Trojan

TrojanBanker.IcedID (file analysis)

Malware Removal

The TrojanBanker.IcedID is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanBanker.IcedID virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (8 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs some HTTP requests
  • Attempts to create or modify system certificates

Related domains:

www.intel.com
help.twitter.com
support.oracle.com
support.apple.com
loadbudapest.casa

How to determine TrojanBanker.IcedID?


File Info:

crc32: BB9DD716
md5: 831f95dc1084adf6efc34ef482c97622
name: upload_file
sha1: 8a4a7f02072ccc1ce789531c6d05d615088ae313
sha256: 75de5fcf6b52c219fc80db2ec7d2822cc9c0b44139defc4d28c7df69129ccdd9
sha512: 664c9f1a5ae5f2da43f329fe44f743c54a0cb8c804a9efb791fc54f3b8bab2e597351bb312e025da0fb305b6512b7e02940cb7f7ba3ad9b09f665a73bde10ae8
ssdeep: 3072:6KB9XLIOI4Bg6YJdC1ZxZgpARBk+ltNuVH:6w9CJA8sB3tg
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

TrojanBanker.IcedID also known as:

FireEyeGeneric.mg.831f95dc1084adf6
McAfeeGenericRXLO-ME!831F95DC1084
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.IcedID.7!c
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojanBanker:Win32/IcedID.acc946b8
K7GWRiskware ( 0040eff71 )
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 85)
GDataTrojan.GenericKDZ.69140
KasperskyTrojan-Banker.Win32.IcedID.twoh
BitDefenderTrojan.GenericKDZ.69140
MicroWorld-eScanTrojan.GenericKDZ.69140
TencentMalware.Win32.Gencirc.11a9af8a
Endgamemalicious (high confidence)
SophosMal/Generic-S
F-SecureTrojan.TR/Crypt.Agent.onnpc
DrWebTrojan.IcedID.30
TrendMicroTROJ_GEN.R002C0DGV20
EmsisoftTrojan.GenericKDZ.69140 (B)
IkarusTrojan.Win32.Crypt
CyrenW32/Trojan.XIFI-8324
JiangminTrojan.Banker.IcedID.nz
WebrootW32.Trojan.Gen
AviraTR/Crypt.Agent.onnpc
MAXmalware (ai score=86)
Antiy-AVLTrojan[Banker]/Win32.IcedID
MicrosoftTrojan:Win32/IcedId.DAX!MTB
ZoneAlarmTrojan-Banker.Win32.IcedID.twoh
AhnLab-V3Trojan/Win32.Agent.R346572
BitDefenderThetaGen:NN.ZedlaF.34144.ku4@a4vY1rc
ALYacTrojan.GenericKDZ.69140
TACHYONBanker/W32.IcedID.176128
VBA32TrojanBanker.IcedID
MalwarebytesTrojan.MalPack.RND
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HFGV
TrendMicro-HouseCallTROJ_GEN.R002C0DGV20
RisingTrojan.Kryptik!8.8 (CLOUD)
MaxSecureWin.MxResIcn.Heur.Gen
Ad-AwareTrojan.GenericKDZ.69140
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.5b8

How to remove TrojanBanker.IcedID?

TrojanBanker.IcedID removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment