Trojan

Trojan:Win32/Danabot.RF!MTB information

Malware Removal

The Trojan:Win32/Danabot.RF!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Danabot.RF!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Serbian
  • Detects the presence of Wine emulator via function name
  • Detects Sandboxie through the presence of a library
  • Detects SunBelt Sandbox through the presence of a library
  • Attempts to remove evidence of file being downloaded from the Internet
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Operates on local firewall’s policies and settings
  • Creates a copy of itself
  • Attempts to disable System Restore
  • Attempts to modify or disable Security Center warnings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
ssofhoseuegsgrfnu.ru
slpsrgpsrhojifdij.ru
aiiaiafrzrueuedur.ru
fuaiuebndieufeufu.ru
eiifngjfksisiufjf.ru
eoroooskfogihisrg.ru
noeuaoenriusfiruu.ru
iuirshriuisruruuf.ru
afeifieuuufufufuf.ru
srndndubsbsifurfd.ru
fiiauediehduefuge.ru
nousiieiffgogogoo.ru
fifiehsueuufidhfi.ru
eofihsishihiursgu.ru
nnososoosjfeuhueu.ru
ssofhoseuegsgrfnj.su
slpsrgpsrhojifdij.su
aiiaiafrzrueuedur.su
fuaiuebndieufeufu.su
eiifngjfksisiufjf.su
eoroooskfogihisrg.su
noeuaoenriusfiruu.su
iuirshriuisruruuf.su
afeifieuuufufufuf.su
srndndubsbsifurfd.su
fiiauediehduefuge.su
nousiieiffgogogoo.su
fifiehsueuufidhfi.su
eofihsishihiursgu.su
nnososoosjfeuhueu.su
ssofhoseuegsgrfnj.in
slpsrgpsrhojifdij.in
aiiaiafrzrueuedur.in
fuaiuebndieufeufu.in
eiifngjfksisiufjf.in
eoroooskfogihisrg.in
noeuaoenriusfiruu.in
iuirshriuisruruuf.in
afeifieuuufufufuf.in
srndndubsbsifurfd.in
fiiauediehduefuge.in
nousiieiffgogogoo.in
fifiehsueuufidhfi.in
eofihsishihiursgu.in
nnososoosjfeuhueu.in
ssofhoseuegsgrfnj.net
slpsrgpsrhojifdij.net
aiiaiafrzrueuedur.net
fuaiuebndieufeufu.net
eiifngjfksisiufjf.net
eoroooskfogihisrg.net
noeuaoenriusfiruu.net
iuirshriuisruruuf.net
afeifieuuufufufuf.net
srndndubsbsifurfd.net
fiiauediehduefuge.net
nousiieiffgogogoo.net
fifiehsueuufidhfi.net
eofihsishihiursgu.net
ssofhoseuegsgrfnj.biz
slpsrgpsrhojifdij.biz
aiiaiafrzrueuedur.biz
fuaiuebndieufeufu.biz
eiifngjfksisiufjf.biz
eoroooskfogihisrg.biz
noeuaoenriusfiruu.biz
iuirshriuisruruuf.biz
afeifieuuufufufuf.biz
srndndubsbsifurfd.biz
fiiauediehduefuge.biz

How to determine Trojan:Win32/Danabot.RF!MTB?


File Info:

crc32: 3D2C6980
md5: 95e6b9a77155d1ce5db4ed593aa1992d
name: 95E6B9A77155D1CE5DB4ED593AA1992D.mlw
sha1: 5651fc936be32ec69fcbaab4b777345f1dbf95a5
sha256: 7082cf0b17da60e7d690d38359b8b71c9e264b920fb7baadf4f11d81da629b89
sha512: 68f47f70a5313d4ee7b21613fbfb092049de40af64d70f8907accc0832652048b84b751803fe873efc249821a89401677ea6271ee2d73b4466fc4446d1538c5a
ssdeep: 3072:ZYL2xKUadrED7FWVcdXZENSaVODsm8rvt5XfNJINbc9dn:6LHtwhW/xODir1tfNJINgz
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2018, uecaxnlejve
InternalName: uzopamzo
FileVersion: 1.6.6.1
ProductVersion: 1.4.7.1

Trojan:Win32/Danabot.RF!MTB also known as:

BkavW32.FamVT.NemimU.Trojan
Elasticmalicious (high confidence)
DrWebTrojan.Siggen9.20826
CynetMalicious (score: 100)
ALYacTrojan.BrsecmonE.1
CylanceUnsafe
ZillyaAdware.Bayrob.Win32.1879
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
Cybereasonmalicious.77155d
SymantecInfostealer.Rultazo
ESET-NOD32a variant of Win32/Kryptik.GNLR
APEXMalicious
AvastWin32:BotX-gen [Trj]
ClamAVWin.Ransomware.Mint-9807934-0
BitDefenderTrojan.BrsecmonE.1
NANO-AntivirusTrojan.Win32.Bayrob.fktvmi
MicroWorld-eScanTrojan.BrsecmonE.1
TencentMalware.Win32.Gencirc.116e6a32
Ad-AwareTrojan.BrsecmonE.1
BitDefenderThetaGen:NN.ZexaF.34684.tq1@aiw8WQcG
TrendMicroTrojanSpy.Win32.FAREIT.SMKC.hp
FireEyeGeneric.mg.95e6b9a77155d1ce
EmsisoftTrojan.BrsecmonE.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Bayrob.asxh
AviraTR/Patched.Ren.Gen
MicrosoftTrojan:Win32/Danabot.RF!MTB
GridinsoftRansom.Win32.Gandcrab.oa!s1
ArcabitTrojan.BrsecmonE.1
ZoneAlarmHEUR:Trojan-Downloader.Win32.Trik.gen
GDataTrojan.BrsecmonE.1
AhnLab-V3Trojan/Win32.MalPacked.C4267266
McAfeeTrojan-FPST!95E6B9A77155
MAXmalware (ai score=86)
VBA32BScope.Trojan.Fuery
MalwarebytesTrojan.MalPack.GS
TrendMicro-HouseCallTrojanSpy.Win32.FAREIT.SMKC.hp
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazrrac5gY2eSvF5Wg+RGYeKj)
YandexTrojan.GenAsa!pRj+6tryd6I
IkarusTrojan.Win32.Crypt
FortinetW32/GenKryptik.CUPF!tr
AVGWin32:BotX-gen [Trj]

How to remove Trojan:Win32/Danabot.RF!MTB?

Trojan:Win32/Danabot.RF!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment