Trojan

Trojan:Win32/Stealc.CA!MTB removal tips

Malware Removal

The Trojan:Win32/Stealc.CA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Stealc.CA!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Punjabi
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Detects Bochs through the presence of a registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempted to write directly to a physical drive
  • Accessed credential storage registry keys
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Stealc.CA!MTB?


File Info:

name: E612B40F6B9BF20E68E9.mlw
path: /opt/CAPEv2/storage/binaries/5ec2a11573e4ca422f317173d59c386786745a84cee1dd02bab28e7d4e0cb8c0
crc32: 9E181659
md5: e612b40f6b9bf20e68e97f4b47a91a27
sha1: 1a3b5d72671c512c252a2a1ec6ef08eb79aa3e73
sha256: 5ec2a11573e4ca422f317173d59c386786745a84cee1dd02bab28e7d4e0cb8c0
sha512: 761825642789cace9ef16b2acc06a73cc239d489dffa3aac021304a23ac57c94daf08afe62709a2c081168c52eb2d806b859360fe61081e43a23e0d1e37bece5
ssdeep: 98304:4CxbO1WMg9SFck0nBGeGwKQBFr8E8jk7iVEODGeYCdmOGdOWo:J6/gQik0nB7GpQTuVRDPYv1K
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12A16234382E13D46EA6AAB329F5FC6EC770DF260CE1977251229DE6F14B10B6C663311
sha3_384: bad8a730926aa7766775a13dd79c7f014c888b28b040d450775099c019c328ab2d013fc85f5ae31a9d56a6c9147b2e7f
ep_bytes: e84a290000e978feffff8bff558bec51
timestamp: 2022-10-06 19:27:40

Version Info:

FileDescription: Mabling
LegalCopyright: Copyright (C) 2022, Crazy
OriginalFilename: Munpler
ProductsVersion: 19.3.71.61
ProductionVersion: 16.78.79.2
Translation: 0x25ad 0x0e92

Trojan:Win32/Stealc.CA!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Windigo.l!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ransom.Loki.7379
FireEyeGeneric.mg.e612b40f6b9bf20e
SkyhighBehavesLike.Win32.Generic.rc
McAfeeArtemis!E612B40F6B9B
Cylanceunsafe
ZillyaTrojan.Kryptik.Win32.4384935
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanSpy:Win32/Stealc.aa7ba9db
K7GWTrojan ( 00587def1 )
K7AntiVirusTrojan ( 00587def1 )
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.HVLJ
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packer.pkr_ce1a-9980177-0
KasperskyHEUR:Trojan-Spy.Win32.Windigo.gen
BitDefenderGen:Variant.Ransom.Loki.7379
NANO-AntivirusTrojan.Win32.Windigo.keznpl
AvastWin32:PWSX-gen [Trj]
TencentTrojan.Win32.Obfuscated.gen
EmsisoftGen:Variant.Ransom.Loki.7379 (B)
F-SecureTrojan.TR/AD.CloudGenRKIT.iycys
DrWebTrojan.Siggen22.24049
VIPREGen:Variant.Ransom.Loki.7379
TrendMicroTROJ_GEN.R002C0DL623
SophosTroj/Krypt-VK
SentinelOneStatic AI – Malicious PE
VaristW32/Kryptik.LET.gen!Eldorado
AviraTR/AD.CloudGenRKIT.iycys
Antiy-AVLTrojan/Win32.Tofsee
KingsoftWin32.Troj.Unknown.a
MicrosoftTrojan:Win32/Stealc.CA!MTB
ArcabitTrojan.Ransom.Loki.D1CD3
ZoneAlarmHEUR:Trojan-Spy.Win32.Windigo.gen
GDataGen:Variant.Ransom.Loki.7379
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R611971
MAXmalware (ai score=88)
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0DL623
RisingMalware.Obscure!1.A3BB (CLASSIC)
IkarusTrojan.Win32.Azorult
MaxSecureTrojan.Malware.90397263.susgen
FortinetW32/GenKryptik.ERHN!tr
AVGWin32:PWSX-gen [Trj]
Cybereasonmalicious.2671c5
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Stealc.CA!MTB?

Trojan:Win32/Stealc.CA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment