Trojan

What is “Trojan:Win32/OffLoader.AST!MTB”?

Malware Removal

The Trojan:Win32/OffLoader.AST!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/OffLoader.AST!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/OffLoader.AST!MTB?


File Info:

name: 4F38E0695FD92620426E.mlw
path: /opt/CAPEv2/storage/binaries/4c2127acc9ef00808df96977fb6fdd089b733a2a2bd8ad994e5896165e3d6341
crc32: 55C945DD
md5: 4f38e0695fd92620426ed00b191d3596
sha1: ce58ab4b45e25850296accb8707fa73b064b21af
sha256: 4c2127acc9ef00808df96977fb6fdd089b733a2a2bd8ad994e5896165e3d6341
sha512: a127545115223cfd6ec378a8331621ba7f10c94122b46202f4040608cf1b1432e9ea49616acd3e4f4d602935741541513171991ede514cd4485bc0ff3cc5418b
ssdeep: 24576:s7FUDowAyrTVE3U5F/DLKic6QL3E2vVsjECUAQT45deRV9R6:sBuZrEUzKIy029s4C1eH9o
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15D75BE3FF268A13EC56A1B3245B38320997BBA51B81A8C1E47FC344DCF765601E3B656
sha3_384: 4f1e441079fa9488c924e7efef5a6870d75c7bbf758ba3bd9ddd5b842f8d231f7e149812d84f640a33bb8137c692e993
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2023-02-15 14:54:16

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Yiff Moon Demo v2 By Yiff Moon Team.exe Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: Yiff Moon Demo v2 By Yiff Moon Team.exe
ProductVersion: 1.1
Translation: 0x0000 0x04b0

Trojan:Win32/OffLoader.AST!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.OffLoader.a!c
MicroWorld-eScanTrojan.GenericKD.70781756
SkyhighBehavesLike.Win32.Trojan.tc
McAfeeArtemis!4F38E0695FD9
MalwarebytesAdware.Bundler
SangforDownloader.Win32.Agent.Vrt2
K7AntiVirusTrojan-Downloader ( 005ae1811 )
AlibabaTrojanDownloader:Win32/OffLoader.01dca812
K7GWTrojan-Downloader ( 005ae1811 )
ArcabitTrojan.Generic.D4380B3C
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.HIV
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Downloader.Win32.OffLoader.aivg
BitDefenderTrojan.GenericKD.70781756
AvastWin32:Malware-gen
EmsisoftTrojan.GenericKD.70781756 (B)
F-SecureTrojan.TR/Downloader.Gen
VIPRETrojan.GenericKD.70781756
TrendMicroTROJ_GEN.R002C0DLD23
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GoogleDetected
AviraTR/Downloader.Gen
MAXmalware (ai score=82)
MicrosoftTrojan:Win32/OffLoader.AST!MTB
ZoneAlarmTrojan-Downloader.Win32.OffLoader.aivg
GDataTrojan.GenericKD.70781756
VaristW32/Agent.HTI.gen!Eldorado
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002C0DLD23
TencentMalware.Win32.Gencirc.13f8cf4e
IkarusTrojan.Inno.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.HIV!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/OffLoader.AST!MTB?

Trojan:Win32/OffLoader.AST!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment