Trojan

What is “Trojan:MSIL/ObsidiumStealer!MTB”?

Malware Removal

The Trojan:MSIL/ObsidiumStealer!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/ObsidiumStealer!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • NtSetInformationThread: attempt to hide thread from debugger
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Checks for the presence of known windows from debuggers and forensic tools
  • CAPE detected the RedLine malware family
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects VirtualBox through the presence of a device
  • Anomalous binary characteristics
  • Binary compilation timestomping detected

How to determine Trojan:MSIL/ObsidiumStealer!MTB?


File Info:

name: 79307B3F34CC3FC127B5.mlw
path: /opt/CAPEv2/storage/binaries/aa222ad68b1c0bf2d7bf5a9b21f4df228c95643380d6f492a16c77168fef89e8
crc32: DE71DB29
md5: 79307b3f34cc3fc127b542a907d8dcb8
sha1: 36ad18e0341de4c472c475b98e357564e39837c6
sha256: aa222ad68b1c0bf2d7bf5a9b21f4df228c95643380d6f492a16c77168fef89e8
sha512: 1e959ed8466597b75002e48512c1e7ffc5123f786d9bb28f244607d2ebfb22f72a22f50c61a45e4c7cd7a3d2bcda9a584e9f18a6573725e4c55195104164c193
ssdeep: 12288:AVdfqWjutRcv9QwmIvIzNtdiKsrk+bsVssPxWXA1l7HGWik3WZXgN:AVdfqEutmywVvIbdiKsrVbsVssJUEcW3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T109C4F16C0B3A488BCC2AD0F9C117C9B936266C3920D6978549F9FE77B572780495E0FE
sha3_384: 204c29343c3c57e556a7c73c05dede8fb11a959cf8a81bb0cb80ecaa3d82d8c5984b5aea91371f0a5d99c6aacd67c1ee
ep_bytes: eb0228aa50eb0563a11203c0e8180000
timestamp: 2059-08-13 16:20:24

Version Info:

FileDescription: Export Plugin for Notepad++, a free (GNU) source code editor
FileVersion: 0.3.0 Unicode
InternalName: Exporter
LegalCopyright: Copyright (C) 2019
OriginalFilename: NppExport.dll
ProductName: NppExport
ProductVersion: 0.3.0
Translation: 0x0409 0x04b0

Trojan:MSIL/ObsidiumStealer!MTB also known as:

MicroWorld-eScanTrojan.GenericKD.48291648
FireEyeGeneric.mg.79307b3f34cc3fc1
CAT-QuickHealTrojanSpy.Stealer
McAfeeRDN/Generic PWS.y
CylanceUnsafe
ZillyaTrojan.Obsidium.Win32.3404
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0058d59f1 )
AlibabaTrojanSpy:Win32/Stealer.c8e8b941
K7GWTrojan ( 0058d59f1 )
Cybereasonmalicious.0341de
CyrenW32/Obsidium.A.gen!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.Obsidium.GL
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan-Spy.Win32.Stealer.bcju
BitDefenderTrojan.GenericKD.48291648
AvastWin32:Trojan-gen
TencentWin32.Trojan-spy.Stealer.Ahem
Ad-AwareTrojan.GenericKD.48291648
SophosMal/Generic-S
ComodoMalware@#exgqtgqpt1sr
DrWebTrojan.PWS.Siggen3.10983
TrendMicroTrojanSpy.Win32.STEALER.USPAXBD22
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.48291648 (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKD.48291648
JiangminTrojanSpy.Stealer.nkh
AviraTR/Spy.Stealer.wahtk
MAXmalware (ai score=84)
Antiy-AVLTrojan[Spy]/Win32.Stealer
KingsoftWin32.Troj.Undef.(kcloud)
GridinsoftRansom.Win32.Wacatac.sa
ZoneAlarmTrojan-Spy.Win32.Stealer.bcju
MicrosoftTrojan:MSIL/ObsidiumStealer!MTB
AhnLab-V3Trojan/Win.RedLineStealer.R471250
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34264.Jq3@aGKzEkki
ALYacTrojan.GenericKD.48291648
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.MalPack.Obsidium
TrendMicro-HouseCallTrojanSpy.Win32.STEALER.USPAXBD22
RisingSpyware.Stealer!8.3090 (CLOUD)
IkarusTrojan.Win32.Obsidium
FortinetW32/Obsidium.FX!tr
WebrootW32.Adware.Gen
AVGWin32:Trojan-gen
PandaGeneric Suspicious
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:MSIL/ObsidiumStealer!MTB?

Trojan:MSIL/ObsidiumStealer!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment