Trojan

Trojan:Win32/Carbanak.MR!MTB (file analysis)

Malware Removal

The Trojan:Win32/Carbanak.MR!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Carbanak.MR!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the shellcode patterns malware family
  • Attempts to modify proxy settings
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Carbanak.MR!MTB?


File Info:

name: 4DC99280459292EF60D6.mlw
path: /opt/CAPEv2/storage/binaries/13b3317567ed7ad620d7e9484246008a6490593159d53e9016a0f5561b19bc09
crc32: AB6CDE19
md5: 4dc99280459292ef60d6d01ed8ece312
sha1: f3f465786038e8944efbb25f428cbd48add9993c
sha256: 13b3317567ed7ad620d7e9484246008a6490593159d53e9016a0f5561b19bc09
sha512: 46ceb4d5908999b787235b1a11eacbcc7cb121943c6fed02b6d8959b77a526455b21a39c924c2944161e99e23fd49e4eebf8b78c1ddcbed700af35870c84abb9
ssdeep: 12288:sENm9K6gMHAisFwF1AZFWD9sPGMVbpMHmX9k9j6NM+ceWyg:sEc9K6gMgisFwF1eWZs+MVbpX9k9j6NO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D4947C2B95D0F223D5F62EB0D728ABB5947F66746F00985A31CE0BA8740CEE0CC65B57
sha3_384: 856099f9a9c563cfa47e052bd5bfe12145c4b51256ad0333c9e6589ecc5b466122f0472c4395a9275dc53abad36db1a6
ep_bytes: e821160000e989feffff8bff558bec8b
timestamp: 2015-12-09 16:26:11

Version Info:

CompanyName: WhatsRunning.net
FileDescription: daycare
FileVersion: 1.2.1.6
InternalName: coppicing.exe
LegalCopyright: Copyright 1 - 1982 - 2005
OriginalFilename: coppicing.exe
ProductVersion: 1.2.1.6
ProductName: engenders
Translation: 0x0409 0x03a4

Trojan:Win32/Carbanak.MR!MTB also known as:

BkavW32.Common.887BDADA
LionicTrojan.Win32.Pakes.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45779577
FireEyeGeneric.mg.4dc99280459292ef
SkyhighTrojan-FQAU!4DC992804592
McAfeeTrojan-FQAU!4DC992804592
MalwarebytesGeneric.Malware/Suspicious
VIPRETrojan.GenericKD.45779577
K7AntiVirusSpyware ( 004efaeb1 )
AlibabaTrojanSpy:Win32/Pakes.11922d1a
K7GWSpyware ( 004efaeb1 )
SymantecTrojan Horse
tehtrisGeneric.Malware
ESET-NOD32Win32/Spy.Agent.OTU
TrendMicro-HouseCallTROJ_FRS.0NA103H318
KasperskyTrojan.Win32.Pakes.auqr
BitDefenderTrojan.GenericKD.45779577
AvastWin32:Malware-gen
TencentWin32.Trojan.Pakes.Jjgl
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1305139
ZillyaAdware.BetterSurf.Win32.11764
TrendMicroTROJ_FRS.0NA103H318
EmsisoftTrojan.GenericKD.45779577 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Pakes.blb
WebrootW32.Trojan.Gen
VaristW32/Agent.KNEJ-1659
AviraHEUR/AGEN.1305139
Antiy-AVLTrojan[APT]/Win32.Fin7
Kingsoftmalware.kb.a.999
MicrosoftTrojan:Win32/Carbanak.MR!MTB
XcitiumMalware@#1j0dpmzygevqt
ArcabitTrojan.Generic.D2BA8A79
ZoneAlarmTrojan.Win32.Pakes.auqr
GDataTrojan.GenericKD.45779577
CynetMalicious (score: 100)
ALYacTrojan.Yakes.Gen
VBA32BScope.Trojan.Pakes
Cylanceunsafe
RisingSpyware.Agent!8.C6 (CLOUD)
IkarusTrojan.Win32.CobaltStrike
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Generic.AP.59BF1!tr
AVGWin32:Malware-gen
Cybereasonmalicious.045929
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Carbanak.MR!MTB?

Trojan:Win32/Carbanak.MR!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment