Trojan

About “Trojan:Win32/Glupteba.MX!MTB” infection

Malware Removal

The Trojan:Win32/Glupteba.MX!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Glupteba.MX!MTB virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Spanish (Honduras)
  • The binary likely contains encrypted or compressed data.
  • Attempts to create or modify system certificates
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

doc-14-b8-docs.googleusercontent.com
redirector.gvt1.com
r4—sn-4g5e6nzz.gvt1.com

How to determine Trojan:Win32/Glupteba.MX!MTB?


File Info:

crc32: AA75E2EA
md5: 05edbe0c68f3568901851b95fef60c9d
name: file.exe
sha1: cb21803aa2daf2050362718dd7a80fe7ce305f4a
sha256: 44612606f97b7370cc8320ad7ec79a84ab3823770c023c409879e68fefecc3c4
sha512: 1ede9080b9d4749203277d9d511192c1bafb86a497bcd8b05b86eac7668cedfaf6d020d00fd0de7cac11622c73a22d897b57e53d35dd9079b31482f2e96a5d66
ssdeep: 12288:nJ4xbmVTk01yVQ/lhVdTL8Xc1YZRazzLsfF8M:n6IV4HolhVdTu0YRazXsf+
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Glupteba.MX!MTB also known as:

BkavW32.AIDetectVM.malware
MicroWorld-eScanTrojan.GenericKD.33741370
FireEyeGeneric.mg.05edbe0c68f35689
Qihoo-360Win32/Trojan.PSW.eec
McAfeeGenericRXKI-TX!05EDBE0C68F3
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 00565b041 )
BitDefenderTrojan.GenericKD.33741370
K7GWTrojan ( 00565b041 )
Cybereasonmalicious.aa2daf
Invinceaheuristic
APEXMalicious
AvastWin32:CoinminerX-gen [Trj]
ClamAVWin.Dropper.Generickdz-7724446-0
GDataTrojan.GenericKD.33741370
KasperskyTrojan-PSW.Win32.Racealer.fdw
RisingMalware.Heuristic!ET#93% (RDMK:cmRtazpWT8rthKKwupcOOv4NacE9)
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.33741370 (B)
ComodoMalware@#3i7yuxe882is
F-SecureTrojan.TR/Kryptik.zocuf
TrendMicroTROJ_GEN.R015C0DDT20
McAfee-GW-EditionBehavesLike.Win32.SoftPulse.hc
SophosMal/Generic-S
AviraTR/Kryptik.zocuf
MAXmalware (ai score=89)
ArcabitTrojan.Generic.D202DA3A
ZoneAlarmTrojan-PSW.Win32.Racealer.fdw
MicrosoftTrojan:Win32/Glupteba.MX!MTB
AhnLab-V3Trojan/Win32.MalPe.R334756
Acronissuspicious
VBA32Trojan.Wacatac
ALYacTrojan.GenericKDZ.66816
Ad-AwareTrojan.GenericKD.33741370
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HCZR
TrendMicro-HouseCallTROJ_GEN.R015C0DDT20
TencentWin32.Trojan-qqpass.Qqrob.Hfp
YandexTrojan.Kryptik!py/gpLFJc4k
SentinelOneDFI – Malicious PE
FortinetW32/GenKryptik.EJKQ!tr
BitDefenderThetaGen:NN.ZexaF.34108.GqW@aaZCs5O
AVGWin32:CoinminerX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Glupteba.MX!MTB?

Trojan:Win32/Glupteba.MX!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment