Trojan

About “Trojan:Win32/RedLineStealer.RPZ!MTB” infection

Malware Removal

The Trojan:Win32/RedLineStealer.RPZ!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/RedLineStealer.RPZ!MTB virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan:Win32/RedLineStealer.RPZ!MTB?


File Info:

name: 7063E711A42E8F578A15.mlw
path: /opt/CAPEv2/storage/binaries/5c2833101e79e8c712a57d535d0cb91c125cbad3f1ac80a8cd099c28e760f70d
crc32: 7243E6B2
md5: 7063e711a42e8f578a1503d7c6bd9c81
sha1: dfc691027995da2011ee667c8aac3446b40c2304
sha256: 5c2833101e79e8c712a57d535d0cb91c125cbad3f1ac80a8cd099c28e760f70d
sha512: 9cfca3110cdfc72e54a9942ad4eaa7d97b605a5f02e2df67109a7b791d4fea26913dab498049fce1805ef0c2557d5a7018916f7d5a4dfe4db1984da54246efa6
ssdeep: 24576:kiuBtZj8qL+XLwcxqf7cEnrJR7bcX1//wm3s2l5yffQkQ6MBaAVxl:TuBfQF8fA3XGm7QQGMBaAVxl
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T18315021079D28132D8735D3246E9F6B9927CF6A0476619E777A02BBD0F201C1E2B29DF
sha3_384: 1e09a73f9d654827ef462253d2b038452c6ba5a863d4f943e6d1055b3a7ed0fd6c3a78c29b0719f80156f97d0493153e
ep_bytes: e898070000e974feffff558bec8b4508
timestamp: 2023-09-13 18:24:50

Version Info:

0: [No Data]

Trojan:Win32/RedLineStealer.RPZ!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Convagent.4!c
MicroWorld-eScanGen:Variant.Lazy.391539
ClamAVWin.Trojan.Stealerc-10008534-0
FireEyeGeneric.mg.7063e711a42e8f57
CAT-QuickHealTrojan.StealercPMF.S31159036
SkyhighBehavesLike.Win32.Generic.dc
McAfeeGenericRXWJ-AT!7063E711A42E
Cylanceunsafe
ZillyaTrojan.Stealerc.Win32.8890
SangforInfostealer.Win32.Redline.Ve6z
K7AntiVirusTrojan ( 005abe431 )
AlibabaTrojanPSW:Win32/Redline.9e63d6ec
K7GWTrojan ( 005ab31d1 )
BitDefenderThetaGen:NN.ZexaF.36680.6yW@ayDRzlpi
SymantecTrojan.Whispergate
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HTQR
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-PSW.Win32.Stealerc.pef
BitDefenderGen:Variant.Lazy.391539
NANO-AntivirusTrojan.Win32.Inject4.kagycq
AvastWin32:CrypterX-gen [Trj]
TencentTrojan-PSW.Win32.Stealerc.hr
EmsisoftGen:Variant.Lazy.391539 (B)
F-SecureHeuristic.HEUR/AGEN.1366948
DrWebTrojan.Inject4.61027
VIPREGen:Variant.Lazy.391539
SophosTroj/Krypt-ABY
IkarusTrojan.Win32.Krypt
GDataWin64.Trojan.Agent.BON
JiangminBackdoor.Mokes.hqq
GoogleDetected
AviraHEUR/AGEN.1366948
Antiy-AVLTrojan/Win32.Sabsik
KingsoftWin32.Troj.Generic.v
XcitiumMalware@#3qs0k7a16xzis
ArcabitTrojan.Lazy.D5F973
ZoneAlarmHEUR:Trojan-PSW.Win32.Stealerc.pef
MicrosoftTrojan:Win32/RedLineStealer.RPZ!MTB
VaristW32/Kryptik.KQV.gen!Eldorado
AhnLab-V3Malware/Win.Generic.R605461
VBA32TrojanPSW.RedLine
ALYacGen:Variant.Lazy.391539
MAXmalware (ai score=83)
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/CI.A
RisingBackdoor.Agent!1.EB3F (CLASSIC)
YandexTrojan.Kryptik!qu4zaKBH5/4
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.HUTD!tr
AVGWin32:CrypterX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/RedLineStealer.RPZ!MTB?

Trojan:Win32/RedLineStealer.RPZ!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment