Trojan

TrojanDownloader:Win32/Brantall.B malicious file

Malware Removal

The TrojanDownloader:Win32/Brantall.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Brantall.B virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • CAPE detected the shellcode get eip malware family
  • Collects information to fingerprint the system
  • Yara detections observed in process dumps, payloads or dropped files

How to determine TrojanDownloader:Win32/Brantall.B?


File Info:

name: D3249D4BF8D47B3831FB.mlw
path: /opt/CAPEv2/storage/binaries/e883f9218b9d8d758e58f47a47296726d14e29a13238dd236fdea5ddf68f6161
crc32: DCE9BB09
md5: d3249d4bf8d47b3831fb7abe52560410
sha1: 1efbb90dd4a5def82a20d50da908f14d4a378a01
sha256: e883f9218b9d8d758e58f47a47296726d14e29a13238dd236fdea5ddf68f6161
sha512: 050832bab2d33fda30794c95b1e186650bfc2b43cf366befd4d4a32aebd593feed64d96d7a79fbc9876330a725acd535d6098ccf6784af169494986f74656cd6
ssdeep: 12288:kzJD2HBryBhGFe4JzRp81Mj+KZzd0BmnsgMc02Fmxfg:ABhYJzR/+oEdh2FmNg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T161C401917BD2D1FEC05719326635E5E1C9B9F4B22AB441BBB3490B6E2F683D2413E243
sha3_384: fb22ac7ba3b4adf8431e5514a54f74614034996394a10a046a6fe14e92e9a6b512ad9791dbdb82279af6b05eb6f0f753
ep_bytes: e8ad440000e989feffff6a0c68c0fa41
timestamp: 2012-12-06 08:07:50

Version Info:

FileVersion: 14.12.8.9
ProductVersion: 14.12.8.9
OriginalFilename: installer.exe
InternalName: installer
FileDescription: Installer
CompanyName:
LegalCopyright: Copyright 2012
ProductName: Installer
LegalTrademarks:
Translation: 0x0409 0x04b0

TrojanDownloader:Win32/Brantall.B also known as:

BkavW32.AIDetectMalware
LionicAdware.Win32.BrainInst.myT8
tehtrisGeneric.Malware
MicroWorld-eScanApplication.Bundler.InstallBrain.A
FireEyeGeneric.mg.d3249d4bf8d47b38
CAT-QuickHealTrojanDownloader.Brantall.A5
SkyhighArtemis!Trojan
McAfeeArtemis!D3249D4BF8D4
Cylanceunsafe
ZillyaAdware.BrainInst.Win32.8
SangforTrojan.Win32.Save.a
CrowdStrikewin/grayware_confidence_100% (W)
AlibabaAdWare:Win32/InstallBrain.945c7e0c
K7GWUnwanted-Program ( 005878d71 )
K7AntiVirusUnwanted-Program ( 005878d71 )
ArcabitApplication.Bundler.InstallBrain.A
BaiduWin32.Adware.InstallBrain.d
VirITAdware.Win32.IBUpdater.C
SymantecSMG.Heur!gen
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/InstallBrain.P potentially unwanted
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Adware.Installbrain-2943
Kasperskynot-a-virus:AdWare.Win32.BrainInst.u
BitDefenderApplication.Bundler.InstallBrain.A
NANO-AntivirusRiskware.Win32.BrainInst.flzbug
SUPERAntiSpywareAdware.InstallBrain/Variant
AvastWin32:InstallBrain-BV [PUP]
SophosInstallBrain (PUA)
F-SecureTrojan:W32/InstallBrain.A
DrWebAdware.Downware.1295
VIPREApplication.Bundler.InstallBrain.A
TrendMicroTROJ_GEN.R002C0DLS23
Trapminemalicious.high.ml.score
EmsisoftApplication.Downloader (A)
SentinelOneStatic AI – Malicious PE
JiangminAdWare/BrainInst.ab
WebrootW32.Adware.Installbrain
VaristW32/A-f24df422!Eldorado
AviraPUA/InstallBrain.Gen7
Antiy-AVLGrayWare[AdWare]/Win32.BrainInst.u
KingsoftWin32.Troj.BrainInst.u
XcitiumApplication.Win32.InstallBrain.KP@5rw6fi
MicrosoftTrojanDownloader:Win32/Brantall.B
ViRobotAdware.Installbrain.574176.A
ZoneAlarmnot-a-virus:AdWare.Win32.BrainInst.u
GDataWin32.Application.InstallBrain.B
GoogleDetected
AhnLab-V3PUP/Win32.InstallBrain.R300358
Acronissuspicious
BitDefenderThetaGen:NN.ZexaCO.36744.Ju1@amVQ!yli
ALYacApplication.Bundler.InstallBrain.A
MAXmalware (ai score=100)
VBA32BScope.Adware.BrainInst
MalwarebytesGeneric.Malware.AI.DDS
PandaPUP/Ibups
TrendMicro-HouseCallTROJ_GEN.R002C0DLS23
RisingTrojan.DL.Win32.Brantall.a (CLASSIC)
YandexTrojan.GenAsa!8pq9e7dda84
Ikarusnot-a-virus:AdWare.Win32.BrainInst
MaxSecurenot-a-virus:Adware.InstallBrain
FortinetAdware/InstallBrain.OP
AVGWin32:InstallBrain-BV [PUP]
DeepInstinctMALICIOUS

How to remove TrojanDownloader:Win32/Brantall.B?

TrojanDownloader:Win32/Brantall.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment