Trojan

Trojan.Redlonam (file analysis)

Malware Removal

The Trojan.Redlonam is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Redlonam virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Redlonam?


File Info:

crc32: 47F0F954
md5: b66ea2403a923c0105ad0559e9f6e53b
name: SWIFT TRANSFER.exe
sha1: c4864e857f383ad6535009a04f5e3b4a7d74e1dc
sha256: ec4ee2fa916e9fc280f06af0ceded7835693723ebbc6c60bd6e371b5d4ad006a
sha512: 6938636c4d34c56d33ceba2d0091e79fdf60dc09541a9d535b4117936d4b100ebd01ea0f31aab39e1a289259ffb5954acf54b6b78129a0eef881c2e683b0fc6b
ssdeep: 6144:dJ+DGUJeaJzbY6mLTA+Fbg3Bhkecvoo0oT9p9weRI6sXZ4LGWeuWiKASr:D3taJz01H5gceyouTSeRI5p4KWaiW
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

Trojan.Redlonam also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.44004867
CAT-QuickHealTrojanpws.Msil
McAfeeGenericRXMC-SE!B66EA2403A92
MalwarebytesTrojan.Redlonam
AegisLabTrojan.MSIL.Coins.i!c
SangforMalware
K7AntiVirusTrojan ( 0056f8bf1 )
BitDefenderTrojan.GenericKD.44004867
K7GWTrojan ( 0056f8bf1 )
Cybereasonmalicious.57f383
TrendMicroTrojanSpy.MSIL.COINS.USMANJ820
CyrenW32/MSIL_Kryptik.BPM.gen!Eldorado
SymantecTrojan Horse
APEXMalicious
AvastWin32:PWSX-gen [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-PSW.MSIL.Coins.gen
AlibabaTrojanPSW:Win32/Formbook.de980a42
NANO-AntivirusTrojan.Win32.Coins.hyzrff
ViRobotTrojan.Win32.S.Agent.502272.DU
Ad-AwareTrojan.GenericKD.44004867
SophosTroj/Formbok-IY
ComodoMalware@#tes7zs2uf0yo
F-SecureTrojan.TR/Kryptik.rjdvg
DrWebTrojan.PackedNET.276
VIPRETrojan.Win32.Generic!BT
InvinceaMal/Generic-R + Troj/Formbok-IY
McAfee-GW-EditionGenericRXMC-SE!B66EA2403A92
EmsisoftTrojan.GenericKD.44004867 (B)
IkarusTrojan.MSIL.Injector
JiangminTrojan.PSW.MSIL.atcg
WebrootW32.Malware.Gen
AviraTR/Kryptik.rjdvg
MicrosoftTrojan:MSIL/Stealer.DR!MTB
ArcabitTrojan.Generic.D29F7603
ZoneAlarmHEUR:Trojan-PSW.MSIL.Coins.gen
GDataTrojan.GenericKD.44004867
AhnLab-V3Malware/Win32.RL_Generic.C4203002
BitDefenderThetaGen:NN.ZemsilF.34566.Em0@a0z4Aal
ALYacTrojan.Agent.FormBook
MAXmalware (ai score=100)
VBA32TScope.Trojan.MSIL
PandaTrj/GdSda.A
ESET-NOD32Win32/Formbook.AA
TrendMicro-HouseCallTrojanSpy.MSIL.COINS.USMANJ820
YandexTrojan.Igent.bUAoJ7.33
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_68%
FortinetMSIL/Kryptik.SHS!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Redlonam?

Trojan.Redlonam removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment