Trojan

About “Trojan:Win32/Downloader.RPJ!MTB” infection

Malware Removal

The Trojan:Win32/Downloader.RPJ!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Downloader.RPJ!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Checks adapter addresses which can be used to detect virtual network interfaces
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Created a process from a suspicious location
  • Attempts to modify proxy settings

How to determine Trojan:Win32/Downloader.RPJ!MTB?


File Info:

name: C43239B65624449D663B.mlw
path: /opt/CAPEv2/storage/binaries/4b12c2dfbbf5eb336903507d02094d3a871c429da40c2c8fb958231ecef76b38
crc32: B51BBE01
md5: c43239b65624449d663b38803a52bb06
sha1: d3fd57fa1322f6b33534fcb5c517a84e8cd0fbc8
sha256: 4b12c2dfbbf5eb336903507d02094d3a871c429da40c2c8fb958231ecef76b38
sha512: 464ffbc40f4c16df32724738dc90f5630eb1ad045f862c023c06f6e3e6ba95a79f43dabd91e6c6a3c0b313c5920236cce4cde9f70a93829375844dc37587dce0
ssdeep: 768:qrUhl79KVCwti4+l9G+HtdgI2MyzNORQtOflIwoHNV2XBFV72BOlA7ZsUI+psm2:qrUn8d+1tdgI2MyzNORQtOflIwoHNV23
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A1C2F7A0E682A8C4D4532977F97BE7C05A17BEDD7422D30C2AD8BD59C6F72817086C1B
sha3_384: 608b6f6a382b257f197d6d6e7d71c557b1a593811ecdba1a9559c7c25a89b7c4f56c092a57056a348c5e6215a916df34
ep_bytes: e803dcffff50e86b000000cccccccccc
timestamp: 2013-09-13 10:52:22

Version Info:

0: [No Data]

Trojan:Win32/Downloader.RPJ!MTB also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanTrojan.GenericKD.1261896
FireEyeGeneric.mg.c43239b65624449d
CAT-QuickHealTrojanPWS.Zbot.KL5
ALYacTrojan.GenericKD.1261896
CylanceUnsafe
VIPRETrojan.GenericKD.1261896
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0001140e1 )
K7GWTrojan ( 0001140e1 )
Cybereasonmalicious.656244
VirITTrojan.Win32.Zbot.BMI
CyrenW32/Trojan.EUVE-3793
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDownloader.Small.PRL
APEXMalicious
ClamAVWin.Downloader.Upatre-5744092-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKD.1261896
NANO-AntivirusTrojan.Win32.DownLoad3.cixiqv
SUPERAntiSpywareTrojan.Agent/Gen-Zbot
AvastWin32:Agent-ASIO [Trj]
TencentMalware.Win32.Gencirc.10b31b52
Ad-AwareTrojan.GenericKD.1261896
EmsisoftTrojan.GenericKD.1261896 (B)
ComodoTrojWare.Win32.Bublik.BEU@523vay
DrWebTrojan.DownLoad3.28507
ZillyaTrojan.Bublik.Win32.12059
TrendMicroTSPY_ZBOT.UJJ
McAfee-GW-EditionPWSZbot-FFA!C43239B65624
Trapminemalicious.moderate.ml.score
SophosML/PE-A + Troj/DwnLdr-LBE
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKD.1261896
JiangminTrojan/Bublik.fye
AviraTR/Inject.JEH.1
MAXmalware (ai score=87)
Antiy-AVLTrojan/Generic.ASBOL.C6E4
ArcabitTrojan.Generic.D134148
MicrosoftTrojan:Win32/Downloader.RPJ!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Bublik.C196976
McAfeePWSZbot-FFA!C43239B65624
VBA32Trojan.FakePdf.16907
MalwarebytesGeneric.Trojan.Dropper.DDS
TrendMicro-HouseCallTSPY_ZBOT.UJJ
RisingDownloader.Waski!1.A489 (CLASSIC)
YandexTrojan.Agent!ZuWxWPCCvxw
IkarusTrojan.Win32.Bublik
MaxSecureTrojan.Upatre.Gen
FortinetW32/Bublik.BEUK!tr
BitDefenderThetaAI:Packer.5DF053BA1F
AVGWin32:Agent-ASIO [Trj]
PandaGeneric Suspicious
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan:Win32/Downloader.RPJ!MTB?

Trojan:Win32/Downloader.RPJ!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment