Trojan

TrojanDownloader:Win32/Rezona.RA!MTB (file analysis)

Malware Removal

The TrojanDownloader:Win32/Rezona.RA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Rezona.RA!MTB virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • A HTTP/S link was seen in a script or command line
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Collects and encrypts information about the computer likely to send to C2 server
  • PowerShell attempted to make a network connection
  • Creates a hidden or system file
  • Attempts to execute suspicious powershell command arguments
  • Anomalous binary characteristics

How to determine TrojanDownloader:Win32/Rezona.RA!MTB?


File Info:

name: 03A0F4D053A0199B8F4D.mlw
path: /opt/CAPEv2/storage/binaries/9bdb36f278215efa9c4ac5341caf308e5a0f0af477a187ba12502b28498af459
crc32: 0201D0FC
md5: 03a0f4d053a0199b8f4d99556d3e581d
sha1: 1b7c8869d1e6d08a828df41bfd3dccde826f4e34
sha256: 9bdb36f278215efa9c4ac5341caf308e5a0f0af477a187ba12502b28498af459
sha512: 1ef270dc826ca67210c1956ded98ce0bf7f2ef5a6847e1ee3f52e04cd04630cb505d133d0cdbcbc5ba7a15ab06f4403bf9a3ef89d9a4a08b028fd11bbb75a185
ssdeep: 6144:U0qq8S/1MW5WqEomz38WH6maci2ywi2WqxCTVtNOFq4mAqrWowoJpr0:XHqnHLLXa5UGNtTvfdwoM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A8647DA0F652FAFAE8598FB924F1170942DFD685E71CE9373950FE2C006961C8373989
sha3_384: 4f6c360d5490d7d8cffc80420015fe1a7e60ccbc0540168e67012cf255414dca19027497d554656315a33d9f4e98ca73
ep_bytes: 83ec0cc7059453400001000000e88e01
timestamp: 2020-08-01 15:39:31

Version Info:

0: [No Data]

TrojanDownloader:Win32/Rezona.RA!MTB also known as:

LionicTrojan.Win32.Agent.trzt
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Graftor.942915
MalwarebytesMalware.AI.3406183710
ZillyaTrojan.Generic.Win32.1401838
SangforTrojan.Win32.Generic.ky
CrowdStrikewin/malicious_confidence_60% (W)
BitDefenderGen:Variant.Graftor.942915
K7GWTrojan ( 0056702f1 )
K7AntiVirusTrojan ( 0056702f1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.LTPGMF
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojanDownloader:Win32/Rezona.d65547cc
NANO-AntivirusTrojan.Win32.Powerless.hlkxrx
MicroWorld-eScanGen:Variant.Graftor.942915
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.BitCoinMiner.la
Ad-AwareGen:Variant.Graftor.942915
EmsisoftGen:Variant.Graftor.942915 (B)
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.ZeroAccess.fh
FireEyeGeneric.mg.03a0f4d053a0199b
SophosMal/Generic-S
IkarusTrojan.Win32.Powerless
GDataGen:Variant.Graftor.942915
JiangminTrojanDownloader.Agent.fwop
AviraTR/Redcap.gbmnk
MAXmalware (ai score=80)
Antiy-AVLTrojan/Generic.ASMalwS.3319E88
ArcabitTrojan.Graftor.DE6343
MicrosoftTrojanDownloader:Win32/Rezona.RA!MTB
AhnLab-V3Malware/Win32.RL_Generic.R294133
McAfeeGenericRXKP-TN!03A0F4D053A0
VBA32BScope.Trojan.Downloader
CylanceUnsafe
RisingTrojan.Powerless!1.C17B (CLASSIC)
YandexTrojan.GenAsa!i4lkbKR8ap8
SentinelOneStatic AI – Suspicious PE
eGambitTrojan.Generic
FortinetW32/PossibleThreat
BitDefenderThetaGen:NN.ZexaF.34294.u8W@aGRaujj
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.053a01
PandaTrj/GdSda.A
MaxSecureTrojan.Malware.300983.susgen

How to remove TrojanDownloader:Win32/Rezona.RA!MTB?

TrojanDownloader:Win32/Rezona.RA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment