Trojan

Trojan:Win32/Glupteba.R!MTB (file analysis)

Malware Removal

The Trojan:Win32/Glupteba.R!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Glupteba.R!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Latvian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the Raccoon malware family

How to determine Trojan:Win32/Glupteba.R!MTB?


File Info:

name: 993D53F22EA3CBCA3BB1.mlw
path: /opt/CAPEv2/storage/binaries/db710c90eaa2f83be99f1004b9eda6cfbf905a1ab116d1738a89f4eac443f4fe
crc32: 27841F86
md5: 993d53f22ea3cbca3bb1e6ba194bf50f
sha1: ad4cf03948ec8b94fa997e261468dbe77bbaea8d
sha256: db710c90eaa2f83be99f1004b9eda6cfbf905a1ab116d1738a89f4eac443f4fe
sha512: 1a8e5239bac59a343373b02330da4bb533a0649f12aa674edc28acbd04604629a334e284b7ef2bd344555c77818cecd6a4b13387f7c8ddf63c4ea257999d2e76
ssdeep: 12288:gkwEfCz+0r5d5k8r3c35DDf8xvFMwBiZ0POoLUI9Y:ffM+06fMvHr2oi
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10BC4E010BA90C034F5F632F8567A9369B52D7AB09B2454CF62D61AFA4B385F0ED31327
sha3_384: 5448340fb7d9af6e29aa4f55b91f084756692e7c8b7b9432394d56cf3a395290951d1c3b45127dc0ff8641f23619d60c
ep_bytes: 8bff558bece886610000e8110000005d
timestamp: 2020-11-20 14:16:15

Version Info:

Translations: 0x48a6 0x0359

Trojan:Win32/Glupteba.R!MTB also known as:

BkavW32.AIDetect.malware1
LionicHeuristic.File.Generic.00×1!p
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKDZ.75975
FireEyeGeneric.mg.993d53f22ea3cbca
CAT-QuickHealRansom.Stop.Z5
ALYacTrojan.PSW.Racealer
CylanceUnsafe
ZillyaTrojan.Racealer.Win32.1695
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojanPSW:Win32/Glupteba.87e5598c
K7GWRiskware ( 0040eff71 )
CyrenW32/Kryptik.EJB.gen!Eldorado
SymantecPacked.Generic.525
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HLKW
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Filerepmalware-9873402-0
KasperskyHEUR:Trojan-PSW.Win32.Racealer.gen
BitDefenderTrojan.GenericKDZ.75975
AvastWin32:PWSX-gen [Trj]
TencentWin32.Trojan-QQPass.QQRob.Gmnw
Ad-AwareTrojan.GenericKDZ.75975
EmsisoftTrojan.Crypt (A)
F-SecureHeuristic.HEUR/AGEN.1242349
DrWebTrojan.DownLoader39.50552
VIPRETrojan.GenericKDZ.75975
TrendMicroTrojanSpy.Win32.RACEALER.AO
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
Trapminemalicious.moderate.ml.score
SophosMal/Generic-R + Troj/Kryptik-TR
IkarusTrojan.Win32.Glupteba
GDataTrojan.GenericKDZ.75975
JiangminTrojan.Zenpak.hpk
GoogleDetected
AviraHEUR/AGEN.1242349
Antiy-AVLTrojan/Generic.ASMalwS.6DB3
ArcabitTrojan.Generic.D128C7
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
ZoneAlarmHEUR:Trojan-PSW.Win32.Racealer.gen
MicrosoftTrojan:Win32/Glupteba.R!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.R426443
Acronissuspicious
McAfeePacked-GDT!993D53F22EA3
MAXmalware (ai score=88)
VBA32BScope.Trojan.Crypt
MalwarebytesTrojan.MalPack.GS
TrendMicro-HouseCallTrojanSpy.Win32.RACEALER.AO
RisingTrojan.Kryptik!1.D792 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.TR!tr
BitDefenderThetaGen:NN.ZexaF.34646.Ju0@ay4LYehI
AVGWin32:PWSX-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Glupteba.R!MTB?

Trojan:Win32/Glupteba.R!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment