Trojan

What is “Trojan:Win32/Redline.DD!MTB”?

Malware Removal

The Trojan:Win32/Redline.DD!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Redline.DD!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Kannada
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Collects information to fingerprint the system

How to determine Trojan:Win32/Redline.DD!MTB?


File Info:

name: B7E2BD11FC2569980DAC.mlw
path: /opt/CAPEv2/storage/binaries/88b3c3011a9eec02deee28e91309cf61b40585fdf8a33ba288d34e27e2fc0c43
crc32: CB63CC9D
md5: b7e2bd11fc2569980dac8bfc8f3b5e40
sha1: 0d202d62b5006a95f6f5553078abe26f1e953f64
sha256: 88b3c3011a9eec02deee28e91309cf61b40585fdf8a33ba288d34e27e2fc0c43
sha512: d7f6d572678dcbca75c43a8b9278bfe201d2255daf46f80bc1a0461dca649df8008964aa1f42f7c6b23f263c701cbb3551722315d8e650d37c22c6e780246dfb
ssdeep: 3072:E3F53aoDF5OCvYwcm/21mhVzIIx7orGsuI6V3h3lldM/h3qpZa9uD6VdyhkEzRv4:O539F5OC/e1mhOIjsuDhbldrwVfEz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16D34CF2077A0C476D166A230487ACFA15B7EBC125A74964F37A4271E7E733C06AB631F
sha3_384: 7edbbf2aaad0942e1ed00601f6ae40826ac7163fcd323840c8f384a4dc81b7c91371b441227e4ab13c2804ab6bdf0a2b
ep_bytes: e81f450000e989feffff578bc683e00f
timestamp: 2021-08-18 17:21:40

Version Info:

FileVersions: 87.72.14.73
Copyrighz: Copyright (C) 2022, pozkarte
ProjectVersion: 60.93.90.88

Trojan:Win32/Redline.DD!MTB also known as:

BkavW32.AIDetect.malware1
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKDZ.90940
FireEyeGeneric.mg.b7e2bd11fc256998
ALYacTrojan.GenericKDZ.90940
CylanceUnsafe
VIPRETrojan.GenericKDZ.90940
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00596ec01 )
K7GWTrojan ( 00596ec01 )
Cybereasonmalicious.2b5006
CyrenW32/Kryptik.GVX.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HQLP
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Azorult-9949206-0
KasperskyHEUR:Exploit.Win32.Shellcode.gen
BitDefenderTrojan.GenericKDZ.90940
AvastWin32:RansomX-gen [Ransom]
Ad-AwareTrojan.GenericKDZ.90940
SophosML/PE-A + Mal/Agent-AWV
TrendMicroTROJ_GEN.R014C0RHG22
McAfee-GW-EditionBehavesLike.Win32.Ransomware.dc
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.GenericKDZ.90940 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.1K94ODC
JiangminTrojan.Agent.ecrv
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/AD.GenSHCode.ftmms
MicrosoftTrojan:Win32/Redline.DD!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R510585
McAfeeGenericRXTW-UH!B7E2BD11FC25
MAXmalware (ai score=89)
VBA32TrojanSpy.Stealer
MalwarebytesTrojan.MalPack.GS
TrendMicro-HouseCallTROJ_GEN.R014C0RHG22
RisingTrojan.Generic@AI.100 (RDML:RtO0tVXEScJ6CAvJ9kZPXA)
IkarusTrojan.Bulta
AVGWin32:RansomX-gen [Ransom]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Redline.DD!MTB?

Trojan:Win32/Redline.DD!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment