Trojan

Trojan:Win32/Redline.MD!MTB information

Malware Removal

The Trojan:Win32/Redline.MD!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Redline.MD!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Redline.MD!MTB?


File Info:

name: 3EACCA91216D782C68BE.mlw
path: /opt/CAPEv2/storage/binaries/217bb63194104a743dea34fafc9d8f38c842cde812ec86dfff64b03526bd2d89
crc32: 11B7FCA3
md5: 3eacca91216d782c68becc40b2056ade
sha1: d890abd8a87633413fee989f37c442e8f6344a64
sha256: 217bb63194104a743dea34fafc9d8f38c842cde812ec86dfff64b03526bd2d89
sha512: c36c67120b4e9d26eeddb22ef2942c8370c769d9bea570690811e2bee01041b2604d1c51e3ec70a6dff19fadc4655665a0a5b76820793f627e516a2009db0570
ssdeep: 49152:Lt76ZDuewHg0RXPS7qstsgZjsC89ILW62ayMDP:B+ZD/wfRXPS7ttsQICV6ay6P
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19A850214876A8136E4D749F0AE51BA85F323BD320F61898715DB125B6F377C8C8B83E9
sha3_384: 757af8897d0971a60df224ab69c2b30899c97738bccde5a4ced4a3df62cd1b54acb565a7adb654fc1e19492df54f8486
ep_bytes: 8bff558bece8c6a00000e8110000005d
timestamp: 2018-07-04 07:12:15

Version Info:

FileVersion: 13.89.58.59
LegalCopyright: Copyright ™ 2010-2022 for Cefic Instance.
ProductVersion: 32.50.31.87
Translation: 0x0000 0x03a4

Trojan:Win32/Redline.MD!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Agent.Y!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Steam.28157
MicroWorld-eScanTrojan.GenericKD.61136428
FireEyeGeneric.mg.3eacca91216d782c
CAT-QuickHealTrojan.ConvagentRI.S28494629
McAfeeGenericRXTW-DP!3EACCA91216D
Cylanceunsafe
ZillyaTrojan.Rescoms.Win32.970
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:Win32/RedLine.ebba7e7b
K7GWRiskware ( 0040eff71 )
VirITTrojan.Win32.Genus.LNC
CyrenW32/Kryptik.HEM.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Rescoms.B
ZonerTrojan.Win32.151492
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Agent.pef
BitDefenderTrojan.GenericKD.61136428
NANO-AntivirusTrojan.Win32.Remcos.jqywsx
AvastWin32:DangerousSig [Trj]
TencentMalware.Win32.Gencirc.13b2de79
EmsisoftTrojan.GenericKD.61136428 (B)
F-SecureTrojan.TR/AD.Remcos.fcrcx
BaiduWin32.Trojan.Kryptik.jm
VIPRETrojan.GenericKD.61136428
TrendMicroTrojanSpy.Win32.REDLINE.AKCRDC
McAfee-GW-EditionGenericRXTW-DP!3EACCA91216D
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GDataWin32.Backdoor.Remcos.6Y136D
JiangminTrojan.Agent.ebyf
WebrootW32.Trojan.Gen
AviraTR/AD.Remcos.fcrcx
Antiy-AVLTrojan/Win32.Convagent
XcitiumMalware@#3c9shbpecineo
ArcabitTrojan.Generic.D3A4DE2C
ZoneAlarmHEUR:Trojan.Win32.Agent.pef
MicrosoftTrojan:Win32/Redline.MD!MTB
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R508738
Acronissuspicious
VBA32BScope.TrojanDownloader.Smoke
ALYacBackdoor.Remcos.A
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/Chgt.AD
TrendMicro-HouseCallTrojanSpy.Win32.REDLINE.AKCRDC
RisingMalware.Obscure/Heur!1.A89F (KTSE)
IkarusTrojan.Win32.Raccrypt
MaxSecureTrojan.Malware.771626.susgen
FortinetW32/Remcos.6ADE!tr
AVGWin32:DangerousSig [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Redline.MD!MTB?

Trojan:Win32/Redline.MD!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment