Trojan

Trojan:Win32/Trickbot.simd!MTB information

Malware Removal

The Trojan:Win32/Trickbot.simd!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Trickbot.simd!MTB virus can do?

  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Urdu (Pakistan)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavior consistent with a dropper attempting to download the next stage.
  • Attempts to modify proxy settings

How to determine Trojan:Win32/Trickbot.simd!MTB?


File Info:

name: 38F20008EEC7B6474925.mlw
path: /opt/CAPEv2/storage/binaries/a4037d132423b6501700e2983156cdd80307c36fb8514b0c0bbf894821576074
crc32: 534E8B37
md5: 38f20008eec7b64749250c53443a7714
sha1: b91c6bd0454fa03ce1b92497e5c43f76e0d3fe17
sha256: a4037d132423b6501700e2983156cdd80307c36fb8514b0c0bbf894821576074
sha512: d1fdcbecf41614427126e1dcd6dd3504e67e73431204f5dc59dfb42b9cae2271f0ca4aba418c8420304e6a15022a0b47f76ef5053513effe00c9205887c06326
ssdeep: 768:tBV7+k89UWA1wp7zVgU72MLUZcuiJp+44VhcfbV/3/KrQVxtFjLP4:tBVK2gV9Fhui7+44VmfbVXKrQPtFjk
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13933E7DAE79445F5E0513934C1339EFB4A3B203D7D2101867A98F83EFEBEAD14626252
sha3_384: fd5e9b7b9caf55ea94ceb38c64ea50a31cc69a6c59716c715cfa6d4072c81af0729cdd01232889f3bb45803ed5b6071c
ep_bytes: 558bec6aff6890644000685855400064
timestamp: 2013-04-07 22:51:15

Version Info:

0: [No Data]

Trojan:Win32/Trickbot.simd!MTB also known as:

BkavW32.AIDetect.malware2
tehtrisGeneric.Malware
DrWebTrojan.Upatre.3343
MicroWorld-eScanTrojan.Upatre.Gen.3
FireEyeGeneric.mg.38f20008eec7b647
CAT-QuickHealTrojan.Kadena.B4
ALYacTrojan.Upatre.Gen.3
CylanceUnsafe
Sangfor[ARMADILLO V1.71]
K7AntiVirusTrojan ( 004c75411 )
K7GWTrojan ( 004c75411 )
Cybereasonmalicious.8eec7b
BitDefenderThetaGen:NN.ZexaF.34606.dqX@a4@HPEfG
VirITTrojan.Win32.Generic.EUE
CyrenW32/Upatre.AS.gen!Eldorado
SymantecDownloader.Upatre!gen5
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.DLZD
TrendMicro-HouseCallTROJ_UPATRE.SM37
ClamAVWin.Downloader.Upatre-9909423-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Upatre.Gen.3
NANO-AntivirusTrojan.Win32.Upatre.dssjef
SUPERAntiSpywareTrojan.Agent/Gen-Upatre
AvastWin32:Malware-gen
TencentTrojan.Win32.Kryptik.dlzda
Ad-AwareTrojan.Upatre.Gen.3
EmsisoftTrojan.Upatre.Gen.3 (B)
ComodoTrojWare.Win32.TrojanDownloader.Upatre.NY@5s465i
F-SecureTrojan.TR/Downloader.Gen7
BaiduWin32.Trojan.Kryptik.jw
ZillyaDownloader.UpatreGen.Win32.23
TrendMicroTROJ_UPATRE.SM37
McAfee-GW-EditionUpatre-FACM!38F20008EEC7
SentinelOneStatic AI – Malicious PE
SophosML/PE-A + Troj/Upatre-NY
IkarusTrojan-Banker.TrickBot
GDataWin32.Trojan-Downloader.Upatre.AE
JiangminTrojanDownloader.Upatre.mso
AviraTR/Downloader.Gen7
Antiy-AVLTrojan/Generic.ASMalwS.119C91B
ArcabitTrojan.Upatre.Gen.3
MicrosoftTrojan:Win32/Trickbot.simd!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.FakeDoc.R465884
McAfeeUpatre-FACM!38F20008EEC7
VBA32BScope.Trojan.Upatre
MalwarebytesTrojan.Upatre.VT
APEXMalicious
RisingMalware.FakePDF/ICON!1.A24C (RDMK:cmRtazokq0nFe7H22YyUSo61C7dP)
YandexTrojan.GenAsa!F+MDvoMFOVU
MAXmalware (ai score=84)
MaxSecureTrojan.Upatre.Gen
FortinetW32/Daserf.B!tr
AVGWin32:Malware-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan:Win32/Trickbot.simd!MTB?

Trojan:Win32/Trickbot.simd!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment