Trojan

Trojan:Win32/Glupteba.DC!MTB (file analysis)

Malware Removal

The Trojan:Win32/Glupteba.DC!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Glupteba.DC!MTB virus can do?

  • Sample contains Overlay data
  • Unconventionial language used in binary resources: Serbian
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/Glupteba.DC!MTB?


File Info:

name: E88D353B3181FC223D68.mlw
path: /opt/CAPEv2/storage/binaries/7f7cec87fc0d73c7317138321184853bf5014709be783dd29fa39d663df7ebb1
crc32: 311F7DAA
md5: e88d353b3181fc223d68290e6debbf8a
sha1: ad723d0d99496bb77f2bc3bf6063f91306c4b53e
sha256: 7f7cec87fc0d73c7317138321184853bf5014709be783dd29fa39d663df7ebb1
sha512: 5d4b3fa88eebf6b347e7c4e9ccd43c37bc245e3c76655c0269d13fa200a575ac97dda72ed2d16d0afd4774e03e5ed0ac7e26e75feac6fd4a008f3f4ea7694df5
ssdeep: 6144:LCiHGSfM+R5dbH/ILytiLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLp:95fMWbLCyU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C6A67F81B6DCEC66D9D746309838C6E96576FCD68D15528BF0983F1F3CB2EC229B0261
sha3_384: 53657031d5b905b861d04fe6d67d06a9f812873f8ecb8f371b423b41e17c05616dfbca0177ff5e82c0bbc0e4170e23e7
ep_bytes: e868500000e978feffffcccccccccccc
timestamp: 2020-03-22 12:13:28

Version Info:

FileV: 44.0.0.55
Translations: 0x0119 0x0799

Trojan:Win32/Glupteba.DC!MTB also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Siggen10.25703
MicroWorld-eScanGen:Heur.Mint.Dreidel.@tW@yu81WwlG
FireEyeGeneric.mg.e88d353b3181fc22
CAT-QuickHealTrojan.AntiavRI.S15903400
McAfeeLockbit-FSUC!E88D353B3181
MalwarebytesMalware.AI.805341135
VIPREGen:Heur.Mint.Dreidel.@tW@yu81WwlG
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005690671 )
K7GWTrojan ( 005690671 )
CrowdStrikewin/malicious_confidence_100% (D)
CyrenW32/Kryptik.BZL.gen!Eldorado
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.HGGF
APEXMalicious
TrendMicro-HouseCallBackdoor.Win32.GLUPTEBA.SMTH.hp
ClamAVWin.Packed.Generickdz-9769553-0
BitDefenderGen:Heur.Mint.Dreidel.@tW@yu81WwlG
NANO-AntivirusTrojan.Win32.Tofsee.hvmerd
RisingTrojan.Kryptik!1.CC90 (CLASSIC)
Ad-AwareGen:Heur.Mint.Dreidel.@tW@yu81WwlG
SophosML/PE-A + Troj/Steal-AVG
ZillyaTrojan.Kryptik.Win32.2562094
TrendMicroBackdoor.Win32.GLUPTEBA.SMTH.hp
Trapminemalicious.high.ml.score
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Malicious PE
GDataGen:Heur.Mint.Dreidel.@tW@yu81WwlG
JiangminBackdoor.Tofsee.cvh
GoogleDetected
Antiy-AVLTrojan/Generic.ASMalwS.69EC
ArcabitTrojan.Mint.Dreidel.E43BD0
MicrosoftTrojan:Win32/Glupteba.DC!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Kryptik.R351627
Acronissuspicious
VBA32BScope.Trojan.Wacatac
MAXmalware (ai score=83)
TencentMalware.Win32.Gencirc.115b66bc
YandexTrojan.Kryptik!Mhzg1iuf/kA
FortinetW32/Kryptik.CNB!tr
Cybereasonmalicious.b3181f
PandaTrj/GdSda.A

How to remove Trojan:Win32/Glupteba.DC!MTB?

Trojan:Win32/Glupteba.DC!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment