Trojan

Trojan:Win32/Glupteba.SAP!MTB (file analysis)

Malware Removal

The Trojan:Win32/Glupteba.SAP!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Glupteba.SAP!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the embedded pe malware family
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Glupteba.SAP!MTB?


File Info:

name: 96F61E41CE6CBCFAF9A0.mlw
path: /opt/CAPEv2/storage/binaries/e6cb8d0992b774e2c18108d91472f2d9bc5e0465563b6078391008744a3aba64
crc32: 07BFAF64
md5: 96f61e41ce6cbcfaf9a066348f941b1e
sha1: 082a66cdda0d7b2451374e17d873b077b12af8b0
sha256: e6cb8d0992b774e2c18108d91472f2d9bc5e0465563b6078391008744a3aba64
sha512: d0960d81f9ac736d2e80f328a86e0ebda1176d7c4bf93284fe2ba1cf7c8c170dcd53c0101c4c5fdfc1cbd47938e5bff0846fd1bfa9796ed271795861771ee6a3
ssdeep: 6144:Rtf6RV5x6Coi1Q4IYCtuoHXPymDrcPvf9yxpoeyz5xYmX/M:CR16Coi1mw4XPHrcP39AoeYxYmE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17C74AF1032F1F430E2A335359934E7B50B7BB8712A31759FAF951A3A6EB47C1866132B
sha3_384: fec077451a57b51dcc962b162e2948bb49468350252490a7ac6f9672dc1c76909d88ce4c90a4a7b672320445a1cbbc38
ep_bytes: e87f350000e989feffff8bff558bec83
timestamp: 2023-03-02 13:17:16

Version Info:

FileVersion: 94.6.17.36
ProductVersion: 57.27.97.50
InternalName: Stupido
LegalCopyright: Silent news
CompanyName: Torque
Translation: 0x177b 0x02fc

Trojan:Win32/Glupteba.SAP!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.MoksSteal.i!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Babar.431373
ClamAVWin.Packed.Filerepmalware-10020053-0
FireEyeGeneric.mg.96f61e41ce6cbcfa
SkyhighBehavesLike.Win32.Worm.fh
McAfeePacked-GBE!96F61E41CE6C
Cylanceunsafe
SangforRansom.Win32.Save.a
K7AntiVirusTrojan ( 005b13711 )
AlibabaBackdoor:Win32/Glupteba.d5464d2a
K7GWTrojan ( 005b13711 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.36744.vu0@aiNx9zji
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HWDP
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Backdoor.Win32.Tofsee.pef
BitDefenderGen:Variant.Babar.431373
AvastWin32:PWSX-gen [Trj]
TencentTrojan.Win32.Obfuscated.gen
EmsisoftGen:Variant.Babar.431373 (B)
F-SecureTrojan.TR/AD.MoksSteal.svrga
VIPREGen:Variant.Babar.431373
TrendMicroTrojanSpy.Win32.AZORULT.YXEA4Z
Trapminemalicious.high.ml.score
SophosTroj/Krypt-ADH
IkarusTrojan.Win32.Crypt
GDataGen:Variant.Babar.431373
GoogleDetected
AviraTR/AD.MoksSteal.svrga
Antiy-AVLTrojan/Win32.Kryptik
ArcabitTrojan.Babar.D6950D
ZoneAlarmHEUR:Backdoor.Win32.Tofsee.pef
MicrosoftTrojan:Win32/Glupteba.SAP!MTB
VaristW32/ABRisk.TLMR-2999
AhnLab-V3Trojan/Win.Glupteba.R633214
VBA32BScope.Backdoor.Tofsee
ALYacGen:Variant.Babar.431373
MAXmalware (ai score=84)
MalwarebytesTrojan.MalPack.GS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTrojanSpy.Win32.AZORULT.YXEA4Z
RisingTrojan.Generic@AI.100 (RDML:dNkfHaDR99YgeqRYJGqiRg)
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.HWCY!tr
AVGWin32:PWSX-gen [Trj]
Cybereasonmalicious.dda0d7
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Glupteba.SAP!MTB?

Trojan:Win32/Glupteba.SAP!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment