Trojan

About “Trojan:Win32/Zbot.SIBD25!MTB” infection

Malware Removal

The Trojan:Win32/Zbot.SIBD25!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Zbot.SIBD25!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Detects Sandboxie through the presence of a library
  • Detects the presence of Wine emulator via function name
  • Deletes its original binary from disk
  • CAPE detected the ZeusPanda malware family
  • Attempts to identify installed analysis tools by a known file location
  • Detects the presence of Wine emulator via registry key
  • Detects Sandboxie using a known mutex
  • Checks for a known DeepFreeze Frozen State Mutex
  • Collects information to fingerprint the system

How to determine Trojan:Win32/Zbot.SIBD25!MTB?


File Info:

name: F96815A02BA3052371FB.mlw
path: /opt/CAPEv2/storage/binaries/7bd5e86b5ab5032a7959cbfa3921db0ffec81318494ddbb402ee913fa2452aa8
crc32: 6FF6F3C6
md5: f96815a02ba3052371fbe8546e774098
sha1: 55ad4df681cbafb8009a749a25df55c4a51d5ad7
sha256: 7bd5e86b5ab5032a7959cbfa3921db0ffec81318494ddbb402ee913fa2452aa8
sha512: f6341531ef22afd0cf6532ee0f58986608d6c8deeaded3f496772c6aa9324d8793c92a46c3bb5890f186da61a6b566dcfc91c55c6223c3db364650d4fb009f7e
ssdeep: 3072:nMa4pV9xzlKoh2HvYNztvvBbO8j14LWN7hFNHiOVrNyr:b6VkE2yztQ8jNVfj3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FBF3F009BBE448F2E08F4B38BC62C1B90DF46E25D7E8C09515417D1EBE7A665453C72E
sha3_384: 5f0332e150860092872bdb2f636a1f5e128e19f67d5c140c379e7f14db26eeeecb99f4077b79c32c0b694e410ea931a0
ep_bytes: 558bec83ec7ca118004200a3d0204200
timestamp: 2018-06-17 09:32:30

Version Info:

CompanyName: AMYUNI Technologies Inc.
FileDescription: PDF Driver installer
FileVersion: 1, 0, 0, 1
InternalName: Install.exe
LegalCopyright: Copyright © 1998-2008
OriginalFilename: Install.exe
ProductName: Amyuni PDF Converter
ProductVersion: 3, 0, 3, 0
Translation: 0x0409 0x04b0

Trojan:Win32/Zbot.SIBD25!MTB also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Panda.l!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.f96815a02ba30523
McAfeeGenericRXHT-DJ!F96815A02BA3
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Skeeyah.A
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanSpy:Win32/Panda.c3e583b5
K7GWSpyware ( 0051fb6b1 )
K7AntiVirusSpyware ( 0051fb6b1 )
VirITTrojan.Win32.MulDrop8.DBKD
SymantecPacked.Generic.530
ESET-NOD32Win32/Spy.Zbot.ADC
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Spy.Win32.Panda.ccl
BitDefenderGen:Variant.Graftor.524601
NANO-AntivirusTrojan.Win32.Panda.fjizrl
MicroWorld-eScanGen:Variant.Graftor.524601
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.114d57fd
Ad-AwareGen:Variant.Graftor.524601
EmsisoftGen:Variant.Graftor.524601 (B)
ComodoMalware@#ru0csqj1lk5a
DrWebTrojan.MulDrop8.53667
ZillyaTrojan.Panda.Win32.314
TrendMicroTSPY_ZBOT.THOIBDAJ
McAfee-GW-EditionGenericRXHT-DJ!F96815A02BA3
SophosMal/Generic-S + Troj/Hancitor-M
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Graftor.524601
JiangminTrojanSpy.Panda.nb
WebrootW32.Trojan.Gen
AviraTR/AD.PandaBanker.rulsh
MAXmalware (ai score=100)
Antiy-AVLTrojan[Spy]/Win32.Panda
KingsoftWin32.Heur.KVMH017.a.(kcloud)
ArcabitTrojan.Graftor.D80139
ZoneAlarmTrojan-Spy.Win32.Panda.ccl
MicrosoftTrojan:Win32/Zbot.SIBD25!MTB
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34212.ju0@a0IpNJnm
ALYacSpyware.Banker.panda
TACHYONTrojan-Spy/W32.Panda.160768
VBA32TrojanSpy.Panda
MalwarebytesGeneric.Malware/Suspicious
TrendMicro-HouseCallTSPY_ZBOT.THOIBDAJ
RisingSpyware.Pandabanker!8.1117A (CLOUD)
YandexTrojan.GenAsa!VUpaVm/pWV4
IkarusTrojan-Spy.Zbot
FortinetW32/Generic.AC.429A48
AVGWin32:Trojan-gen
Cybereasonmalicious.02ba30
PandaTrj/CI.A

How to remove Trojan:Win32/Zbot.SIBD25!MTB?

Trojan:Win32/Zbot.SIBD25!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment