Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now
79
Global rank
60 infographic chevron month
Month rank
56 infographic chevron week
Week rank

Danabot is an advanced banking Trojan malware that was designed to steal financial information from victims. Out of the Trojans in the wild, this is one of the most advanced thanks to the modular design and a complex delivery method.

Trojan
Type
Unknown
Origin
6 May, 2018
First seen
18 September, 2026
Last seen

How to analyze Danabot with ANY.RUN

Type
Unknown
Origin
6 May, 2018
First seen
18 September, 2026
Last seen

IOCs

IP addresses
23.52.181.141
172.211.123.249
23.59.18.102
142.250.154.100
48.209.133.15
150.171.28.11
23.11.41.157
2.16.241.218
104.18.19.203
48.192.1.64
52.168.112.66
20.50.73.5
150.171.109.107
2.23.246.101
13.33.187.10
104.18.18.203
2.16.164.66
74.178.240.61
48.209.138.189
202.146.222.15
Hashes
388a796580234efc95f3b1c70ad4cb44bfddc7ba0f9203bf4902b9929b136f95
b9fa2d52a4ffabb438b56184131b893b04655b01f336066415d4fe839efe64e7
75da533888189d13fc340d40637b9fc07a3f732e3fcf33ec300f4c7268790a62
907f2709d1d3c8fa26294938f4080bc477e62281c4c50a082c22db0195cda663
22ca9415e294d9c3ec3384b9d08cdaf5164af73b4e4c251559e09e529c843ea6
474d668707f1cb929fef1e3798b71b632e50675bd1a9dceaab90c9587f72f680
3d0361a85adfcd35d0de74135723a75b646965e775188f7dcdd35e3e42db788e
6028bd681dbf11a0a58dde8a0cd884115c04caa59d080ba51bde1b086ce0079d
9c70f766d3b84fc2bb298efa37cc9191f28bec336329cc11468cfadbc3b137f4
eacd09517ce90d34ba562171d15ac40d302f0e691b439f91be1b6406e25f5913
fbcfe23a2ecb82b7100c50811691dde0a33aa3da8d176be9882a9db485dc0f2d
0f1bad70c7bd1e0a69562853ec529355462fcd0423263a3d39d6d0d70b780443
b3ece279943b28c8d855ec86ac1ce53bdfb6a709240d653508764493a75f7518
4ecedb9c1f3dd0d0e3aeb86146561b3d7e58656cbdbed1a39b91737b52ec7f2c
e758273c25fbad804fe884584e2797caefbbd1c2877dfd6f87ab1340cd25252e
3377a873db531113d79919e7a89369a79a602bac6ae09b9864b9378dc285f345
a3eb276fbd19dce2b00db6937578b214b9e33d67487659fe0bf21a86225ece73
a41670d52423ba69c7a65e7e153e7b9994e8dd0370c584bda0714bd61c49c578
54241ebe651a8344235cc47afd274c080abaebc8c3a25afb95d8373b6a5670a2
bbd37d41b7de6f93948fa2437a7699d4c30a3c39e736179702f212cb36a3133c
Domains
settings-win.data.microsoft.com
google.com
activation-v2.sls.microsoft.com
1drv.ms
onedrive.live.com
us-east-2.protection.sophos.com
slscr.update.microsoft.com
self.events.data.microsoft.com
edge.microsoft.com
www.bing.com
res.public.onecdn.static.microsoft
api.edgeoffer.microsoft.com
ecs.office.com
go.microsoft.com
eu-mobile.events.data.microsoft.com
edge-cloud-resource-static.azureedge.net
res-1.cdn.office.net
copilot.microsoft.com
www.microsoft.com
config.edge.skype.com
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/microsoft%20secure%20server%20ca%202026.crl
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:f76unyfslhk6su7-tjaadep8gnez-37juujlvglezza&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
https://copilot.microsoft.com/c/api/user/eligibility
https://us-east-2.protection.sophos.com/?d=1drv%e3%80%82ms/u/c/d75dfb286939ccaf/iqbszusg0wobqy_0ywvbo140adh8w7_-cxmci7odovlaate?e=qxj7nn&jcastro@intermex.com&u=ahr0chm6ly8xzhj244ccbxmvds9jl2q3nwrmyji4njkzownjywyvsvfcu1pvu2cwv29iuvlfmhlxvkjpmtqwqwroohc3xy1jwg1jstdvrg92tefbveu_zt1xwgo3bk4mamnhc3ryb0bpbnrlcm1lec5jb20=&p=m&i=njhknmqyodrkmdfmmtq1mzq1odvkymfk&t=t0r4qupdaw03tgtgk2huulpsyktct0ttywjkbglknkyznwlywkhjs1o4yz0=&h=24a048383e3a41ad8192f1bb3d50fa3a&s=avnpuehut0nftknswvbusvzceqxrtzytpemqvyx8izuuisxq7doqcvo-r8wmo2as6a
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appid=edge-extensions&country=us
https://1drv.ms/u/c/d75dfb286939ccaf/iqbszusg0wobqy_0ywvbo140adh8w7_-cxmci7odovlaate?e=qxj7nn&jcastro@intermex.com
https://onedrive.live.com/:u:/g/personal/d75dfb286939ccaf/iqbszusg0wobqy_0ywvbo140adh8w7_-cxmci7odovlaate?resid=d75dfb286939ccaf!sa04465526ad1411b8ff4c965413b5e34&e=qxj7nn&jcastro%40intermex.com&migratedtospo=true&redeem=ahr0chm6ly8xzhj2lm1zl3uvyy9knzvkzmiyody5mzljy2fml0lrqlnavvnnmfdvylfzxzb5v1zctze0mefkadh3n18ty1hty0k3b0rvdkxbqvrfp2u9cvhqn25ojmpjyxn0cm9aaw50zxjtzxguy29t
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edgeruntime%2cedgeruntimeconfig%2cedgedomainactions&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://onedrive.live.com/?id=d75dfb286939ccaf%21sa04465526ad1411b8ff4c965413b5e34&cid=d75dfb286939ccaf&spopath=%2fpersonal%2fd75dfb286939ccaf%2fdocuments%2fekcyzsyk%2ezip&listurl=%2fpersonal%2fd75dfb286939ccaf%2fdocuments&e=qxj7nn&migratedtospo=true&parent=%2fpersonal%2fd75dfb286939ccaf%2fdocuments&redeem=ahr0chm6ly8xzhj2lm1zl3uvyy9knzvkzmiyody5mzljy2fml0lrqlnavvnnmfdvylfzxzb5v1zctze0mefkadh3n18ty1hty0k3b0rvdkxbqvrfp2u9cvhqn25ojmpjyxn0cm9aaw50zxjtzxguy29t&ga=1
https://www.bing.com/bloomfilterfiles/expandeddomainsfilterglobal.json
https://onedrive.live.com/_layouts/15/spwebworkerproxy.ashx
https://onedrive.live.com/_layouts/15/spwebappmanifest.ashx?app=onedriveconsumer
https://onedrive.live.com/_layouts/15/images/odbfavicon.ico?rev=50
https://onedrive.live.com/_layouts/15/images/onedrive.144x144.png
https://res.public.onecdn.static.microsoft/files/odsp-web-prod_2026-09-04.002/odbspartan/odc-prefetch.js
https://res.public.onecdn.static.microsoft/files/odsp-web-prod_2026-09-04.002/odbspartan/en-us/odc-files.resx.js
https://res.public.onecdn.static.microsoft/files/odsp-web-prod_2026-09-04.002/odbspartan/odcfiles.js
Last Seen at

Recent blog posts

post image
How MSSPs Can Prove Their Value When “Nothing...
watchers 2564
comments 0
post image
Enterprise Threat Intelligence Buying Guide:...
watchers 2932
comments 0
post image
ANY.RUN & SentinelOne: One Workspace, Ins...
watchers 4471
comments 0

What is Danabot banking malware?

Danabot is a banking trojan that was spotted in the wild in 2018. Danabot differs from competing Trojans thanks to its robust delivery system and modular design. Since its first appearance, Danabot has obtained high popularity among cybercriminals and became an active threat in multiple regions of the world.

This malware is constantly updated by the creators, helping the Trojan continue to gain popularity in the hacking community. Danabot is written using the Delphi programming language carries several credential theft functions.

General description of Danabot

When first documented, Danabot malware was being used by just one actor who carried out a campaign against Australian companies. Since then, other malicious actors have started utilizing this malware and expanded the geography of attacks to Europe and North America.

In particular, the Danabot trojan was seen in attacks in Poland, Germany, Italy, Austria, and the US. Particularly, the US campaigns were carried out on a large scale, indicating that the malware is evolving and developing.

As far as the function set of this malware is concerned, Danabot can be classified as a banking trojan, though some of its features suggest that it is becoming a more versatile malware. Danabot is constructed out of three main components. The loader is a program created to download the main payload. The main component, which is installed by the loader, is configured to download the modules that the attacker can specify. Finally, once installed, the modules provide the functionality, which can vary depending on which modules were chosen by the ill-wisher in a particular campaign.

The malware can take screenshots, grant attackers remote control of the victims’ machine, collect system information, steal credentials, and record lists of files stored on infected PCs. Once collected, all information recorded by Danabot is sent to the control server in an encrypted form. Danabot aims to steal sensitive information that can be leveraged by the attackers later, therefore instead of confirming the victim head-on and demanding a ransom. This malware tries to stay hidden and collect valuable data over time. Some of the smaller distribution campaigns featuring Danabot were well made in terms of clever social engineering and carried on with the same philosophy of a more subtle approach.

In addition, researchers noticed that the attackers utilizing Danabot ventured beyond banking credentials theft and started utilizing this banking malware to host other spam and malicious campaigns, using the infected machines of their victims. What’s more, Danabot creators are thought to be collaborating with the group behind a different banking trojan – GootKit. Danabot was recorded as being used to distribute this type of threat. This case is a first for both malicious programs since neither has been distributed or distributed by other malware before.

In January 2019, researchers noticed a new version of the Danabot trojan in the wild. The investigation confirmed the new samples to be the evolution of Danabot, with a different C2 communication protocol that began to use multiple encryption layers and proved very complex. In the new variant, AES and RSA encryption algorithms were employed in particular. On top of that, the core design of the malware was also changed, as the loader was made responsible for downloading all the modules along with the main component. The researchers believe a technique was used to avoid detection on a network level that the attackers could have invented after reading existing analysis material on Danabot.

It should be noted that Danabot features several evasion techniques designed to make research as complicated as possible. For one, the banking malware is loaded with many lines of junk code, implemented solely to mislead the researchers. The malware also uses encryption and Windows API function hashing to fool automated sandboxes and researchers and prevent them from uncovering the true nature of the code.

Malware analysis of Danabot

A video recorded in the ANY.RUN malware hunting service enables us to take a look at Danabot in action.

danabot execution process graph

Figure 1: A process graph generated by ANY.RUN for the convenience of the researchers

text report of the Danabot malware execution

Figure 2: The text report generated by ANY.RUN is created to allow easy sharing of the study results

Danabot banking malware execution process

Typically Danabot trojan infects devices according to the following scenario. First of all, the downloader establishes a connection with the C2 server and downloads an executable file with a DLL file, which can be either 32-bit or 64-bit based on the infected OS version.

After that, Danabot begins stealing information from the infected OS. The banking malware bypasses user access control by using a DLL hijacking vulnerability in the Windows Update Standalone Installer (wusa.exe). This allows Danabot to create services and execute the injection into system processes. After all of these steps, Danabot receives full system control.

How to avoid infection by Danabot?

Danabot is distributed in email spam campaigns targeting organizations and using social engineering to trick victims into downloading malicious documents the same scenario as

Danabot is also known to get into PCs with another malware called Hancitor. Email campaigns featuring Danabot were considered well crafted by some researchers, who noted that social engineering involved seemed very effective.

Communication with C&C

In older samples of Danabot, the loader component used HTTP protocol to communicate with the control server, whereas the main component utilized the binary protocol. In more recent iterations, both components started to communicate with the C2 server over TCP port 443 using TLS instead.

How to detect Danabot using ANY.RUN?

ANY.RUN uses Suricata IDS rule sets, so if malware trying to communicate with C&C servers, it will be detected. To look at what threats were detected, click on the "Threats" section of the "Network" tab.

danabot network threats Figure 3: Danabot's network threats

Conclusion

Danabot is a very sophisticated malicious program used as a banking trojan and more. Targeting organizations across multiple continents, Danabot malware poses a high threat to businesses thanks to robust distribution methods and cutting-edge anti-evasion and persistence techniques.

In addition, the module nature of this banking malware allows attackers to fine-tune their campaigns, customizing them for every potential victim. All these traits combined helped make Danabot a very popular banking trojan that is only continuing to gain traction in the criminal community and further expand the geography of attacks.

To establish a reliable cyber defense, security professionals can utilize malware hunting and analysis services such as ANY.RUN, which allows to dissect malware samples and thoroughly study their behavior and architecture.

HAVE A LOOK AT

DarkComet screenshot
DarkComet
darkcomet rat darkcomet rat
DarkComet RAT is a malicious program designed to remotely control or administer a victim's computer, steal private data and spy on the victim.
Read More
EvilTokens screenshot
EvilTokens
eviltokens
EvilTokens is a phishing-as-a-service (PhaaS) toolkit that emerged in mid-February 2026. It automates device code phishing attacks against Microsoft 365 and Entra ID environments. Unlike traditional credential-harvesting phishing, EvilTokens tricks users into completing legitimate authentication on Microsoft's own login pages, resulting in the issuance of valid OAuth access and refresh tokens directly to the attacker, effectively bypassing MFA without stealing passwords.
Read More
Remote Access Trojan screenshot
Remote access trojans (RATs) are a type of malware that enables attackers to establish complete to partial control over infected computers. Such malicious programs often have a modular design, offering a wide range of functionalities for conducting illicit activities on compromised systems. Some of the most common features of RATs include access to the users’ data, webcam, and keystrokes. This malware is often distributed through phishing emails and links.
Read More
Phantom Stealer screenshot
Phantom Stealer
phantomstealer
Phantom Stealer is a commercially available Malware-as-a-Service infostealer targeting Windows systems. It harvests browser passwords, session cookies, payment data, cryptocurrency wallets, system information, screenshots, and application data.
Read More
AsyncRAT screenshot
AsyncRAT
asyncrat
AsyncRAT is a RAT that can monitor and remotely control infected systems. This malware was introduced on Github as a legitimate open-source remote administration software, but hackers use it for its many powerful malicious functions.
Read More
DEVMAN screenshot
DEVMAN
devman
DEVMAN is a fast-evolving malware family targeting Windows environments with a mix of credential theft, remote control capabilities, and persistence techniques typical of modern crimeware. Initially observed in early 2025, DEVMAN quickly became a favorite tool among cybercriminal groups thanks to its stealth, modular structure, and ability to bypass traditional AV solutions.
Read More