Trojan

Should I remove “Trojan:Win32/Sabsik.RM!MTB”?

Malware Removal

The Trojan:Win32/Sabsik.RM!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Sabsik.RM!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/Sabsik.RM!MTB?


File Info:

name: DDA320CDB60094470B14.mlw
path: /opt/CAPEv2/storage/binaries/1b7b6ef3fc21c58be4121dcd66b8e3b1231c0bb49f6e256460cc213775f4dd90
crc32: 99470AA0
md5: dda320cdb60094470b148e93760105f3
sha1: 2dcb621aec4f844fd37c64e6eabee9f827abf93d
sha256: 1b7b6ef3fc21c58be4121dcd66b8e3b1231c0bb49f6e256460cc213775f4dd90
sha512: 9ca7350d5a228df36552bdedc1b5e35af66b01b0464592ba818c31c3beff8fa2c71bcd0e2ad2037b45c4c86577b920a21c5e35a66772c1a2b842d1afeef33e21
ssdeep: 24576:kLcvE4N6whUaZiRAK/cRgOnmq9g6iBcZDy:kYvMf37cOU7m6Lhy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15225EF82A24364A0D4C51BBD07F39A4E05D7EAC96E0C4DA94F067067709FBEF16E24BD
sha3_384: cc5622326bfc5e01510991b9e20948f1c771016dc05447bcca99dc029c1a16b523f05f2a0a969411d67a0805442d0a77
ep_bytes: 6801105900e801000000c3c38ec2c7c0
timestamp: 2022-01-15 13:28:17

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Print driver host for applications
FileVersion: 10.0.19041.1415 (WinBuild.160101.0800)
InternalName: splwow64.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: splwow64.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 10.0.19041.1415
Translation: 0x0409 0x04b0

Trojan:Win32/Sabsik.RM!MTB also known as:

LionicTrojan.Win32.Bingoml.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.dda320cdb6009447
McAfeeRDN/Generic.dx
MalwarebytesSpyware.PasswordStealer
SangforTrojan.Win32.Bingoml.djkv
K7AntiVirusTrojan ( 005376ae1 )
AlibabaTrojan:Win32/Bingoml.d8350ffd
K7GWTrojan ( 005376ae1 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Generic.D2FB14C2
CyrenW32/Trojan.AUBC-8386
SymantecTrojan.Gen.MBT
ESET-NOD32Win32/Spy.Raccoon.A
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Bingoml.djkv
BitDefenderTrojan.GenericKD.50009282
MicroWorld-eScanTrojan.GenericKD.50009282
AvastWin32:Malware-gen
TencentWin32.Trojan.Bingoml.Wvap
Ad-AwareTrojan.GenericKD.50009282
SophosMal/Generic-S
ComodoMalware@#1hlb9sn801znp
DrWebTrojan.PWS.Raccoon.4
ZillyaTrojan.Raccoon.Win32.199
McAfee-GW-EditionBehavesLike.Win32.Virut.dc
EmsisoftTrojan.GenericKD.50009282 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraTR/AD.StellarStealer.rjbkh
MAXmalware (ai score=86)
KingsoftWin32.Troj.Bingoml.dj.(kcloud)
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.RM!MTB
ZoneAlarmTrojan.Win32.Bingoml.djkv
GDataTrojan.GenericKD.50009282
AhnLab-V3Trojan/Win.Sabsik.R466153
BitDefenderThetaGen:NN.ZexaF.34212.8C0aaOz3Mmhk
ALYacTrojan.PSW.Racealer
VBA32Trojan.Bingoml
TrendMicro-HouseCallTROJ_GEN.R002C0DAH22
RisingSpyware.Raccoon!8.1235D (CLOUD)
IkarusTrojan.Win32.Spy
FortinetW32/Kryptik.HMAS!tr
AVGWin32:Malware-gen
PandaTrj/CI.A
MaxSecureTrojan.Malware.138630309.susgen

How to remove Trojan:Win32/Sabsik.RM!MTB?

Trojan:Win32/Sabsik.RM!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment