Trojan

Trojan:Win32/Ranumbot.RM!MTB (file analysis)

Malware Removal

The Trojan:Win32/Ranumbot.RM!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ranumbot.RM!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Spanish (Chile)
  • The binary likely contains encrypted or compressed data.

Related domains:

z.whorecord.xyz
a.tomx.xyz
api.faceit.com

How to determine Trojan:Win32/Ranumbot.RM!MTB?


File Info:

crc32: 4CB08773
md5: 22813974b5f59cea727bfc2ac161ae99
name: 22813974B5F59CEA727BFC2AC161AE99.mlw
sha1: 451f44f22033100cddcdfe2631ae41315d36346d
sha256: da7c1a29438b2c219e7ef8d84b198604d663de649d4f8fca71a3f46b895eaf1c
sha512: 3979e74c87306787baf4dba2f20090669e5e782030a2201cda02e4d921f57b9cef23ff8835979173f2df3ab42717d543109e6e8eb2f6c3ab8956a3a13229ad26
ssdeep: 12288:FTNHOistBPZkHSI6EZ1SlDCGWPk2bZkU9U8oORgGjJNIDHpa:VMisbRc/n1FvM2bZkUGxGjJUJa
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

ProductVersus: 1.8.37.29
FileVerus: 1.0.52.18
Translations: 0x0286 0x00be

Trojan:Win32/Ranumbot.RM!MTB also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0056f9be1 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.30312
CynetMalicious (score: 100)
McAfeeRDN/ArkeiStealer
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Ranumbot.a5058a1f
K7GWTrojan ( 0056f9be1 )
Cybereasonmalicious.220331
CyrenW32/Kryptik.DYI.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HKPA
APEXMalicious
AvastFileRepMalware
KasperskyHEUR:Trojan.Win32.Chapak.gen
BitDefenderTrojan.GenericKD.46181998
MicroWorld-eScanTrojan.GenericKD.46181998
Ad-AwareTrojan.GenericKD.46181998
SophosMal/Generic-R + Mal/GandCrypt-A
BitDefenderThetaGen:NN.ZexaF.34684.PuW@aS4XFTIi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Lockbit.jc
FireEyeGeneric.mg.22813974b5f59cea
EmsisoftTrojan.GenericKD.46181998 (B)
SentinelOneStatic AI – Malicious PE
KingsoftWin32.PSWTroj.Undef.(kcloud)
MicrosoftTrojan:Win32/Ranumbot.RM!MTB
AegisLabTrojan.Win32.Malicious.4!c
GDataWin32.Trojan.PSE.1L1P37C
AhnLab-V3CoinMiner/Win.Glupteba.R417847
Acronissuspicious
MAXmalware (ai score=85)
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
RisingMalware.Obscure/Heur!1.9E03 (CLOUD)
IkarusTrojan.Win32.Krypt
eGambitUnsafe.AI_Score_96%
FortinetW32/GandCrypt.A
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Trojan:Win32/Ranumbot.RM!MTB?

Trojan:Win32/Ranumbot.RM!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment