Trojan

Trojan:Win32/Redline.DAA!MTB malicious file

Malware Removal

The Trojan:Win32/Redline.DAA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Redline.DAA!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Redline.DAA!MTB?


File Info:

name: 73A6C1161FC40C155756.mlw
path: /opt/CAPEv2/storage/binaries/ba3132282c1bf362cadbcf53731afceda13b120c18085a50a5dc053253dd2471
crc32: 89BB2A66
md5: 73a6c1161fc40c155756c39742892838
sha1: ea3aa59105b5c79d9a0ae8460e08481b7f119181
sha256: ba3132282c1bf362cadbcf53731afceda13b120c18085a50a5dc053253dd2471
sha512: c6061e9104e65a9e6691664164b86fedf026cef7899304bfdf12c4f8c0ddf8b3d655b421aa0b60b635bbc7e9558802a62565e0892fffa8f4e2cee4e1b3742d85
ssdeep: 3072:0j+oJwJcsWgviNh3lPGsit42+eL6M0MpZKegBcvqd4fxvwXZB:bomWtHVMpEeFCmCZB
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T15D4439C335A0EB76E446C1767846CD8894FF6052865A42DEFADDDBCC232C7F06AAC461
sha3_384: 1cefb2156db39ea9b09dd5c80fd230636bf744c8ea477e4791146e46ce493bd7f6daa01f78240e26e699c6a42e3737c2
ep_bytes: e80d300000e9a4feffff3b0d04c14300
timestamp: 2023-06-13 00:59:50

Version Info:

Comments: Esta es una aplicación legítima.
CompanyName: Telefónica
FileDescription: Telefónica Produit
FileVersion: 895
InternalName: AplicacionInterna
LegalCopyright: Derechos de autor © Telefónica Todos los derechos reservados.
LegalTrademarks: Marcas registradas © Telefónica
OriginalFilename: app.exe
ProductName: Aplicacion
ProductVersion: 895
Translation: 0x0407 0x04b0

Trojan:Win32/Redline.DAA!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Convagent.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.472379
FireEyeGeneric.mg.73a6c1161fc40c15
MalwarebytesTrojan.Crypt
SangforTrojan.Win32.Convagent.V5z5
CrowdStrikewin/malicious_confidence_100% (W)
VirITTrojan.Win32.GenusT.DMYV
CyrenW32/Kryptik.JZU.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HTUE
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-PSW.MSIL.Convagent.gen
BitDefenderGen:Variant.Zusy.472379
AvastWin32:CrypterX-gen [Trj]
TencentMsil.Trojan-QQPass.QQRob.Nsmw
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1311187
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Zusy.472379 (B)
IkarusAdWare.Lollipop
GDataGen:Variant.Zusy.472379
AviraHEUR/AGEN.1311187
ArcabitTrojan.Zusy.D7353B
ZoneAlarmHEUR:Trojan-PSW.MSIL.Convagent.gen
MicrosoftTrojan:Win32/Redline.DAA!MTB
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R586431
McAfeeArtemis!73A6C1161FC4
MAXmalware (ai score=80)
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.Convagent!8.123DC (TFE:5:daY4mwMI6gV)
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.HTUE!tr
BitDefenderThetaGen:NN.ZexaF.36250.pq2@aeDpdffi
AVGWin32:CrypterX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Redline.DAA!MTB?

Trojan:Win32/Redline.DAA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment