Spy Trojan

What is “TrojanSpy:Win32/Rebhip.E”?

Malware Removal

The TrojanSpy:Win32/Rebhip.E is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:Win32/Rebhip.E virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Creates known SpyNet mutexes and/or registry changes.
  • Yara detections observed in process dumps, payloads or dropped files

How to determine TrojanSpy:Win32/Rebhip.E?


File Info:

name: 5A4F1505EA2D481EA57E.mlw
path: /opt/CAPEv2/storage/binaries/c0a888a162b02134e9d665af56d121c39da4e89d0051043f13c12496a5a17158
crc32: 42FBA547
md5: 5a4f1505ea2d481ea57e6c5011fc0be4
sha1: e29ac5ffaca37308396e33abaec09abb76c7093a
sha256: c0a888a162b02134e9d665af56d121c39da4e89d0051043f13c12496a5a17158
sha512: 26ac973474bf515a74359892bcb25bc4f0c6c2025a3434ed0670e4441a8bb978d0b0fbd410b7efcec592ef1a6117588d67eeb9b4d4dccae6d1d75b6f95954da9
ssdeep: 6144:m7uOGsfZ4iel4j+SLPvgAAiSi+L634Y1m1JRTRzNVA4OXyF9CTDtP9Um3Ivazghq:Qwsfepl2PvgAZ59+BvCT5PiRvMqE7/
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T10AA4237EB78005F2C24C9B73712B25E2509698F1A0BED171B62D7E6DB2AD03D7466F01
sha3_384: 78418aba13fe15012614bce5d71d8465f6f87bdfc2299632aac69e7a5262e03761f821bf628e2d33299b1c5fe3de4c7b
ep_bytes: 807c2408010f85d901000060be005045
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

TrojanSpy:Win32/Rebhip.E also known as:

BkavW32.AIDetectMalware
Elasticmalicious (moderate confidence)
MicroWorld-eScanDeepScan:Generic.MSIL.PasswordStealerA.6868FC70
ClamAVWin.Malware.SpyNet-9945002-1
FireEyeGeneric.mg.5a4f1505ea2d481e
SkyhighBehavesLike.Win32.PolyPatch.gc
McAfeeGenericRXAA-FA!5A4F1505EA2D
Cylanceunsafe
ZillyaTrojan.Buzus.Win32.34514
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojanSpy:Win32/Buzus.e02cdeef
K7GWSpyware ( 0055e3db1 )
K7AntiVirusSpyware ( 0055e3db1 )
ArcabitDeepScan:Generic.MSIL.PasswordStealerA.6868FC70
BitDefenderThetaAI:Packer.83BEA8AA19
VirITTrojan.Win32.Generic.CNDV
SymantecInfostealer
tehtrisGeneric.Malware
ESET-NOD32Win32/Spy.Delf.NYS
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Buzus.xyjy
BitDefenderDeepScan:Generic.MSIL.PasswordStealerA.6868FC70
NANO-AntivirusTrojan.Win32.Buzus.bslrq
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.10bdce6a
EmsisoftDeepScan:Generic.MSIL.PasswordStealerA.6868FC70 (B)
BaiduWin32.Trojan-Spy.Delf.a
F-SecureTrojan.TR/Spy.Gen
DrWebTrojan.PWS.Multi.217
VIPREDeepScan:Generic.MSIL.PasswordStealerA.6868FC70
TrendMicroTROJ_DELF.SMA
Trapminemalicious.moderate.ml.score
SophosTroj/Delf-FFJ
IkarusBackdoor.Win32.Havar
JiangminTrojan/Buzus.bpcq
GoogleDetected
AviraTR/Spy.Gen
Antiy-AVLTrojan/Win32.Buzus
KingsoftWin32.Trojan.Buzus.xyjy
XcitiumTrojWare.Win32.Buzus.jsoa@2091b1
MicrosoftTrojanSpy:Win32/Rebhip.E
ViRobotTrojan.Win32.Buzus.316928.A[UPX]
ZoneAlarmTrojan.Win32.Buzus.xyjy
GDataDeepScan:Generic.MSIL.PasswordStealerA.6868FC70
VaristW32/Injector.A.gen!Eldorado
AhnLab-V3Trojan/Win32.Buzus.R3150
Acronissuspicious
VBA32Trojan.Buzus
ALYacDeepScan:Generic.MSIL.PasswordStealerA.6868FC70
MAXmalware (ai score=100)
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_DELF.SMA
RisingWorm.Rebhip!8.B31 (TFE:5:0jc0QllyaOV)
YandexTrojan.GenAsa!1SJdXQBhTZs
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.9740308.susgen
FortinetW32/Buzus.GS!tr
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS

How to remove TrojanSpy:Win32/Rebhip.E?

TrojanSpy:Win32/Rebhip.E removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment