Trojan

About “Trojan:Win32/Raccoon.RF!MTB” infection

Malware Removal

The Trojan:Win32/Raccoon.RF!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Raccoon.RF!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Georgian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering
  • Collects information to fingerprint the system

How to determine Trojan:Win32/Raccoon.RF!MTB?


File Info:

name: BFDC0D855914804496D3.mlw
path: /opt/CAPEv2/storage/binaries/82eea2878a074baf08371835539ca576c2267a99a625b541e0fc2c678aaa7f1b
crc32: 80EBE0E6
md5: bfdc0d855914804496d36d484b8c0b9e
sha1: 36362ea3ef51a7c76bf56e1f48971c25139d3819
sha256: 82eea2878a074baf08371835539ca576c2267a99a625b541e0fc2c678aaa7f1b
sha512: 3312db3d16771682ad9afbd88f334016f3f3000a8b56eef0b3eb4898bab0dce9cd020344f2859224870d9523bfc8c592dd8950c87fc176dd8a204d2d7c5bdba3
ssdeep: 6144:AWOewqTW5asoLtCl+099YnenUPO4bMzyvT7w2DMIF1E6aKme3PLGO0wWOnligavm:AWOHT5KQl+09FnU8YT8FD7ejGXOoc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19384E003BAD5D973C5621C301826CBF05B7BB8797A305997F7949B6E1E723C0AA32346
sha3_384: 6c3f7756b8e8da5203bf864985eb88ebd96a5ce63f64bdee7c36a82faae3bb585ed6250c395df12a2db10e91543fde3b
ep_bytes: e808820000e979feffffcccccc8b4c24
timestamp: 2021-04-30 18:40:39

Version Info:

FileVersions: 98.52.44.24
InternationalName: povgwaoci.iwe
Copyright: Copyright (C) 2022, somoklos
ProjectVersion: 0.32.81.93

Trojan:Win32/Raccoon.RF!MTB also known as:

BkavW32.AIDetect.malware1
DrWebTrojan.DownLoader45.19336
MicroWorld-eScanGen:Variant.Mikey.141270
FireEyeGeneric.mg.bfdc0d8559148044
CAT-QuickHealRansom.Stop.P5
ALYacGen:Variant.Mikey.141270
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005989381 )
K7GWTrojan ( 005989381 )
Cybereasonmalicious.3ef51a
CyrenW32/Ransom.QS.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HQXJ
APEXMalicious
ClamAVWin.Malware.Azorult-9949206-0
KasperskyTrojan-PSW.Win32.Tepfer.pszbir
BitDefenderGen:Variant.Mikey.141270
AvastWin32:DropperX-gen [Drp]
Ad-AwareGen:Variant.Mikey.141270
EmsisoftGen:Variant.Mikey.141270 (B)
VIPREGen:Variant.Mikey.141270
McAfee-GW-EditionBehavesLike.Win32.Adware.fc
Trapminesuspicious.low.ml.score
SophosML/PE-A
GDataWin32.Trojan.PSE.1MVGON2
GoogleDetected
MAXmalware (ai score=83)
MicrosoftTrojan:Win32/Raccoon.RF!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.CrypterX-gen.R522027
Acronissuspicious
McAfeeArtemis!BFDC0D855914
VBA32BScope.Trojan.Denes
MalwarebytesTrojan.MalPack.GS
RisingMalware.Obscure!1.A89F (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Siggen18.49!tr
AVGWin32:DropperX-gen [Drp]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Raccoon.RF!MTB?

Trojan:Win32/Raccoon.RF!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment