Spy Trojan

Trojan:Win32/SpyStealer.AU!MTB (file analysis)

Malware Removal

The Trojan:Win32/SpyStealer.AU!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/SpyStealer.AU!MTB virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the Vidar malware family
  • Anomalous binary characteristics

How to determine Trojan:Win32/SpyStealer.AU!MTB?


File Info:

name: 14E455E70814E6C61635.mlw
path: /opt/CAPEv2/storage/binaries/ebb9294dcce30bf6cf60d7451b0ace1e780487099c85960439b8b19dd781439a
crc32: 3FEA4F66
md5: 14e455e70814e6c616358efaa092a232
sha1: 52e6794b54281ad19b7922fe2e1e978c6d7a2bca
sha256: ebb9294dcce30bf6cf60d7451b0ace1e780487099c85960439b8b19dd781439a
sha512: 2222397379d70b44cf602431e2a7233d8d942be4a9a65a551b67e84b97144860d53a188a30c1c8202e1a9b7e03fc4356fe5bfa9de9e9f458ae4d7fada2f5a8e1
ssdeep: 24576:3J3BJMbDezfC6kZf7FVB/tkiYkiwKYi60vPodOYuQ5p3h35h:1zsOsfVKHkcYim
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1E6B51A039A8B4E75DDD23BB461CB633A9734FD30CA2A9B7FE708C53559632C4681A712
sha3_384: 777353ada4d4e2e434f1da72e031d22d8699e0877ba7dc2467be2b3aaa4dcc115fb90c8fea0997bb91ff09ec9a2becee
ep_bytes: 83ec1cc7042401000000ff15cc825300
timestamp: 2022-05-27 20:47:25

Version Info:

0: [No Data]

Trojan:Win32/SpyStealer.AU!MTB also known as:

Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.GenericKDZ.88244
ALYacTrojan.GenericKDZ.88244
CylanceUnsafe
ArcabitTrojan.Generic.D158B4
CyrenW32/Wacatac.EE.gen!Eldorado
ESET-NOD32a variant of Win32/Kryptik.HPTA
ClamAVWin.Keylogger.Generickdz-9951136-0
KasperskyHEUR:Trojan-Spy.Win32.Stealer.gen
BitDefenderTrojan.GenericKDZ.88244
AvastWin32:Malware-gen
Ad-AwareTrojan.GenericKDZ.88244
EmsisoftTrojan.GenericKDZ.88244 (B)
DrWebTrojan.Inject4.32809
FireEyeTrojan.GenericKDZ.88244
WebrootW32.Trojan.Genkdz
MAXmalware (ai score=80)
MicrosoftTrojan:Win32/SpyStealer.AU!MTB
GDataWin32.Trojan.PSE.168GJNY
AhnLab-V3Trojan/Win.Generic.R495243
McAfeeGenericRXTE-ZT!14E455E70814
VBA32TrojanSpy.Stealer
MalwarebytesSpyware.Vidar
RisingStealer.Reline!8.132F4 (TFE:dGZlOgXLfQ0e5lVocQ)
SentinelOneStatic AI – Suspicious PE
FortinetW32/GenKryptik.FUXS!tr
BitDefenderThetaGen:NN.ZexaF.34712.x!Z@a4Zxrun
AVGWin32:Malware-gen

How to remove Trojan:Win32/SpyStealer.AU!MTB?

Trojan:Win32/SpyStealer.AU!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment