Trojan

Trojan:Win32/GhostRAT.MA!MTB (file analysis)

Malware Removal

The Trojan:Win32/GhostRAT.MA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/GhostRAT.MA!MTB virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine Trojan:Win32/GhostRAT.MA!MTB?


File Info:

name: B08493D92FB6001297AE.mlw
path: /opt/CAPEv2/storage/binaries/665966c75c327082b910b72c5fdca99a0029633eed52516a4c122836156c545c
crc32: FE6ECA60
md5: b08493d92fb6001297aeba89fd43a5a2
sha1: ea62bb6bde8817ab6f8dbf962b7efbfc4faa5f40
sha256: 665966c75c327082b910b72c5fdca99a0029633eed52516a4c122836156c545c
sha512: a71532454014b7a3f8a679f04c773a69c532856b6f3c07f02e08982ccfa1a8a9e407e4f6f9928a4eb512b772f99eb80b5578e1de7eef8cb391f9decbc8f8413a
ssdeep: 24576:MUc0H4ynjkQoP22LsRRqNuCPsAjeDeeFmaxUKRSwFrke68EeP69p3D/C17JvZGkT:I0Tjk//LsRRqLrHeHRSTePUTC17JJT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11DB59F03B19680F1D16D053444666736AB769F960F349BCFA3A8EEBE1D322D1673324B
sha3_384: 2240d5df2552c54fe6a7e1f58e172fcf9c5c77d8f48e38071b654aae6bdf8a433f089f06896009a1a953b375b294cc08
ep_bytes: 558bec6aff6870fe610068c4b7470064
timestamp: 2023-12-12 05:33:35

Version Info:

0: [No Data]

Trojan:Win32/GhostRAT.MA!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Multi.Generic.muUy
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Application.Graftor.730190
SkyhighBehavesLike.Win32.Generic.vh
McAfeeArtemis!B08493D92FB6
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Application.Graftor.730190
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojan:Win32/GhostRAT.19e7a590
K7GWTrojan ( 005246d51 )
K7AntiVirusTrojan ( 005246d51 )
ArcabitTrojan.Application.Graftor.DB244E
BitDefenderThetaGen:NN.ZexaF.36680.tsW@ayg0!3cb
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
CynetMalicious (score: 100)
APEXMalicious
KasperskyUDS:Trojan-GameThief.Win32.Magania.ugbc
BitDefenderGen:Variant.Application.Graftor.730190
NANO-AntivirusTrojan.Win32.Sdbot.kfhyhx
AvastWin32:Evo-gen [Trj]
RisingTrojan.Generic@AI.99 (RDML:+7qhSKRuHpAaHEUWNVpBbw)
EmsisoftGen:Variant.Application.Graftor.730190 (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebBackDoor.IRC.Sdbot.34261
ZillyaTrojan.Magania.Win32.75305
TrendMicroTROJ_GEN.R011C0DLE23
SophosMal/Generic-S
IkarusTrojan.Agent
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.FlyStudio.a
KingsoftWin32.Troj.Undef.a
XcitiumWorm.Win32.Dropper.RA@1qraug
MicrosoftTrojan:Win32/GhostRAT.MA!MTB
ZoneAlarmUDS:Trojan-GameThief.Win32.Magania.ugbc
GDataWin32.Application.PSE.1OV7PVV
VaristW32/S-480dd005!Eldorado
Acronissuspicious
VBA32BScope.Trojan.Tiggre
ALYacGen:Variant.Application.Graftor.730190
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R011C0DLE23
YandexTrojan.GenAsa!NDFzMdZeW+8
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/CoinMiner.PHP!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.bde881
DeepInstinctMALICIOUS

How to remove Trojan:Win32/GhostRAT.MA!MTB?

Trojan:Win32/GhostRAT.MA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment