Trojan

About “Trojan:Win32/MarsStealer.MB!MTB” infection

Malware Removal

The Trojan:Win32/MarsStealer.MB!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/MarsStealer.MB!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Trojan:Win32/MarsStealer.MB!MTB?


File Info:

name: 46CF85A18E1B530C2F34.mlw
path: /opt/CAPEv2/storage/binaries/b133d293a02c7c8ea3a38135265a1e0f86b4062b4e95557b4cc0c05d5ed84810
crc32: D1B34FB8
md5: 46cf85a18e1b530c2f3462b390abb3b6
sha1: 1b139d36d2c7eaf65b60b8ff1f88da73c3944c50
sha256: b133d293a02c7c8ea3a38135265a1e0f86b4062b4e95557b4cc0c05d5ed84810
sha512: b14be5049392313445599d5ba0ddd1ba54294d59e4bc7c6347d7b5ef7e5395a35fad3512b6dc4c8f77be222835525e671a80f04de43966fe44494da7e2ca22d0
ssdeep: 1536:+GvNAYsnH5B+QQrhhl6BaFSm0cV8l8V+JlfKyBzDyuRSyOHm9RNKQFGo:RvoZPQr7l60c/cVUkmJzDyuRS8RMr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19FB39E10C510E51ED562407FD7E35FB8DD8DAE7A0B0944D3DBC0AAD216B88FA9E1A81F
sha3_384: b00a19ded496aa7d3251f20991172cc15db77247df26ff70932ccb0ee0afb0da377d589cb6b48765e8dd76bfce493a04
ep_bytes: 64a1300000008b400c8b40148b7810e8
timestamp: 2022-01-05 14:09:08

Version Info:

0: [No Data]

Trojan:Win32/MarsStealer.MB!MTB also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebBackDoor.CoreBot.54
MicroWorld-eScanGen:Variant.Lazy.117521
FireEyeGeneric.mg.46cf85a18e1b530c
ALYacGen:Variant.Lazy.117521
CylanceUnsafe
SangforBackdoor.Win32.Androm.vahr
K7AntiVirusTrojan ( 005718151 )
AlibabaBackdoor:Win32/Androm.a5bf549d
K7GWTrojan ( 005718151 )
Cybereasonmalicious.18e1b5
BitDefenderThetaAI:Packer.F9069DCA1E
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/PSW.Agent.OMJ
TrendMicro-HouseCallTROJ_GEN.R002C0PB822
Paloaltogeneric.ml
KasperskyBackdoor.Win32.Androm.vahr
BitDefenderGen:Variant.Lazy.117521
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:PWSX-gen [Trj]
TencentWin32.Trojan.Ransom.Peqh
Ad-AwareGen:Variant.Lazy.117521
EmsisoftGen:Variant.Lazy.117521 (B)
TrendMicroTROJ_GEN.R002C0PB822
McAfee-GW-EditionGenericRXRR-PG!30057EACAA66
SophosML/PE-A + Mal/Behav-215
IkarusTrojan-PSW.Agent
GDataGen:Variant.Lazy.117521
WebrootW32.Trojan.Gen
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=88)
Antiy-AVLTrojan/Generic.ASMalwS.3524D85
GridinsoftRansom.Win32.AI.sa
ArcabitTrojan.Lazy.D1CB11
ZoneAlarmBackdoor.Win32.Androm.vahr
MicrosoftTrojan:Win32/MarsStealer.MB!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4915042
Acronissuspicious
McAfeeGenericRXAA-AA!46CF85A18E1B
VBA32BScope.Backdoor.CoreBot
MalwarebytesMalware.AI.1501573999
APEXMalicious
RisingSpyware.Stealer!8.3090 (CLOUD)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
AVGWin32:PWSX-gen [Trj]
PandaGeneric Suspicious
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan:Win32/MarsStealer.MB!MTB?

Trojan:Win32/MarsStealer.MB!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment