Trojan

Trojan:Win32/IcedId.DBC!MTB (file analysis)

Malware Removal

The Trojan:Win32/IcedId.DBC!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/IcedId.DBC!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (5 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Attempts to create or modify system certificates

Related domains:

www.intel.com
support.apple.com
ldrgopak.casa
support.oracle.com
help.twitter.com

How to determine Trojan:Win32/IcedId.DBC!MTB?


File Info:

crc32: 4DDC02ED
md5: 081c1c2d353fb6e3b294e835fd46d434
name: upload_file
sha1: 20a1aaa302b2329e9eabcfdd273f322472c4bd47
sha256: 91561f8b1c1ca7290bc3c1d7586fc44d2d6faf2a07df54803205c4a483772bc0
sha512: aff674d2d370a885a30068767f3b6ef81de525687c214ef726e41f25ddf9172f2f9521283d4fa28307352620d8a5fb6e9d1c7f3bff6e4691fd5e865a0df0793c
ssdeep: 3072:v3jEL8+nUD7fkznXS/SBVTnKlbC6WdLXD13FWzwSd+MEwwxcrKcHgZXSoNNPrQG:vzgs7fkzXSgD6sKwSdIqEBNuGIJyF
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 Sure ArtCommon 1998-2013
FileVersion: 5.7.5.49
CompanyName: Sure ArtCommon
ProductName: Expect Poor opposite
ProductVersion: 5.7.5.49
FileDescription: Expect Poor opposite
OriginalFilename: common.dll
Translation: 0x0409 0x04e4

Trojan:Win32/IcedId.DBC!MTB also known as:

BkavW32.AIDetectVM.malware1
DrWebTrojan.IcedID.30
MicroWorld-eScanTrojan.GenericKD.43573853
FireEyeTrojan.GenericKD.43573853
McAfeeGenericRXLO-OL!081C1C2D353F
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 0056bb971 )
AlibabaTrojanBanker:Win32/IcedID.7328f188
K7GWTrojan ( 0056bb971 )
ArcabitTrojan.Generic.D298E25D
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.EPLP
TrendMicro-HouseCallTROJ_GEN.R002C0WH220
KasperskyTrojan-Banker.Win32.IcedID.twoo
BitDefenderTrojan.GenericKD.43573853
NANO-AntivirusTrojan.Win32.IcedID.hpxpoj
Paloaltogeneric.ml
AegisLabTrojan.Win32.IcedID.7!c
Ad-AwareTrojan.GenericKD.43573853
EmsisoftTrojan.GenericKD.43573853 (B)
F-SecureTrojan.TR/Kryptik.rqhta
ZillyaTrojan.IcedId.Win32.2197
TrendMicroTROJ_GEN.R002C0WH220
FortinetW32/ACORult.55FC!tr
SophosMal/Generic-S
IkarusTrojan-Banker.DanaBot
AviraTR/Kryptik.rqhta
MAXmalware (ai score=80)
Antiy-AVLTrojan[Banker]/Win32.IcedID
MicrosoftTrojan:Win32/IcedId.DBC!MTB
ZoneAlarmTrojan-Banker.Win32.IcedID.twoo
CynetMalicious (score: 85)
RisingTrojan.GenKryptik!8.AA55 (CLOUD)
GDataTrojan.GenericKD.43573853
AVGWin32:Malware-gen
PandaTrj/GdSda.A
Qihoo-360Win32/Trojan.1e0

How to remove Trojan:Win32/IcedId.DBC!MTB?

Trojan:Win32/IcedId.DBC!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment