Trojan

What is “Trojan:Win32/LummaStealer.MB!MTB”?

Malware Removal

The Trojan:Win32/LummaStealer.MB!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/LummaStealer.MB!MTB virus can do?

  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan:Win32/LummaStealer.MB!MTB?


File Info:

name: 235F9BE6B8C98F1C9249.mlw
path: /opt/CAPEv2/storage/binaries/2879de9c8544df87c416e73a70483286902d60d8013191e08fb263d0d18329d8
crc32: DE37A97C
md5: 235f9be6b8c98f1c9249e6cac86d6e39
sha1: e54e1d5449875b6b6483b4ea5e4b01a3cac83ee1
sha256: 2879de9c8544df87c416e73a70483286902d60d8013191e08fb263d0d18329d8
sha512: 0cedec5a1cf6ba44d9e32241e1ccbfa63600a42c26ee56999f5292b5cb82028c6f63606e34b0785bcbf46ce1cc80598a0431d2ecf0ce02f6e82ee33b52909d16
ssdeep: 6144:ukm8xeLFU6rELTNkE0anh5Mh0P0IBi8eHGILJ1oXvaJZ27rNeFWfutSmqLltNRYS:uz8xeRsGVqCpJOfaCUmGSmAPNRYUuHB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E5B4AE25B9C280F1D863283241F4E3765E38B671C9368DCBFBD46C78DA75690971A32E
sha3_384: a9561c4dbc853fb855e8a4562324b8ac5de9be32f9bb0388e5e7d409a05c96bb31abe77615b91c6b4d1722dbf2eebb57
ep_bytes: e856020000e97afeffff558becff7508
timestamp: 2023-11-03 17:45:22

Version Info:

0: [No Data]

Trojan:Win32/LummaStealer.MB!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Stealerc.i!c
AVGWin32:SpywareX-gen [Trj]
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.488690
SkyhighBehavesLike.Win32.Generic.hh
McAfeeArtemis!235F9BE6B8C9
Cylanceunsafe
ZillyaTrojan.Agent.Win32.3763422
SangforSuspicious.Win32.Save.a
K7AntiVirusSpyware ( 0055134d1 )
AlibabaTrojanPSW:Win32/LummaStealer.a2ffff35
K7GWSpyware ( 0055134d1 )
Cybereasonmalicious.449875
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.Agent.PRG
CynetMalicious (score: 100)
APEXMalicious
KasperskyHEUR:Trojan-PSW.Win32.Stealerc.gen
BitDefenderGen:Variant.Zusy.488690
AvastWin32:SpywareX-gen [Trj]
RisingSpyware.Agent!8.C6 (TFE:5:HvGx52H04WI)
EmsisoftGen:Variant.Zusy.488690 (B)
F-SecureTrojan.TR/Spy.Agent.vdzvf
VIPREGen:Variant.Zusy.488690
TrendMicroTROJ_GEN.R002C0DLT23
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.235f9be6b8c98f1c
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminTrojan.PSW.Stealerc.ra
VaristW32/ABSpyware.NROW-5955
AviraTR/Spy.Agent.vdzvf
Antiy-AVLTrojan/Win32.Sabsik
MicrosoftTrojan:Win32/LummaStealer.MB!MTB
ArcabitTrojan.Zusy.D774F2
ZoneAlarmHEUR:Trojan-PSW.Win32.Stealerc.gen
GDataGen:Variant.Zusy.488690
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R611473
BitDefenderThetaGen:NN.ZexaF.36744.GqW@ayhUjol
ALYacGen:Variant.Zusy.488690
MAXmalware (ai score=86)
VBA32BScope.TrojanPSW.Lumma
MalwarebytesGeneric.Malware.AI.DDS
TrendMicro-HouseCallTROJ_GEN.R002C0DLT23
TencentMalware.Win32.Gencirc.10bf4af5
YandexTrojanSpy.Agent!37xvaceUpBg
IkarusTrojan-Spy.Win32.Agent
MaxSecureTrojan.Malware.202870010.susgen
FortinetW32/Agent.PRG!tr.spy
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/LummaStealer.MB!MTB?

Trojan:Win32/LummaStealer.MB!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment