Trojan

About “Trojan:Win32/MysticStealer.EM!MTB” infection

Malware Removal

The Trojan:Win32/MysticStealer.EM!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/MysticStealer.EM!MTB virus can do?

  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/MysticStealer.EM!MTB?


File Info:

name: 29E0AE6020D14F1A926B.mlw
path: /opt/CAPEv2/storage/binaries/656e2402d865c5a60acbaa165f604aae380a3fcac2d92c852cf37538d3fe0a1a
crc32: 83AC39C8
md5: 29e0ae6020d14f1a926b9f6b9eaced47
sha1: 5f380333cfb15c9f40f7506ffa5f78a00e044005
sha256: 656e2402d865c5a60acbaa165f604aae380a3fcac2d92c852cf37538d3fe0a1a
sha512: 3e1d639552ec7320dc20fb6d3ad62cd2e8f266de2693b16ce5fcd05efe29b2eb80a02577fac91be81fcae70793f95fc051a737c41f044f0a40e3cd9cef470f9c
ssdeep: 6144:JjXFo/N5ExgFbNOUAHEHIXbLvZAOC2/k+QLNpXVk5CWfVOPVs0BC+:TwDExgFY5vxP/kpVk5C68s0BC+
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T136847EF33CC140BED8F39E327AD4AAA5073974FC9C5B499B77604BB819B8590A35C462
sha3_384: 305f84983599ff6c05523ad212d88eb521bda5d57811ed2aff29d997942c492edd15dec2a87771032a63cb65eafad322
ep_bytes: e8c8070000e974feffff558bec8b4508
timestamp: 2023-09-30 09:05:57

Version Info:

0: [No Data]

Trojan:Win32/MysticStealer.EM!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Stealerc.4!c
MicroWorld-eScanGen:Variant.Lazy.402314
FireEyeGeneric.mg.29e0ae6020d14f1a
SkyhighBehavesLike.Win32.Generic.fh
ALYacGen:Variant.Lazy.402314
MalwarebytesTrojan.Crypt
VIPREGen:Variant.Lazy.402314
SangforInfostealer.Win32.Kryptik.Vhio
K7AntiVirusTrojan ( 005abe3f1 )
BitDefenderGen:Variant.Lazy.402314
K7GWTrojan ( 005abe3f1 )
BitDefenderThetaGen:NN.ZexaF.36792.yqW@aSDGJ1e
VirITTrojan.Win32.Genus.TKH
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HUQK
APEXMalicious
KasperskyHEUR:Trojan-PSW.Win32.Stealerc.pef
AlibabaTrojanPSW:Win32/MysticStealer.7ffa43df
NANO-AntivirusTrojan.Win32.Inject4.kbmghn
RisingBackdoor.Mokes!8.619 (TFE:5:cp4sb0ybDnO)
TACHYONTrojan/W32.Injurer.399360
SophosTroj/Krypt-ACG
F-SecureTrojan.TR/AD.RedLineSteal.djbhl
DrWebTrojan.Inject4.61510
TrendMicroTrojanSpy.Win32.TRICKBOT.SMC
Trapminesuspicious.low.ml.score
EmsisoftGen:Variant.Lazy.402314 (B)
IkarusTrojan.Win32.Crypt
JiangminTrojan.PSW.Stealerc.ir
Webroot
GoogleDetected
AviraTR/AD.RedLineSteal.djbhl
VaristW32/Kryptik.KTF.gen!Eldorado
Antiy-AVLTrojan/Win32.Kryptik.huqk
MicrosoftTrojan:Win32/MysticStealer.EM!MTB
ArcabitTrojan.Lazy.D6238A
ZoneAlarmHEUR:Trojan-PSW.Win32.Stealerc.pef
GDataWin32.Trojan.PSE.10X1BKT
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C5302376
McAfeeGenericRXAA-AA!29E0AE6020D1
MAXmalware (ai score=83)
DeepInstinctMALICIOUS
VBA32Trojan.Injurer
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTrojanSpy.Win32.TRICKBOT.SMC
TencentTrojan-PSW.Win32.Stealerc.kg
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HUTD!tr
AVGWin32:PWSX-gen [Trj]
AvastWin32:PWSX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/MysticStealer.EM!MTB?

Trojan:Win32/MysticStealer.EM!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment