Trojan

Should I remove “Trojan:Win32/IcedId.PA!MTB”?

Malware Removal

The Trojan:Win32/IcedId.PA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/IcedId.PA!MTB virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Access the NetLogon registry key, potentially used for discovery or tampering
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Creates a hidden or system file
  • CAPE detected the IcedID malware family

How to determine Trojan:Win32/IcedId.PA!MTB?


File Info:

name: 7BF94CFE2E45FA3E469E.mlw
path: /opt/CAPEv2/storage/binaries/27e9f996553701f26df7eed5c5893bf6e7ccc121d5dadd3ce9018a84f5b55744
crc32: F293F005
md5: 7bf94cfe2e45fa3e469eae39f8448437
sha1: a85dce41ef755e427eefb2e633f91032f4cefa69
sha256: 27e9f996553701f26df7eed5c5893bf6e7ccc121d5dadd3ce9018a84f5b55744
sha512: 00957d60cd40f438f7872d4df3aca46b08e9d5db4ff604b2cc7a05df47f52f7388d1c9a00447767e119662cdb403af71fd77ce35f8cd8f129d939cdaaa51e4ea
ssdeep: 3072:KCV1N3e1Gl+7Ky4mX3n4aULJJOd+hQyz8RMtNcGjKZ6rMrrrjEfRlV56QKZGvpV1:HVvl++UXN8KAlci8Mh7KUsKPt
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10E04BF48FAF1C272C6A434780C33CD642DADBC20A6818967B29D575F6B20793591F6AF
sha3_384: acbbe496020cd500f8ac26963c9c1b1fbe32083f880b550200c76ee1f26a5fb8838830e2e97bbaa491368b6164bebd40
ep_bytes: e8fd270000e978feffff8bff558bec81
timestamp: 2010-04-30 12:35:39

Version Info:

CompanyName: Precision Development Charge
FileDescription: Precision Development Mountain Flow
FileVersion: 13.1.88.15
InternalName: restdivision.exe
LegalCopyright: Copyright (c) Precision Development, 2014. All rights reserved
OriginalFilename: restdivision.exe
ProductName: Precision Development Year
ProductVersion: 13.1.88.15
Translation: 0x0409 0x04e4

Trojan:Win32/IcedId.PA!MTB also known as:

BkavW32.BanloadBCAB.Trojan
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.DWEV
FireEyeGeneric.mg.7bf94cfe2e45fa3e
McAfeeGenericRXHO-JB!7BF94CFE2E45
CylanceUnsafe
Cybereasonmalicious.e2e45f
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GSSG
APEXMalicious
ClamAVWin.Dropper.Icedid-6960708-1
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Agent.DWEV
NANO-AntivirusTrojan.Win32.IcedID.fpswpw
SUPERAntiSpywareTrojan.Agent/Gen-Banker
AvastWin32:Malware-gen
TencentTrojan.Win32.BitCoinMiner.la
Ad-AwareTrojan.Agent.DWEV
EmsisoftTrojan.Agent.DWEV (B)
DrWebTrojan.Inject3.14810
McAfee-GW-EditionGenericRXHO-JB!7BF94CFE2E45
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
GDataTrojan.Agent.DWEV
JiangminTrojan.Banker.IcedID.hq
AviraHEUR/AGEN.1104065
MAXmalware (ai score=86)
Antiy-AVLTrojan/Generic.ASMalwS.2B65A68
MicrosoftTrojan:Win32/IcedId.PA!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Inject.C3181714
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34294.lu0@aSovX0di
ALYacTrojan.Agent.DWEV
VBA32BScope.TrojanBanker.IcedID
MalwarebytesMalware.AI.22494142
RisingTrojan.Generic@ML.100 (RDMK:QX1rnuD08HrkANLxhoB14Q)
YandexTrojan.GenAsa!GNumwV4Cflw
IkarusTrojan-Banker.IcedID
eGambitUnsafe.AI_Score_91%
FortinetW32/GenKryptik.DHDJ!tr
AVGWin32:Malware-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Trojan:Win32/IcedId.PA!MTB?

Trojan:Win32/IcedId.PA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment