Trojan

Trojanspy.Fbkatz (file analysis)

Malware Removal

The Trojanspy.Fbkatz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojanspy.Fbkatz virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (9 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Network anomalies occured during the analysis.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Queries information on disks, possibly for anti-virtualization
  • Steals private information from local Internet browsers
  • Collects information about installed applications
  • Generates some ICMP traffic
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities

Related domains:

www.wdsfw34erf93.com
www.rationalowl.com
crt.usertrust.com
ocsp.comodoca.com
ocsp.usertrust.com
ocsp.sectigo.com
iplogger.org
apps.identrust.com
isrg.trustid.ocsp.identrust.com
ocsp.int-x3.letsencrypt.org

How to determine Trojanspy.Fbkatz?


File Info:

crc32: 0BF50A6A
md5: 9c6fdeb2af716fee153488d8e2288b86
name: upload_file
sha1: 9eddc3f78a070ce0eecb9d9091a7f4206cd00472
sha256: 3419cd3aa1836577742af73aefa4d0fd5a198cbc4474af670408e6752f0dd89e
sha512: 55d671e73c895226e99564e8ef3fd2b251bbb5fc45e86344403b83a041c5d7bcf75010db8ec1b4e7afef9f57d48d0e8767c57803302bcbbeaffa9c27aab3bfce
ssdeep: 196608:JIUtl0sOY4e7ik+TuKKhIS0CuxjS81goG1XPZjjKKqaslMIz1kDaZ1//oq4nTf39:u8WQ7F9KKhN0J1goG1F0aslMIz1bZ13a
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojanspy.Fbkatz also known as:

Elasticmalicious (high confidence)
CAT-QuickHealTrojanspy.Fbkatz
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
BitDefenderTrojan.GenericKD.34729064
K7GWTrojan ( 00570bb91 )
K7AntiVirusTrojan ( 00570bb91 )
InvinceaMal/Generic-S
CyrenW32/Trojan.FZGN-2908
SymantecTrojan.Gen.MBT
APEXMalicious
ClamAVWin.Malware.Nemesis-9775649-0
KasperskyHEUR:Trojan-Dropper.Win32.Dapato.gen
AlibabaTrojanPSW:Win32/Socelars.8ec66080
NANO-AntivirusTrojan.Win32.Fbkatz.hvpzzm
EmsisoftTrojan.GenericKD.34729064 (B)
ComodoMalware@#v728lg4gb1ki
F-SecureTrojan.TR/Kryptik.hxwkw
DrWebTrojan.PWS.Siggen2.57014
TrendMicroTROJ_GEN.R011C0WJC20
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
FireEyeGeneric.mg.9c6fdeb2af716fee
SophosMal/Generic-S
JiangminPSWTool.NetPass.tb
AviraTR/AD.PredatorThief.HX
MicrosoftTrojanSpy:Win32/Socelars!MSR
ArcabitApplication.Heur.mmKfkyM2bMpO
ZoneAlarmHEUR:Trojan-Dropper.Win32.Dapato.gen
GDataWin32.Trojan-Stealer.CoinStealer.UAS46U
CynetMalicious (score: 85)
AhnLab-V3Unwanted/Win32.Mimikatz.C4191634
McAfeeArtemis!9C6FDEB2AF71
MAXmalware (ai score=85)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Downloader
PandaTrj/CI.A
ESET-NOD32multiple detections
TrendMicro-HouseCallTROJ_GEN.R011C0WJC20
RisingTrojan.IPLogger!1.C3EB (CLASSIC:5:kMsZxfVInkV)
YandexTrojan.PWS.Agent!haHc1puF2MQ
IkarusTrojan.Win32.Krypt
FortinetW32/GenKryptik.ETPY!tr
AVGWin32:MalwareX-gen [Trj]
Cybereasonmalicious.78a070
AvastWin32:MalwareX-gen [Trj]
Qihoo-360Win32/Trojan.Dropper.9f4

How to remove Trojanspy.Fbkatz?

Trojanspy.Fbkatz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment