Backdoor

About “Backdoor:Win32/Remcos!MTB” infection

Malware Removal

The Backdoor:Win32/Remcos!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Remcos!MTB virus can do?

  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Arabic (Qatar)
  • Attempts to remove evidence of file being downloaded from the Internet
  • Code injection with CreateRemoteThread in a remote process
  • Collects information to fingerprint the system

Related domains:

z.whorecord.xyz
a.tomx.xyz
wzefi.duckdns.org

How to determine Backdoor:Win32/Remcos!MTB?


File Info:

crc32: 10DD0345
md5: a07b0a1e30a411eb7b2acff98a07312f
name: upload_file
sha1: 203a1af72a21fafcd06bd545c66a2d28318fdd89
sha256: 7fa4e7e851fd8997ceb6a4b87912523dd682387f70eb840afc01806e08c26c2f
sha512: c0f6a1b8da6944cf7b9d3fa68ee087d53114b586d7b050fcc4bcb8e9aa7533a40c77fc4bf2c90edb0d4bd0d0b757c6dc467e4355e80fe07df52d9d51657e23dc
ssdeep: 1536:10jP7/L1B5rVmN8sxHv2M28ix8EUaJxWZoB4u0OVE01+t:O1VmhaH8EFvW+0OVE0Qt
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x5f00x8feax8feax5f00x5f00x5f00x514bx5409x514bx8feax8feax8feax8feax7ef4x5409x5f00x8feax5f00x8feax5f00x5f00x5409x8feax5f00x514bx5f00x5f00x7ef4x5f00
Assembly Version: 2.3.2.6
FileVersion: 0.5.1.2
CompanyName: x514bx7ef4x514bx7ef4x514bx8feax5409x7ef4x5f00x8feax7ef4x8feax5f00x7ef4x5f00x514bx5409x8feax514bx8feax8feax8feax5f00x8feax8feax5f00x5f00x5409
LegalTrademarks: x8feax514bx7ef4x7ef4x5f00x7ef4x8feax7ef4x7ef4x5f00
Comments: x5f00x8feax5f00x7ef4x5f00x8feax5f00x8feax8feax5f00
ProductName: x5f00x7ef4x5f00x5f00x5409x8feax8feax8feax514bx514bx7ef4x514bx514bx8feax5409x5f00x8feax514bx514bx5409x5f00
ProductVersion: 2.3.2.6
FileDescription: x8feax7ef4x5409x8feax514bx5f00x514bx5f00x5409x5f00
OriginalFilename: x5f00x7ef4x5f00x5f00x5409x8feax8feax8feax514bx514bx7ef4x514bx514bx8feax5409x5f00x8feax514bx514bx5409x5f00.exe
Translation: 0x0409 0x0514

Backdoor:Win32/Remcos!MTB also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ser.Mikey.2127
CAT-QuickHealTrojan.IGENERIC
McAfeeGenericRXLJ-HT!A07B0A1E30A4
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Agentb.4!c
SangforMalware
K7AntiVirusTrojan ( 0019d9b81 )
BitDefenderGen:Variant.Ser.Mikey.2127
K7GWTrojan ( 0019d9b81 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Ser.Mikey.D84F
InvinceaMal/Generic-R
CyrenW32/Antiav.INDT-0919
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.AveMaria-8799014-1
KasperskyTrojan.Win32.Agentb.jiad
AlibabaBackdoor:Win32/Agentb.03d70930
NANO-AntivirusTrojan.Win32.AntiAV.fljpfv
Ad-AwareGen:Variant.Ser.Mikey.2127
EmsisoftGen:Variant.Ser.Mikey.2127 (B)
ComodoTrojWare.Win32.AntiAV.VA@81mmki
F-SecureTrojan.TR/Redcap.ghjpt
DrWebTrojan.PWS.Maria.3
ZillyaTrojan.Agent.Win32.1391531
TrendMicroTrojanSpy.Win32.MOCRT.SM
McAfee-GW-EditionBehavesLike.Win32.Dropper.cm
FireEyeGeneric.mg.a07b0a1e30a411eb
SophosTroj/AntiAV-P
SentinelOneDFI – Malicious PE
JiangminTrojan.Agentb.eab
WebrootW32.Trojan.Gen
AviraTR/Redcap.ghjpt
eGambitTrojan.Generic
MAXmalware (ai score=84)
Antiy-AVLTrojan/Win32.SGeneric
MicrosoftBackdoor:Win32/Remcos!MTB
ZoneAlarmTrojan.Win32.Agentb.jiad
GDataWin32.Backdoor.AveMaria.A
CynetMalicious (score: 100)
VBA32Trojan.Agentb
ALYacGen:Variant.Ser.Mikey.2127
MalwarebytesBackdoor.AveMaria
ESET-NOD32a variant of Win32/Agent.TJS
TrendMicro-HouseCallTrojanSpy.Win32.MOCRT.SM
RisingStealer.AveMaria!1.BA1C (CLASSIC)
YandexTrojan.AntiAV!DUTgE8gwzUM
IkarusTrojan.Win32.Agent
FortinetW32/Agent.TJS!tr
BitDefenderThetaGen:NN.ZexaF.34282.ky0@aq1I2rgi
AVGWin32:Malware-gen
AvastWin32:Malware-gen
Qihoo-360Win32/Trojan.59e

How to remove Backdoor:Win32/Remcos!MTB?

Backdoor:Win32/Remcos!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment