Trojan

Trojan:Win32/Bunitucrypt.RTA!MTB information

Malware Removal

The Trojan:Win32/Bunitucrypt.RTA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Bunitucrypt.RTA!MTB virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Arabic (Syria)
  • The binary likely contains encrypted or compressed data.
  • Attempts to create or modify system certificates
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

tttttt.me
apps.identrust.com

How to determine Trojan:Win32/Bunitucrypt.RTA!MTB?


File Info:

crc32: 50E37596
md5: 3f891f4ea01741d664416c3b34f64208
name: 3F891F4EA01741D664416C3B34F64208.mlw
sha1: 1603618f831c60c59c5748b620c9685f8609e1df
sha256: dd1dea95bf17e3f135d2740e87d8b9f08ccf347e4ff832b9e747f775017ff346
sha512: d25410bb7ef7f2c77921abd0995dc3b3e9e5c751c336831714cc19eec1d47b9eb04df693716bcbd307cc9ca416190b7f0603b1f60d169c9270bf5925cf249fb1
ssdeep: 24576:uscqzDohX1lerbtv1acwAyXIrt2go5pvxM+Yy5X1IVeY27:u4YhQbttyA1r3o5ZxNX1IVeY
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Bunitucrypt.RTA!MTB also known as:

BkavW32.AIDetect.malware2
K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.37118746
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (W)
AlibabaTrojan:Win32/Chapak.5013d3e7
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.f831c6
CyrenW32/Trojan.QYRU-8833
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Spy.Raccoon.A
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyTrojan.Win32.Chapak.ezrb
BitDefenderTrojan.GenericKD.37118746
MicroWorld-eScanTrojan.GenericKD.37118746
Ad-AwareTrojan.GenericKD.37118746
ComodoTrojWare.Win32.UMal.idswt@0
BitDefenderThetaGen:NN.ZelphiF.34744.bHW@aCNQfcpI
McAfee-GW-EditionBehavesLike.Win32.DealPly.tc
FireEyeGeneric.mg.3f891f4ea01741d6
EmsisoftTrojan.GenericKD.46502573 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/AD.StellarStealer.cznhv
eGambitUnsafe.AI_Score_97%
KingsoftWin32.Troj.Chapak.ez.(kcloud)
MicrosoftTrojan:Win32/Bunitucrypt.RTA!MTB
AegisLabTrojan.Multi.Generic.4!c
GDataTrojan.GenericKD.37118746
McAfeeArtemis!3F891F4EA017
MAXmalware (ai score=100)
VBA32BScope.Trojan.Chapak
PandaTrj/CI.A
RisingTrojan.Generic@ML.83 (RDML:cOetzjTltT0FO8eXffJ/GA)
IkarusTrojan.WinGo.Netbounce
MaxSecureTrojan.Malware.300983.susgen
FortinetPossibleThreat.PALLAS.H
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml

How to remove Trojan:Win32/Bunitucrypt.RTA!MTB?

Trojan:Win32/Bunitucrypt.RTA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment