Trojan

What is “Trojan:Win64/Coinminer.RB!MTB”?

Malware Removal

The Trojan:Win64/Coinminer.RB!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win64/Coinminer.RB!MTB virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win64/Coinminer.RB!MTB?


File Info:

name: A0909FC0F5E5152FD8F6.mlw
path: /opt/CAPEv2/storage/binaries/88dc9bb9a4ac54afa660205dd270398933426c600bf3f4e32d5b4f85e70c01ab
crc32: 8463AB13
md5: a0909fc0f5e5152fd8f6ae7d00ed4b4a
sha1: efbb92a82497ac3f5d667bdbd7e38691c601ae1b
sha256: 88dc9bb9a4ac54afa660205dd270398933426c600bf3f4e32d5b4f85e70c01ab
sha512: 17da9f1af4e3621860f69f875258324a7bb337c5ff524b504e84b552f79fb7b1fb7d427700ea040d6ee74be268fd5fa6a3877e7bedc67e9b0e7176af6add936f
ssdeep: 49152:7EAh02jxrhuGdh2VlVMxo4cbgDcKdBHclBlOQlb5ajm8OOMx6u24ny:7csrhP+Vgo4MgwKdO7FlaCkZu24
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T15BC5331E7355B0ECE814863B66E4FE5B495ADD230B26B1C7EFF0D84A5AF12CAD835810
sha3_384: 5d8da2e82fd846fc5cb6cbe476e5a6a79100d3760402925337be251105e8c7ef7ed4e9014c78643f86e8d94bdc201a18
ep_bytes: 4883ec28488b05d54e0000c700010000
timestamp: 2023-12-23 11:04:48

Version Info:

0: [No Data]

Trojan:Win64/Coinminer.RB!MTB also known as:

BkavW64.AIDetectMalware
LionicTrojan.Win32.Agent.Y!c
MicroWorld-eScanGen:Variant.Tedy.488309
FireEyeGeneric.mg.a0909fc0f5e5152f
SkyhighBehavesLike.Win64.Generic.vh
McAfeeArtemis!A0909FC0F5E5
Cylanceunsafe
VIPREGen:Variant.Tedy.488309
SangforTrojan.Win64.Kryptik.V1ei
K7AntiVirusTrojan ( 005af85d1 )
AlibabaTrojan:Win64/Coinminer.36de29c3
K7GWTrojan ( 005af85d1 )
Cybereasonmalicious.82497a
ArcabitTrojan.Tedy.D77375
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win64/Kryptik.EDF
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Agent.gen
BitDefenderGen:Variant.Tedy.488309
AvastWin64:Evo-gen [Trj]
RisingTrojan.Agent!8.B1E (TFE:5:Hq24sHNUm4U)
Ad-AwareGen:Variant.Tedy.488309
EmsisoftGen:Variant.Tedy.488309 (B)
GoogleDetected
Antiy-AVLTrojan/Win64.GenKryptik
Kingsoftmalware.kb.a.1000
MicrosoftTrojan:Win64/Coinminer.RB!MTB
ZoneAlarmHEUR:Trojan.Win32.Agent.gen
GDataGen:Variant.Tedy.488309
VaristW64/Agent.HWR.gen!Eldorado
AhnLab-V3Dropper/Win.DropperX-gen.R622355
ALYacGen:Variant.Tedy.488309
MAXmalware (ai score=87)
MalwarebytesTrojan.Downloader
TencentWin32.Trojan.Agent.Majl
IkarusTrojan.Win64.Krypt
FortinetW64/GenKryptik.GQCB!tr
AVGWin64:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Trojan:Win64/Coinminer.RB!MTB?

Trojan:Win64/Coinminer.RB!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment