Trojan

Trojan:Win32/Glupteba.GKM!MTB malicious file

Malware Removal

The Trojan:Win32/Glupteba.GKM!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Glupteba.GKM!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (5 unique times)
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Urdu (India)
  • The binary likely contains encrypted or compressed data.
  • Steals private information from local Internet browsers
  • Attempts to access Bitcoin/ALTCoin wallets
  • Attempts to create or modify system certificates
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

telete.in
apps.identrust.com
globalsalespartscn.top

How to determine Trojan:Win32/Glupteba.GKM!MTB?


File Info:

crc32: BFAAC7BC
md5: 8cbfe1706d94bd1565478e565c0a2519
name: 8CBFE1706D94BD1565478E565C0A2519.mlw
sha1: 315c6a3643f66bdd3a3b5687b9ab7198aa59b82a
sha256: 1207d4bf8a616e765354ca275284b24729639d5c5cab4991ace74d1b8d252cbc
sha512: 74d1e9c168823371afc2af0b32fd0a61bb79231382ee229ba1cce21d032b9a069235df268ceb5db6776d4fad0443f46175d530df3fc2b0862b647cf052ad8174
ssdeep: 12288:7R6eEQeYcDrhL6UqMET3iVqv6rWIO7XP:7AeUY0xLqlT3bv6yVzP
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Glupteba.GKM!MTB also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.72708
FireEyeGeneric.mg.8cbfe1706d94bd15
ALYacTrojan.GenericKDZ.72708
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_90% (D)
BitDefenderTrojan.GenericKDZ.72708
K7GWTrojan ( 0056f9be1 )
K7AntiVirusTrojan ( 0056f9be1 )
BitDefenderThetaGen:NN.ZexaF.34804.CqW@amt5vvnO
CyrenW32/Kryptik.DCH.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
ClamAVWin.Dropper.Wacatac-9826966-0
KasperskyHEUR:Exploit.Win32.Shellcode.gen
Ad-AwareTrojan.GenericKDZ.72708
SophosMal/Generic-S
DrWebTrojan.PWS.Siggen2.61343
TrendMicroTROJ_GEN.R004C0DB221
McAfee-GW-EditionBehavesLike.Win32.SoftPulse.gc
EmsisoftTrojan.Crypt (A)
IkarusTrojan-Downloader.Win32.Stantinko
MicrosoftTrojan:Win32/Glupteba.GKM!MTB
ArcabitTrojan.Generic.D11C04
ZoneAlarmHEUR:Exploit.Win32.Shellcode.gen
GDataTrojan.GenericKDZ.72708
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C4318209
Acronissuspicious
McAfeeLockbit-FSWW!8CBFE1706D94
MAXmalware (ai score=82)
MalwarebytesGlupteba.Backdoor.Bruteforce.DDS
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HJBW
TrendMicro-HouseCallTROJ_GEN.R004C0DB221
RisingTrojan.Kryptik!1.D1E0 (CLASSIC)
SentinelOneStatic AI – Malicious PE
FortinetW32/GenericKDZ.3848!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.643f66
Qihoo-360HEUR/QVM10.1.061F.Malware.Gen

How to remove Trojan:Win32/Glupteba.GKM!MTB?

Trojan:Win32/Glupteba.GKM!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment