Trojan

About “Trojan:Win32/Tinba.V!MTB” infection

Malware Removal

The Trojan:Win32/Tinba.V!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Tinba.V!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Expresses interest in specific running processes
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Installs itself for autorun at Windows startup

How to determine Trojan:Win32/Tinba.V!MTB?


File Info:

name: 4624309369250A05EFA3.mlw
path: /opt/CAPEv2/storage/binaries/e1fa01f12b30c9dbdb3ee47e6948012339aa5397b3811cc605f86cd2384274c5
crc32: 70070B63
md5: 4624309369250a05efa3e8c2a6024497
sha1: 08ddd5ba6ece320954c2215e9f3d2c5b49e843ac
sha256: e1fa01f12b30c9dbdb3ee47e6948012339aa5397b3811cc605f86cd2384274c5
sha512: b310b4fc7527fa1ef461298b6250cb46ebde21a32342221f220f84e7d55cdbdc84ca935e7ae90ae464715b796924afc39296eac88ec59a804a4aa687cd4d66aa
ssdeep: 1536:8z44CpRkr9DXhH/2m//56RrufqjhzrmKIFAV0E:8zvokZRfN/yFj1qrFAH
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T12C932971E215E487C917D8F2991ECD2168627D7D8AA0851E32E97F6D68B3BE30049F0F
sha3_384: 0dc57f62acfaa5b3b567f3861e243e4d2ee2f576b15d58645a5a3e446b5543bcd727fe6124f98bd300c5175df406e74b
ep_bytes: 5589e55683ec4066c745f2d023c745e8
timestamp: 2015-01-01 16:03:44

Version Info:

CompanyName: Sun Microsystems, Inc.
FileDescription: Java(TM) Platform SE binary
FileVersion: 6.0.310.5
Full Version: 1.6.0_31-b05
InternalName: java
LegalCopyright: Copyright © 2012
OriginalFilename: java.exe
ProductName: Java(TM) Platform SE 6 U31
ProductVersion: 6.0.310.5
Translation: 0x0000 0x04b0

Trojan:Win32/Tinba.V!MTB also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.4624309369250a05
McAfeeGenericRXHB-CT!462430936925
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0052964f1 )
K7GWTrojan ( 004b9f111 )
Cybereasonmalicious.369250
ArcabitTrojan.Zusy.D522CE
VirITTrojan.Win32.Tinba.RL
CyrenW32/S-bd04db17!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Tinba.BF
APEXMalicious
ClamAVWin.Malware.TinyBanker-9877962-1
KasperskyBackdoor.Win32.Hupigon.tipv
BitDefenderGen:Variant.Zusy.336590
NANO-AntivirusTrojan.Win32.Hupigon.dogvlz
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
MicroWorld-eScanGen:Variant.Zusy.336590
AvastWin32:BackdoorX-gen [Trj]
TencentMalware.Win32.Gencirc.10b4633c
Ad-AwareGen:Variant.Zusy.336590
EmsisoftGen:Variant.Zusy.336590 (B)
ComodoTrojWare.Win32.TrojanDownloader.Dofoil.GN@79ajoh
DrWebTrojan.PWS.Tinba.453
ZillyaBackdoor.Hupigon.Win32.210470
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.nm
SophosML/PE-A
IkarusTrojan.Win32.Crypt
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan[Backdoor]/Win32.Hupigon
MicrosoftTrojan:Win32/Tinba.V!MTB
ZoneAlarmBackdoor.Win32.Hupigon.tipv
GDataWin32.Trojan.PSE.17SHAL
AhnLab-V3Backdoor/Win.Hupigon.C4855088
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34182.fq1@aK5SS7f
ALYacGen:Variant.Zusy.336590
TACHYONBackdoor/W32.Hupigon.94720.Z
VBA32Backdoor.Hupigon
MalwarebytesMalware.AI.3181727957
RisingTrojan.Kryptik!1.AF53 (RDMK:cmRtazorqyr7LMBaR8Y7nCMpvMp1)
YandexBackdoor.Hupigon!geHhH2iYWPk
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Tinba.BF!tr
AVGWin32:BackdoorX-gen [Trj]
PandaTrj/Ransom.BH
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan:Win32/Tinba.V!MTB?

Trojan:Win32/Tinba.V!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment