Trojan

About “Trojan:Win32/Glupteba.ASG!MTB” infection

Malware Removal

The Trojan:Win32/Glupteba.ASG!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Glupteba.ASG!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Sindhi
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization

How to determine Trojan:Win32/Glupteba.ASG!MTB?


File Info:

name: 2E6F3BDB0A29CD63689A.mlw
path: /opt/CAPEv2/storage/binaries/cccbb68975eabf958a5868a55f0e25a7a758728c0a81f742fa16f8e6fe59d0ce
crc32: 1B82A3FB
md5: 2e6f3bdb0a29cd63689afd2a0164f665
sha1: 79345a852e56bc5744931452c24ca632c6359cc3
sha256: cccbb68975eabf958a5868a55f0e25a7a758728c0a81f742fa16f8e6fe59d0ce
sha512: 9c5f3f4d21492f37cd1fa84930c7ad7ddcf8d39fbf355f8975e319840edc9070dece1603ee64a7051a9a07583411c6b4cf51add8ffc23064e9f00a41e5127919
ssdeep: 3072:9KAXqmRVsicmhBfVn7S7RR49YwWjlnbI1vB8kh36Cebkc:9ZX3cmhBfNWL49YpnM9CHC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F0F3CF563FE294B1E0B7423129B4CB621A7F74722771459F77A41A7E0F603C0AAB9327
sha3_384: c88680a60c63ad9ed843f6fcde10da4cdbde53cc8f0f6aba0020942fd971c2fec158a6eea541f78bb7cb737d407101c5
ep_bytes: e89b410000e989feffff8bff558bec51
timestamp: 2023-04-30 23:16:49

Version Info:

InternalName: Octupubrefestival.exe
LegalTrademark1: Clavion
LegalTrademarks2: Gunshut
OriginalFilename: Marabegda.exe
ProductVersion: 1.25.86.34
Translation: 0x0708 0x04e3

Trojan:Win32/Glupteba.ASG!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Convagent.m!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Mint.Zard.2
ClamAVWin.Malware.Pwsx-10012872-0
FireEyeGeneric.mg.2e6f3bdb0a29cd63
SkyhighBehavesLike.Win32.Lockbit.cc
McAfeeArtemis!2E6F3BDB0A29
Cylanceunsafe
ZillyaTrojan.Kryptik.Win32.4353600
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005ad4041 )
AlibabaBackdoor:Win32/Glupteba.6698933b
K7GWTrojan ( 005ad4041 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HVCG
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Agent.gen
BitDefenderGen:Variant.Mint.Zard.2
NANO-AntivirusTrojan.Win32.Convagent.kcxypj
AvastWin32:PWSX-gen [Trj]
TencentTrojan.Win32.Obfuscated.gen
EmsisoftGen:Variant.Mint.Zard.2 (B)
F-SecureTrojan.TR/AD.SmokeLoader.biyvq
DrWebTrojan.DownLoader46.27250
VIPREGen:Variant.Mint.Zard.2
Trapminemalicious.high.ml.score
SophosTroj/Krypt-ACJ
IkarusTrojan.Win32.Ranumbot
GDataGen:Variant.Mint.Zard.2
JiangminTrojanSpy.Windigo.ame
VaristW32/Kryptik.LAC.gen!Eldorado
AviraTR/AD.SmokeLoader.biyvq
Antiy-AVLTrojan[Backdoor]/Win32.Convagent
KingsoftWin32.Hack.Convagent.gen
ArcabitTrojan.Mint.Zard.2
ZoneAlarmHEUR:Trojan.Win32.Agent.gen
MicrosoftTrojan:Win32/Glupteba.ASG!MTB
GoogleDetected
AhnLab-V3Trojan/Win.TrojanX-gen.R618542
Acronissuspicious
ALYacGen:Variant.Mint.Zard.2
MAXmalware (ai score=89)
VBA32Malware-Cryptor.Azorult.gen
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
RisingTrojan.ShellCodeRunner!1.F244 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.110133250.susgen
FortinetW32/Kryptik.HVCD!tr
AVGWin32:PWSX-gen [Trj]
Cybereasonmalicious.52e56b
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Glupteba.ASG!MTB?

Trojan:Win32/Glupteba.ASG!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment