Trojan

What is “Trojan:Win32/TrickBotCrypt.DL!MTB”?

Malware Removal

The Trojan:Win32/TrickBotCrypt.DL!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/TrickBotCrypt.DL!MTB virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Kannada
  • Looks up the external IP address

Related domains:

myexternalip.com
158.102.105.176.zen.spamhaus.org
158.102.105.176.cbl.abuseat.org
158.102.105.176.b.barracudacentral.org
158.102.105.176.dnsbl-1.uceprotect.net
158.102.105.176.spam.dnsbl.sorbs.net

How to determine Trojan:Win32/TrickBotCrypt.DL!MTB?


File Info:

crc32: FC63A55C
md5: e2e034dfa6cc9e5dae4121a0b3fa6d56
name: E2E034DFA6CC9E5DAE4121A0B3FA6D56.mlw
sha1: 210eeadcffea02e7e7376423b818833af6a909b1
sha256: e4d2675a178319609e0b022d9dfed2b6e68d1d269b0b4e25ed63cc24f7296841
sha512: e0a9f62b9b23600fe18de9e5db842bed3095772c711c05cb8b1bb8d64ba3356e72a1e160905b0ca9364b24839b2d00f87d92b830b0b24260fa314e33af939ef0
ssdeep: 6144:ybRfnjXFr2KmL3bbHHjYXWOZcy8QGd37ci/fW6/gNXtlTF5yVNU5JhJDCyFE:UZr2XHHmjMd1W6/gNXtrkVQhJDrG
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: asq.exe
FileVersion: 151.0.5.81.asq.exe
CompanyName: cart machine corp.
ProductVersion: 151.0.5.81.asq.exe
FileDescription: deli hevet associacy limte
OriginalFilename: asq.exe
Translation: 0x004b 0x04b0

Trojan:Win32/TrickBotCrypt.DL!MTB also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.KillProc2.16379
ClamAVWin.Malware.Generic-9880574-0
McAfeeGenericRXPI-VA!E2E034DFA6CC
CylanceUnsafe
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
ESET-NOD32a variant of Win32/GenKryptik.FHTK
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Trickpak.gen
BitDefenderTrojan.Agent.FKSQ
ViRobotTrojan.Win32.Trickbot.465408
MicroWorld-eScanTrojan.Agent.FKSQ
Ad-AwareTrojan.Agent.FKSQ
SophosML/PE-A
BitDefenderThetaGen:NN.ZexaF.34050.Cu0@a0hEXteQ
FireEyeGeneric.mg.e2e034dfa6cc9e5d
EmsisoftGen:Variant.Trickbot.Zusy.65 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Kryptik.rrwgc
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/TrickBotCrypt.DL!MTB
GDataTrojan.Agent.FKSQ
AhnLab-V3Trojan/Win.Generic.R433064
MAXmalware (ai score=86)
MalwarebytesSpyware.PasswordStealer
PandaTrj/GdSda.A
RisingTrojan.Generic@ML.100 (RDML:1bEpb0+wGK4fS+E2eDQ4jQ)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.FHTK!tr
AVGWin32:Malware-gen
Qihoo-360HEUR/QVM10.1.C13F.Malware.Gen

How to remove Trojan:Win32/TrickBotCrypt.DL!MTB?

Trojan:Win32/TrickBotCrypt.DL!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment