Trojan

Trojan:Win64/Coinminer.RB!MTB information

Malware Removal

The Trojan:Win64/Coinminer.RB!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win64/Coinminer.RB!MTB virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win64/Coinminer.RB!MTB?


File Info:

name: F8237724503FD22CEEFE.mlw
path: /opt/CAPEv2/storage/binaries/0f2be04e10720272499e770a64e5a4a04cad5a4474e68cd62ed559f0f6304dba
crc32: 4217D18C
md5: f8237724503fd22ceefe267b151d2dd5
sha1: 78c95a5cee456c55b64585692f65794f445115b3
sha256: 0f2be04e10720272499e770a64e5a4a04cad5a4474e68cd62ed559f0f6304dba
sha512: 907647dc578a6db18c6f172f64fb67d2196d2b0901161b7a53196cbc764a1a8904d77202148499a1cd95cd2ae687c865143c6e1320bfe887cd77aa3d72c8ef29
ssdeep: 49152:7EAh02jxrhuGdh2VlVMxo4cbgDcKdBHclBlOQlb5ajm8OOMx6u24ny:7csrhP+Vgo4MgwKdO7FlaCkZu24
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T176C5331E7355B0ECE814863B66E4FE5B495ADD230B26B1C7EFF0D84A5AF12CAD835810
sha3_384: 0dc4402110f58312e0012b11e720a4c234ce11d6fec114ba9f173e143293378a2de32c2528c7315c559c2380dfb19aba
ep_bytes: 4883ec28488b05d54e0000c700010000
timestamp: 2023-12-23 11:04:48

Version Info:

0: [No Data]

Trojan:Win64/Coinminer.RB!MTB also known as:

BkavW64.AIDetectMalware
LionicTrojan.Win32.Agent.Y!c
MicroWorld-eScanGen:Variant.Tedy.488309
FireEyeGeneric.mg.f8237724503fd22c
SkyhighBehavesLike.Win64.Generic.vh
ALYacGen:Variant.Tedy.488309
Cylanceunsafe
SangforTrojan.Win64.Kryptik.V8ds
K7AntiVirusTrojan ( 005af85d1 )
AlibabaTrojan:Win64/Coinminer.36de29c3
K7GWTrojan ( 005af85d1 )
CrowdStrikewin/malicious_confidence_90% (D)
ArcabitTrojan.Tedy.D77375
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win64/Kryptik.EDF
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Agent.gen
BitDefenderGen:Variant.Tedy.488309
AvastWin64:Evo-gen [Trj]
TencentWin32.Trojan.Agent.Edhl
Ad-AwareGen:Variant.Tedy.488309
SophosMal/Generic-S
VIPREGen:Variant.Tedy.488309
EmsisoftGen:Variant.Tedy.488309 (B)
IkarusTrojan.Win64.Krypt
Antiy-AVLTrojan/Win64.GenKryptik
MicrosoftTrojan:Win64/Coinminer.RB!MTB
ZoneAlarmHEUR:Trojan.Win32.Agent.gen
GDataGen:Variant.Tedy.488309
VaristW64/Agent.HWR.gen!Eldorado
AhnLab-V3Dropper/Win.DropperX-gen.R622355
McAfeeArtemis!F8237724503F
MAXmalware (ai score=88)
MalwarebytesTrojan.Downloader
RisingTrojan.Agent!8.B1E (TFE:5:Hq24sHNUm4U)
FortinetW64/GenKryptik.GQCB!tr
AVGWin64:Evo-gen [Trj]
Cybereasonmalicious.cee456
DeepInstinctMALICIOUS

How to remove Trojan:Win64/Coinminer.RB!MTB?

Trojan:Win64/Coinminer.RB!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment