c43a2964d5916a0755af9b1fcf45828
ssdeep: 6144:eCjIWnayWF6WF84AsxmPrgcYUxsAAgB1w//jiByeaCG:Al6YAsxmPrgUxQnOG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AF54135C7E438C92EC6A6671AEE3C3519D5FC0587C468541869A3E0E4F722F62E7B318
sha3_384: 9636b8ea3dc896f9a33e84113befa5db099894989b241ad9c7021aec75d517c6dbb6d843158843fd6a56cdd4bd30b5f9
ep_bytes: 60be007046008dbe00a0f9ffc7870ce7
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Trojan.Spy.Banbra.W also known as:

LionicTrojan.Win32.Banbra.7!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.Spy.Banbra.W
ClamAVWin.Trojan.Bancos-91
McAfeeArtemis!02183BE87261
MalwarebytesMalware.Heuristic.1003
ZillyaTrojan.Banbra.Win32.18355
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 7000000f1 )
AlibabaTrojanSpy:Win32/Banbra.f809fab2
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.87261e
CyrenW32/Banker.JSCV-6841
SymantecInfostealer.Bancos
ESET-NOD32a variant of Win32/Spy.Banbra.BF
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:Trojan-Banker.Win32.Banbra.bf
BitDefenderTrojan.Spy.Banbra.W
NANO-AntivirusTrojan.Win32.Banbra.oshi
AvastWin32:Malware-gen
TencentWin32.Trojan.Agen.Rzfl
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1355186
DrWebTrojan.PWS.Banker.2043
VIPRETrojan.Spy.Banbra.W
TrendMicroTSPY_BANCOS.AUF
McAfee-GW-EditionPWS-Banker.gen.f
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.02183be87261e2ee
EmsisoftTrojan.Spy.Banbra.W (B)
GDataTrojan.Spy.Banbra.W
JiangminTrojan/Banker.Banbra.kmn
WebrootTroj/Bancban-BD
AviraHEUR/AGEN.1355186
MAXmalware (ai score=82)
Antiy-AVLTrojan[Banker]/Win32.Banbra
XcitiumMalware@#2nld8owjd4tc7
ArcabitTrojan.Spy.Banbra.W
ViRobotTrojan.Win32.A.Banbra.291328.B[UPX]
ZoneAlarmUDS:Trojan-Banker.Win32.Banbra.bf
MicrosoftTrojanSpy:Win32/Banker
GoogleDetected
AhnLab-V3Trojan/Win32.Banbra.R67601
BitDefenderThetaGen:NN.ZelphiF.36250.rmGfa0SYq3jG
ALYacTrojan.Spy.Banbra.W
VBA32TScope.Trojan.Delf
Cylanceunsafe
PandaTrj/Banbra.gen
TrendMicro-HouseCallTSPY_BANCOS.AUF
RisingTrojan.Spy.Banbra.apx (CLOUD)
IkarusTrojan-Banker.Win32.Banker
FortinetW32/Banbra.BF!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Trojan.Spy.Banbra.W?

Trojan.Spy.Banbra.W removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment