Trojan

Trojan:Win32/Glupteba!pz (file analysis)

Malware Removal

The Trojan:Win32/Glupteba!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Glupteba!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Deletes executed files from disk

How to determine Trojan:Win32/Glupteba!pz?


File Info:

name: B35BB413BE06BD1D18A6.mlw
path: /opt/CAPEv2/storage/binaries/bc93d8332d0d7c09901e339e920273d34c91d15be77c6763389c358c8bd9b30b
crc32: 88E2EBDC
md5: b35bb413be06bd1d18a69ba03288ba12
sha1: 5ed68fcf5872aa5b37ee44eaa92ff94f3ea1209e
sha256: bc93d8332d0d7c09901e339e920273d34c91d15be77c6763389c358c8bd9b30b
sha512: b923c28763149bc913fc5710adbbc35e5b5a422740fce1833272f68babf709a61ff53f685213a095aa5dcb31ff10a4e738a7b80e522184863f1c744107f598d1
ssdeep: 1536:jtBFOjLtzQUKKTpAwJLRY/piWv2qVGLmJXzWP7e4SjWrz5Xg5Wnu8WwaDR909Vql:jPojLtxTq0eRfv2qIaJe7ejRonun9+E1
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1358302DF546A1566D6CE42B2CF49495B5CB648A2BF22F136CCC1E4FB841910DA1E8CFC
sha3_384: 208534c1458b48aa435bb54957437f708237b572928dcd7f31cfae2d8858232044a757c6269f2e9e2ccdc6dcaef49cfc
ep_bytes: 83ec04c7042400000000595081eb2c93
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Trojan:Win32/Glupteba!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Copak.4!c
MicroWorld-eScanGen:Variant.Razy.870640
SkyhighBehavesLike.Win32.Glupteba.mc
ALYacGen:Variant.Razy.870640
MalwarebytesMalware.AI.4161335647
VIPREGen:Variant.Razy.870640
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0058c5ff1 )
BitDefenderGen:Variant.Razy.870640
K7GWTrojan ( 005304e81 )
Cybereasonmalicious.f5872a
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.XVS
APEXMalicious
KasperskyHEUR:Trojan.Win32.Copak.pef
AlibabaTrojan:Win32/Glupteba.51d342f7
NANO-AntivirusVirus.Win32.Gen.ccmw
RisingTrojan.Injector!1.C865 (CLASSIC)
EmsisoftGen:Variant.Razy.870640 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.Siggen16.27259
TrendMicroTROJ_GEN.R002C0DK723
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.b35bb413be06bd1d
SophosTroj/Agent-BGOS
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=81)
GoogleDetected
AviraTR/Crypt.XPACK.Gen
VaristW32/Kryptik.ECM.gen!Eldorado
Antiy-AVLTrojan/Win32.GenKryptik
Kingsoftmalware.kb.a.999
MicrosoftTrojan:Win32/Glupteba!pz
ArcabitTrojan.Razy.DD48F0
ZoneAlarmHEUR:Trojan.Win32.Copak.pef
GDataGen:Variant.Razy.870640
CynetMalicious (score: 100)
BitDefenderThetaGen:NN.ZexaF.36792.fuW@aOoyGCh
DeepInstinctMALICIOUS
VBA32BScope.Trojan.Wacatac
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002C0DK723
TencentTrojan.Win32.Copak.pa
YandexTrojan.Copak!oZEKUrFNB2w
IkarusTrojan.Win32.Vindor
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.ECM!tr
AVGWin32:Evo-gen [Trj]
AvastWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Glupteba!pz?

Trojan:Win32/Glupteba!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment