Trojan

TrojanBNK.Zbot.mue (file analysis)

Malware Removal

The TrojanBNK.Zbot.mue is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanBNK.Zbot.mue virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine TrojanBNK.Zbot.mue?


File Info:

name: 8BC6A95B1AE14235357A.mlw
path: /opt/CAPEv2/storage/binaries/411bd7d6c2a8f1dcb29c2e8a8e476c04b2d0f6c6b75371b9d6942894fcd8cb44
crc32: FBA3D9C3
md5: 8bc6a95b1ae14235357ab87a733f4ddb
sha1: e48692c6f9f92b76d869a0d05effae987ce7dc8c
sha256: 411bd7d6c2a8f1dcb29c2e8a8e476c04b2d0f6c6b75371b9d6942894fcd8cb44
sha512: ebc399433ac21f1f00a3d915d767465ee37be71b55c2bd08eaca4c7e83ddce05f2c88dd73e407d4492d14c25bdcb3578ee8d5af038d5a130a095604d011fbfd7
ssdeep: 3072:huxnEJt4yjyiLB0NklbN6UgUXJZE69UYCuQ:huFEYyjF0NEB6U95ZEmUgQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T131D31346FB965C1ED16F8BBFD4731D3A16384005AF2FC90B0038221F93A053BDA2AE52
sha3_384: ee9c117b2a38ddc400b305e12643485d88df960f5ff6020578fb3727d982b83b453e8fb30234938bd10f8d3d710fa6a9
ep_bytes: 60be155044008dbeebbffbff5783cdff
timestamp: 2004-11-16 16:05:52

Version Info:

0: [No Data]

TrojanBNK.Zbot.mue also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Zbot.l!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zbot.13
FireEyeGeneric.mg.8bc6a95b1ae14235
CAT-QuickHealTrojanBNK.Zbot.mue
McAfeePWS-Zbot.gen.pp
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.26125
SangforTrojan.Win32.Zbot.gen!Y
K7AntiVirusTrojan ( 0055dd191 )
AlibabaTrojanPSW:Win32/Kryptik.d0d2f5f5
K7GWTrojan ( 0055dd191 )
Cybereasonmalicious.b1ae14
VirITTrojan.Win32.Generic.AHHW
CyrenW32/Zbot.AX.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HAZ
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Zbot-48383
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zbot.13
NANO-AntivirusTrojan.Win32.Krap.ecctsf
SUPERAntiSpywareTrojan.Agent/Gen-Zbot
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.11bbe00f
Ad-AwareGen:Variant.Zbot.13
SophosMal/Generic-R + Mal/Zbot-U
ComodoMalware@#28w65s9zvmbw5
DrWebTrojan.PWS.Panda.387
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY_ZBOT.GPF
McAfee-GW-EditionBehavesLike.Win32.Dropper.cc
EmsisoftGen:Variant.Zbot.13 (B)
IkarusTrojan-Spy.Win32.Zbot
GDataGen:Variant.Zbot.13
JiangminTrojanSpy.Zbot.ansl
WebrootW32.Trojan.Gen
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.1868C2D
ViRobotTrojan.Win32.A.Zbot.137216.AM[UPX]
MicrosoftPWS:Win32/Zbot.gen!Y
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.IRCBot.R7502
BitDefenderThetaAI:Packer.C68222741F
ALYacGen:Variant.Zbot.13
MAXmalware (ai score=99)
VBA32Trojan.Zeus.EA.0999
TrendMicro-HouseCallTSPY_ZBOT.GPF
RisingSpyware.Zbot!8.16B (CLOUD)
YandexTrojan.GenAsa!ffpOiSdINwU
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Zbot.APYN!tr
AVGWin32:Malware-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove TrojanBNK.Zbot.mue?

TrojanBNK.Zbot.mue removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment