Trojan

Trojan:Win32/Glupteba.DA!MTB information

Malware Removal

The Trojan:Win32/Glupteba.DA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Glupteba.DA!MTB virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Serbian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the DanaBot malware family

How to determine Trojan:Win32/Glupteba.DA!MTB?


File Info:

name: 0AB56432940A17F3A811.mlw
path: /opt/CAPEv2/storage/binaries/86bab39a6d50a11e8733e6f4b3b365daeed69a31cbd99d8c6334ec42e65796f3
crc32: F2E2909D
md5: 0ab56432940a17f3a811b38ddfbbb27a
sha1: 61b3907a1664b684444c8c082c35caba94292fdb
sha256: 86bab39a6d50a11e8733e6f4b3b365daeed69a31cbd99d8c6334ec42e65796f3
sha512: 6419b9dc84e26bff7baf4dc7e13c10937aa47d5f562f96f234c7fda0acd29780ebcbba7f2e7a226892e295fd54d7778edf9228b47d55a5fe4fd7b3790b6745c8
ssdeep: 24576:u/nFeB4SCkco2x8jI8XmSKaPbVZ3C00J8HkWYfPrDWlI20:u/FI4S3co2Sc8WybZHRkGax
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B23522213580E733C59A12704874DAA4FF72AC75ADA56A47373473AEAF303D065BB34A
sha3_384: 8c7e86601ac74b4ac87e234af62817c3897e05ca7d65820f26c7c1a0ac7aa9de253faa64c235138eb11d99c7b1d41488
ep_bytes: e89c660000e978feffff8bff558bec51
timestamp: 2020-02-09 16:17:20

Version Info:

InternalName: kogzmuahoke.exi
Copyright: Copyrighz (C) 2020, vodkaguts
ProductVersion: 91.78.38.10
Translation: 0x0483 0x011e

Trojan:Win32/Glupteba.DA!MTB also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Agent.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
McAfeeArtemis!0AB56432940A
CylanceUnsafe
SangforRansom.Win32.Gandcrab_66.se2
K7AntiVirusTrojan ( 00576f791 )
BitDefenderGen:Heur.Variadic.A.396.1
K7GWTrojan ( 00576f791 )
CrowdStrikewin/malicious_confidence_90% (W)
CyrenW32/Kryptik.EUY.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HLYB
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Dropper.Babar-9883606-0
KasperskyUDS:DangerousObject.Multi.Generic
AlibabaTrojan:Win32/Raccrypt.20f64a59
MicroWorld-eScanGen:Heur.Variadic.A.396.1
AvastWin32:PWSX-gen [Trj]
RisingTrojan.Kryptik!1.B40D (CLASSIC)
Ad-AwareGen:Heur.Variadic.A.396.1
EmsisoftGen:Heur.Variadic.A.396.1 (B)
F-SecureTrojan.TR/Crypt.Agent.xbvzf
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R03FC0DH521
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.0ab56432940a17f3
SophosMal/Generic-S + Mal/Agent-AWV
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Chapak.nel
AviraTR/Crypt.Agent.xbvzf
Antiy-AVLTrojan/Win32.Kryptik
MicrosoftTrojan:Win32/Glupteba.DA!MTB
ArcabitTrojan.Variadic.A.396.1
GDataWin32.Trojan.BSE.1ATWZKQ
AhnLab-V3Trojan/Win.Hynamer.R435479
Acronissuspicious
ALYacGen:Heur.Variadic.A.396.1
MAXmalware (ai score=86)
VBA32BScope.Trojan.Azorult
MalwarebytesTrojan.MalPack.GS
TrendMicro-HouseCallTROJ_GEN.R03FC0DH521
TencentWin32.Trojan.Generic.Hyz
YandexTrojan.Kryptik!4cuXse+Qi0I
IkarusTrojan-Spy.MSIL.Agent
FortinetW32/Kryptik.HLZT!tr
AVGWin32:PWSX-gen [Trj]
Cybereasonmalicious.a1664b
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan:Win32/Glupteba.DA!MTB?

Trojan:Win32/Glupteba.DA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment