Trojan

Trojan:Win32/RedLine.CAP!MTB malicious file

Malware Removal

The Trojan:Win32/RedLine.CAP!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/RedLine.CAP!MTB virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/RedLine.CAP!MTB?


File Info:

name: BD45FC5269F0FD1B06C4.mlw
path: /opt/CAPEv2/storage/binaries/c3d0f3e52d49ee5823b63d55d9778ac1e7131c5662dc680485962e81951ca25f
crc32: 67BEE037
md5: bd45fc5269f0fd1b06c4716aabc89c40
sha1: 5a430415b6cab4c3e4f0930a5398ba01e4dc24df
sha256: c3d0f3e52d49ee5823b63d55d9778ac1e7131c5662dc680485962e81951ca25f
sha512: e5d3f6ab48ae429c0ece92301f0433cb1ca545c5c6055682194c98e240adde54380246a025a6a2540085d7b705b942fd9f2f7bdfad40db4fcb242466e463d4c0
ssdeep: 12288:ZrN8gyF0OusH4aoRNkKFSqkWF7DmQBQtw0O:ZrsFlHDONkKYcmQm9O
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1F8B4E0013184A838F8E9E870CCD5AB751A3CBDB1A7DF51CBB785266FCA17EE03A51251
sha3_384: c67053e9e8ef4e67b97d1598f3055a726e38fea41cfca733c9020d16a04b5a58e72b101d7e39a3093a581776ea6ba9eb
ep_bytes: e8a5680000e9a4feffff6a0c68e08542
timestamp: 2023-05-13 00:05:48

Version Info:

Comments: Roll reputedly army climates marchioness siamese
CompanyName: Raver bola
FileDescription: Prostatic chalk goals sanctum accepted shrewdly
FileVersion: 8.249.79.8
InternalName: Redefined lessor
LegalCopyright: Copyright © Shuffler surfboard revolutionaries flamenco
LegalTrademarks: Anterior dyed
OriginalFilename: Auteur
ProductName: Weathercock
ProductVersion: 8.249.79.8
Translation: 0x081a 0x081a

Trojan:Win32/RedLine.CAP!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Stealerc.4!c
MicroWorld-eScanGen:Variant.Zusy.467841
ClamAVWin.Packed.Zusy-10001910-0
FireEyeGeneric.mg.bd45fc5269f0fd1b
ALYacGen:Variant.Zusy.467841
Cylanceunsafe
VIPREGen:Variant.Zusy.467841
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0059d4ec1 )
AlibabaTrojanPSW:Win32/Stealerc.814feecb
K7GWTrojan ( 0059d4ec1 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Agent.GAX.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HSEV
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-PSW.Win32.Stealerc.gen
BitDefenderGen:Variant.Zusy.467841
AvastWin32:BackdoorX-gen [Trj]
TencentMalware.Win32.Gencirc.11a59f72
EmsisoftGen:Variant.Zusy.467841 (B)
F-SecureTrojan.TR/AD.GenSteal.iynoo
DrWebBackDoor.Andromeda.1809
TrendMicroTROJ_GEN.R002C0DF123
McAfee-GW-EditionRDN/Generic PWS.y
Trapminemalicious.high.ml.score
SophosTroj/Steal-DNO
IkarusTrojan.Win32.Redline
GDataGen:Variant.Zusy.467841
JiangminTrojan.PSW.Reline.aei
AviraTR/AD.GenSteal.iynoo
Antiy-AVLTrojan/Win32.Kryptik
ArcabitTrojan.Zusy.D72381
ViRobotTrojan.Win.Z.Zusy.533128
ZoneAlarmHEUR:Trojan-PSW.Win32.Stealerc.gen
MicrosoftTrojan:Win32/RedLine.CAP!MTB
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R578284
McAfeeRDN/Generic PWS.y
MAXmalware (ai score=81)
VBA32TrojanPSW.Arkei
MalwarebytesExpiro.Virus.FileInfector.DDS
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0DF123
RisingBackdoor.Agent!8.C5D (TFE:5:Ojq6eX0sX8N)
FortinetW32/Kryptik.HSEV!tr
AVGWin32:BackdoorX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/RedLine.CAP!MTB?

Trojan:Win32/RedLine.CAP!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment