Trojan

Trojan:Win32/RedLine.DB!MTB (file analysis)

Malware Removal

The Trojan:Win32/RedLine.DB!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/RedLine.DB!MTB virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/RedLine.DB!MTB?


File Info:

name: 8AEA4AFD1F1DDC32C5E0.mlw
path: /opt/CAPEv2/storage/binaries/95dd9daaf8a919b4db885cee2ebc406d3eac78d450e9d23bfa72ad3e4af89eb6
crc32: 48F632D7
md5: 8aea4afd1f1ddc32c5e0488d2dfc12ce
sha1: 0d6eec461b98c3796444b44b5c004d4f800815d3
sha256: 95dd9daaf8a919b4db885cee2ebc406d3eac78d450e9d23bfa72ad3e4af89eb6
sha512: 48b5fdf3e2ae0687fa8576c240e05efc2ea9f43d6f6f99ee00354256108c58a43718ea395517e0cf75fa98dee8105f861c00ef2b865b5d1fb4bc2ca2b82d7b04
ssdeep: 12288:ahhkT/vW5pGJ3VsLEGWkLu/mZr9X6a9Dhvh6Lo0MvRUPVc0V:ah8vKI3WX/Vt6a9DhvhiMGPV9
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1AD75F90162F90B4DF5F35AB866BAE611087ABCAA9F11C6DF3161544E0C21AD4C970FFB
sha3_384: a9a61b03e716314509f772b1095efac4d12dc5c6ec88afbb397a7fa03baf872a6d964084709c44d3f8fe3f60b90d7cb9
ep_bytes: e910ec0100e98b1e0300e943130100e9
timestamp: 2023-11-04 12:46:07

Version Info:

0: [No Data]

Trojan:Win32/RedLine.DB!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Mokes.m!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.GHQI
SkyhighArtemis!Trojan
McAfeeGenericRXAA-AA!8AEA4AFD1F1D
MalwarebytesRamnit.Virus.FileInfector.DDS
ZillyaTrojan.GenKryptik.Win32.279361
K7AntiVirusTrojan ( 005add031 )
AlibabaBackdoor:Win32/RedLine.e56adb5a
K7GWTrojan ( 005add031 )
CrowdStrikewin/malicious_confidence_70% (W)
ArcabitTrojan.Agent.GHQI
VirITTrojan.Win32.Genus.UAY
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HVFH
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Pwsx-10012424-0
KasperskyHEUR:Backdoor.Win32.Mokes.gen
BitDefenderTrojan.Agent.GHQI
AvastWin32:PWSX-gen [Trj]
RisingBackdoor.Mokes!8.619 (TFE:5:sP5HB3NEaJD)
EmsisoftTrojan.Agent.GHQI (B)
F-SecureBackdoor.BDS/Mokes.zjpum
DrWebTrojan.SmokeLoader.41
VIPRETrojan.Agent.GHQI
TrendMicroTROJ_GEN.R002C0DKB23
SophosTroj/Krypt-ABY
IkarusTrojan.Win32.Krypt
JiangminBackdoor.Mokes.hst
VaristW32/Kryptik.KNN.gen!Eldorado
AviraBDS/Mokes.zjpum
Antiy-AVLTrojan[Backdoor]/Win32.Mokes
KingsoftWin32.Hack.Mokes.gen
MicrosoftTrojan:Win32/RedLine.DB!MTB
ZoneAlarmHEUR:Backdoor.Win32.Mokes.gen
GDataWin32.Trojan.PSE.1CRCKSQ
GoogleDetected
AhnLab-V3Trojan/Win.Agent.R620798
BitDefenderThetaGen:NN.ZexaF.36680.NDX@aa18B0l
MAXmalware (ai score=84)
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DKB23
TencentMalware.Win32.Gencirc.10bf45d0
YandexTrojan.Kryptik!LEwu0Bhp4ZA
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/GenKryptik.GPTP!tr
AVGWin32:PWSX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/RedLine.DB!MTB?

Trojan:Win32/RedLine.DB!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment