Threat Database Backdoors Backdoor.ClipBanker.TM

Backdoor.ClipBanker.TM

By CagedTech in Backdoors

Threat Scorecard

Threat Level: 60 % (Medium)
Infected Computers: 3
First Seen: April 27, 2025
Last Seen: August 27, 2025
OS(es) Affected: Windows

The detection of Backdoor.ClipBanker.TM on your system indicates a potential security threat that requires immediate attention. This backdoor threat can compromise the security and integrity of your computer, allowing unauthorized access and potentially leading to further malicious activities. It is essential to understand the nature of this threat and take prompt action to remove it and prevent future infections.

What Is Backdoor.ClipBanker.TM?

Backdoor.ClipBanker.TM is a type of malware that creates a secret doorway into your computer system, allowing hackers to access and control your device remotely. This backdoor can be used to steal sensitive information, install additional malware, or disrupt the normal functioning of your computer. The name Backdoor.ClipBanker.TM itself suggests that it may be related to clipboard-related activities, but without specific details, it's crucial to focus on general removal and protection strategies.

How Backdoor.ClipBanker.TM Operates

Backdoor threats like Backdoor.ClipBanker.TM typically operate by exploiting vulnerabilities in software or using social engineering tactics to trick users into installing them. Once installed, they can communicate with their command and control servers to receive instructions, which may include stealing data, installing additional malware, or using the infected computer as part of a botnet. These threats can be particularly dangerous because they can remain hidden for extended periods, making them difficult to detect without proper security measures.

Symptoms of Infection

Symptoms of a Backdoor.ClipBanker.TM infection can vary, but common signs include unusual network activity, slow computer performance, and unexpected changes to system settings. You might also notice unfamiliar programs or toolbars installed on your browser, or find that your computer is behaving erratically. However, some backdoors are designed to be stealthy and may not exhibit obvious symptoms, making regular security scans crucial for detection.

How to Remove Backdoor.ClipBanker.TM

  1. Enter Safe Mode with Networking to prevent the malware from interfering with the removal process. This mode allows you to use the internet to download removal tools while limiting the malware's ability to launch.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter. Ensure the tool is updated with the latest definitions to improve the chances of detecting and removing the threat.
  3. Uninstall any suspicious programs or applications that you do not recognize or no longer need. Be cautious and only remove programs you are certain are safe to uninstall.
  4. Reset your web browsers (Google Chrome, Mozilla Firefox, Microsoft Edge) to their default settings. This can help remove any malicious extensions or settings changes made by the malware.
  5. Reboot your computer and perform another scan to ensure that the threat has been fully removed. This step is crucial as some malware can only be completely eradicated after a system restart.

Conclusion

Removing Backdoor.ClipBanker.TM requires a combination of using the right tools, following safe removal practices, and adopting preventive measures to avoid future infections. Regularly updating your operating system, browsers, and other software can help patch vulnerabilities that malware exploits. Additionally, being cautious with email attachments, downloads, and links can significantly reduce the risk of infection. By taking these steps and remaining vigilant, you can protect your computer and personal data from threats like Backdoor.ClipBanker.TM and maintain a secure computing environment.

Analysis Report

General information

Family Name: Backdoor.ClipBanker.TM
Signature status: Self Signed

Known Samples

MD5: dc51f909e64a88d3c10eb9c90462f10d
SHA1: 946781ffe6d076c79c0411e8b3a887784a45afb8
SHA256: 27E7A348899C9E894D9661091EEB18F30DFE88BB06D48F3CEE03B434C121FFC5
File Size: 3.43 MB, 3434544 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File has exports table
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name Quantum Corp
File Description Enterprise Solution
File Version 2.9.38
Legal Copyright Copyright © Core Technologies 2023. All rights reserved.
Original Filename undefined
Product Name Enterprise Firuzi
Product Version 2.9.38

Digital Signatures

Signer Root Status
OrionSign Code Signing Solvex Root CA Self Signed

File Traits

  • dll
  • fptable
  • HighEntropy
  • x64

Block Information

Total Blocks: 2,445
Potentially Malicious Blocks: 396
Whitelisted Blocks: 1,997
Unknown Blocks: 52

Visual Map

0 0 0 x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x x 0 0 0 0 0 x x 0 0 0 0 0 x 0 0 x x 0 0 0 x x 0 0 0 x 0 0 0 0 0 1 0 0 1 x 0 0 x x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x 0 0 x x 0 0 x 0 0 0 x 0 0 x 0 0 x 0 0 0 x 0 0 x 0 0 x 0 x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 x 0 x 0 0 x 0 x 0 1 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 x x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 x x x x 0 0 x 0 0 0 1 0 0 0 0 0 0 0 x 0 0 x x 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 x x 0 x x 0 0 0 0 0 x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 ? ? 0 0 0 1 0 0 0 0 0 0 0 0 x x x 0 0 x 0 x 0 x x x 0 x x x 0 0 0 0 0 0 0 0 x 0 0 x x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x x 0 0 0 0 ? 0 0 0 0 0 1 x 0 0 0 0 x x 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 x 0 0 x x 0 0 0 0 0 0 x x 1 x 0 x x 0 0 0 0 0 0 1 0 x ? 0 x x 0 0 0 0 x x x 0 0 x 0 0 0 ? ? ? ? ? ? x ? 0 0 0 0 x 0 0 x 0 0 x 0 0 0 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x 0 0 0 0 0 0 ? 0 0 0 0 x 0 0 0 ? 0 0 ? x 0 x ? x 0 ? ? 0 ? ? ? ? ? ? ? x 0 0 0 0 0 0 x 0 x x 0 0 x 0 0 x 0 0 x 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x 0 0 0 0 0 x x 0 0 0 0 0 x 0 x 0 0 0 0 0 x x ? x x ? x x ? x 0 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x x x 0 0 x 0 0 0 0 x x ? 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 ? 0 x 0 ? 0 ? ? x x 0 0 0 0 0 0 0 x x x x 0 x x 0 0 0 0 0 x 0 0 0 0 0 x x 0 x 0 0 0 x x x x x 0 0 0 0 0 0 0 x 0 0 0 x 0 0 x 0 x x x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 x 0 0 0 x x x x x x 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x x x 0 x 0 0 0 0 0 0 0 ? ? 0 0 0 x ? 0 0 0 0 0 x 0 x x 0 x x 0 0 x 0 ? ? ? 0 0 0 0 x x x 0 x x x x x x x x x x 0 x 0 0 0 0 0 0 x 0 0 0 1 x 0 0 0 0 0 0 0 x 0 x 0 x 0 0 0 0 0 0 0 0 x x x x 0 0 0 x 0 0 0 0 0 x x x x x ? x x 0 0 0 x x 0 x 0 0 0 0 0 x x x 0 0 0 0 x 0 0 0 0 0 x x 0 x x 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 x 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 x 0 0 0 0 0 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 ? 0 0 ? ? ? 0 ? 0 0 x ? x x 0 ? 0 0 0 0 0 0 0 0 0 0 0 x x x 0 x x x x x x 0 x x x 0 0 x 0 x 0 x x x x x x x 0 x x x x x 0 x 0 x ? x 0 x 0 x 0 x x x x x 0 0 x x x x 0 0 0 x 0 0 x x 0 0 x x x 0 x x x 0 0 x 0 0 x x x 0 x x 0 0 0 x x x x ? 0 x x x x 0 x x x x ? x x 0 0 0 ? 0 0 0 0 0 0 x x 0 x x x x 0 x 0 0 0 0 0 0 0 x x 0 x x x x x 0 x x x 0 x x 0 x x x x x 0 x x x 0 0 x 0 0 0 0 x x x x 0 0 0 0 0 x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • ClipBanker.TM

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
Show More
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenMutant
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • win32u.dll!NtGdiAnyLinkedFonts
  • win32u.dll!NtGdiBitBlt
  • win32u.dll!NtGdiComputeXformCoefficients
  • win32u.dll!NtGdiCreateBitmap
  • win32u.dll!NtGdiCreateCompatibleBitmap
  • win32u.dll!NtGdiCreateCompatibleDC
  • win32u.dll!NtGdiCreateDIBitmapInternal
  • win32u.dll!NtGdiCreateRectRgn
  • win32u.dll!NtGdiCreateSolidBrush
  • win32u.dll!NtGdiDeleteObjectApp
  • win32u.dll!NtGdiDoPalette
  • win32u.dll!NtGdiExcludeClipRect
  • win32u.dll!NtGdiExtGetObjectW
  • win32u.dll!NtGdiExtSelectClipRgn
  • win32u.dll!NtGdiExtTextOutW
  • win32u.dll!NtGdiFontIsLinked
  • win32u.dll!NtGdiGetCharABCWidthsW
  • win32u.dll!NtGdiGetDCDword
  • win32u.dll!NtGdiGetDCObject
  • win32u.dll!NtGdiGetDeviceCaps
  • win32u.dll!NtGdiGetDIBitsInternal
  • win32u.dll!NtGdiGetFontData
  • win32u.dll!NtGdiGetGlyphIndicesW
  • win32u.dll!NtGdiGetOutlineTextMetricsInternalW
  • win32u.dll!NtGdiGetRandomRgn
  • win32u.dll!NtGdiGetRealizationInfo
  • win32u.dll!NtGdiGetTextCharsetInfo
  • win32u.dll!NtGdiGetTextExtentExW
  • win32u.dll!NtGdiGetTextFaceW
  • win32u.dll!NtGdiGetTextMetricsW
  • win32u.dll!NtGdiGetWidthTable

78 additional items are not displayed above.

Related Posts

Trending

Most Viewed

Loading...