Trojan

About “Trojan:Win32/TrickBot.DE!MTB” infection

Malware Removal

The Trojan:Win32/TrickBot.DE!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/TrickBot.DE!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Spoofs its process name and/or associated pathname to appear as a legitimate process
  • Network activity detected but not expressed in API logs
  • CAPE detected the TrickBot malware family
  • Creates a copy of itself
  • Attempts to disable Windows Defender

How to determine Trojan:Win32/TrickBot.DE!MTB?


File Info:

name: 25344EDD143B30449599.mlw
path: /opt/CAPEv2/storage/binaries/badde6b8e04fa1c1a7fbf6db6b19096d211d3d0ab731b76dc8a2481034295243
crc32: 3F3E30DB
md5: 25344edd143b30449599f0b5e968d540
sha1: 0feb2e6a182d47f45815292a0f278a121b58ed25
sha256: badde6b8e04fa1c1a7fbf6db6b19096d211d3d0ab731b76dc8a2481034295243
sha512: 2da752998d020337ad0f466531414dbb384c296c31203d643ffbb7c426edf91bcfec1c54ba87fa52ecce0802812436811c0afbd3beafb312a5a545594bf32038
ssdeep: 6144:RLUqlRecVn+Ge77Y3dNhewOa6T6VWl9UennnnkwG+g65lDHkywuj9X2bXW0f1v/A:5UOAW+Ge/Y3dNhewsuVWl9UennnnkwGy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19634023294AF165BE812A07B6496156ECEA4DE1156DE2BF746BB7DDF02F0BC4C0DB002
sha3_384: d53004580602f008342f6a257ec54a73aeecd749c1279d5cb1d774bb7a52b54b236e826bf7fc0e6f4f48bece463d3555
ep_bytes: 558bec81ec140c000033c0568d8decf3
timestamp: 2017-12-06 12:21:31

Version Info:

0: [No Data]

Trojan:Win32/TrickBot.DE!MTB also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Trickster.7!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Tdss.27
ALYacGen:Variant.Tdss.27
CylanceUnsafe
ZillyaTrojan.Trickster.Win32.1198
K7AntiVirusTrojan ( 0051ffe21 )
AlibabaTrojanBanker:Win32/TrickBot.84bd55d1
K7GWTrojan ( 0051ffe21 )
Cybereasonmalicious.d143b3
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrickBot.AC
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Trickbot-6335790-0
KasperskyTrojan-Banker.Win32.Trickster.ipm
BitDefenderGen:Variant.Tdss.27
NANO-AntivirusTrojan.Win32.Trickster.fkgbky
AvastWin32:Malware-gen
TencentWin32.Trojan.Tdss.Hoye
Ad-AwareGen:Variant.Tdss.27
SophosMal/Generic-S
TrendMicroTROJ_GEN.R002C0DKM21
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.25344edd143b3044
EmsisoftGen:Variant.Tdss.27 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Tdss.27
JiangminTrojan.Banker.Trickster.yq
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.230D466
ArcabitTrojan.Tdss.27
MicrosoftTrojan:Win32/TrickBot.DE!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Generic.C2390143
Acronissuspicious
McAfeeArtemis!25344EDD143B
MAXmalware (ai score=83)
VBA32BScope.TrojanBanker.Trickster
MalwarebytesMalware.AI.3439911061
TrendMicro-HouseCallTROJ_GEN.R002C0DKM21
RisingTrojan.Generic@ML.100 (RDML:FYKV4PgEnZ4rlRmSxKvuAg)
YandexTrojan.GenAsa!xPGbZCQuftU
IkarusTrojan.Win32.Trickbot
eGambitUnsafe.AI_Score_88%
FortinetW32/TrickBot.AC!tr
BitDefenderThetaAI:Packer.B70A2DE61F
AVGWin32:Malware-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan:Win32/TrickBot.DE!MTB?

Trojan:Win32/TrickBot.DE!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment