Trojan

UDS:Trojan-Banker.Win32.ClipBanker.rrh (file analysis)

Malware Removal

The UDS:Trojan-Banker.Win32.ClipBanker.rrh is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:Trojan-Banker.Win32.ClipBanker.rrh virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • Binary compilation timestomping detected

How to determine UDS:Trojan-Banker.Win32.ClipBanker.rrh?


File Info:

name: 68C5BE642AA82AE6C65C.mlw
path: /opt/CAPEv2/storage/binaries/9f4d6a62519d18369b54a6ed4d9afe2ad9260323a5b4203d02ae4d7609a18547
crc32: D69253F4
md5: 68c5be642aa82ae6c65cccfd24b5c086
sha1: 253da8af2542123158377b3c46b809c804c1a50b
sha256: 9f4d6a62519d18369b54a6ed4d9afe2ad9260323a5b4203d02ae4d7609a18547
sha512: a8645a1a3a97ad472eae0b3b34a9bf8b725bf7d9004ff20493a7e5dfbfca7ce656bf1faad7cf1cbccf9b57eb0c9f88ce8babaf0d528a2969e4ff1859c3138c3d
ssdeep: 98304:SjliaX3c2KeRsY7mHtfyVQ3jwIA2/Bt/UwvrfYiPZW1E:Sj22sY7UthB/tkiRwE
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T1491600B3319551B4D4231E3CB0A752328EB3ECBD3AB4079BED647E691BB17452422B27
sha3_384: 7e2683fabdd78560e39c3212dc13bfb5927b181132119df0efee2e3e5c2d4be470fce5f7c2a55432a2a85cd0ac0a8a7b
ep_bytes: 4883ec28e85b0700004883c428e90600
timestamp: 2062-07-25 12:18:00

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Auto-extracteur de fichier CAB Win32
FileVersion: 11.00.19041.1288 (WinBuild.160101.0800)
InternalName: Wextract
LegalCopyright: © Microsoft Corporation. Tous droits réservés.
OriginalFilename: WEXTRACT.EXE .MUI
ProductName: Internet Explorer
ProductVersion: 11.00.19041.1288
Translation: 0x040c 0x04b0

UDS:Trojan-Banker.Win32.ClipBanker.rrh also known as:

Elasticmalicious (high confidence)
FireEyeGeneric.mg.68c5be642aa82ae6
McAfeeArtemis!68C5BE642AA8
CylanceUnsafe
Cybereasonmalicious.f25421
ESET-NOD32a variant of Win32/Delf.TYB
APEXMalicious
KasperskyUDS:Trojan-Banker.Win32.ClipBanker.rrh
NANO-AntivirusTrojan.Win32.Drop.fczyqp
SophosGeneric ML PUA (PUA)
DrWebTrojan.MulDrop9.4175
McAfee-GW-EditionBehavesLike.Win64.Dropper.rc
AviraHEUR/AGEN.1105456
Antiy-AVLTrojan/Generic.ASMalwS.263D693
CynetMalicious (score: 100)
MalwarebytesTrojan.Delf
eGambitUnsafe.AI_Score_80%
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_60% (W)

How to remove UDS:Trojan-Banker.Win32.ClipBanker.rrh?

UDS:Trojan-Banker.Win32.ClipBanker.rrh removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment