Trojan

Trojan:Win64/Coinminer.RB!MTB (file analysis)

Malware Removal

The Trojan:Win64/Coinminer.RB!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win64/Coinminer.RB!MTB virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win64/Coinminer.RB!MTB?


File Info:

name: 283BC9467395F02EEF2C.mlw
path: /opt/CAPEv2/storage/binaries/85188ed7c6cd24091f25b61d8ed84d052c3f612a60e161c8482986ed3e699f26
crc32: 05FD07FE
md5: 283bc9467395f02eef2c4e475432f7b6
sha1: d0b5509f8953fddeb31d99f6aaf4dd4c5769f65d
sha256: 85188ed7c6cd24091f25b61d8ed84d052c3f612a60e161c8482986ed3e699f26
sha512: 87fe9a26d5bd8580a5b0aefa77a40948321ab537126b41ef6ed40f89785084386ca6419e804b03ae27cec997141fef2ca626260f285effe272dbb5409cb26738
ssdeep: 49152:NsEwA/RRal7H55M3sJCjptYvkpUeLQdDfVNqG8dr7XZ:WDA/RRY7HI3nNtbpUeLQdxNkXX
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T1BEC533043B07D9ADDB7A4A786EB15FD27191A7E04696F2F3A14AF0290094DC4BE3F790
sha3_384: 4bc8f3a71547d8e25f2af203c0f19a05b14616d7b2e39c5e5e1ef3b3e840c9d9ea2746d2a1c63bdfb298556962d8527f
ep_bytes: 4883ec28488b05d54e0000c700010000
timestamp: 2023-12-25 10:21:37

Version Info:

0: [No Data]

Trojan:Win64/Coinminer.RB!MTB also known as:

BkavW64.AIDetectMalware
LionicTrojan.Win32.Miner.4!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Tedy.488309
FireEyeGeneric.mg.283bc9467395f02e
SkyhighBehavesLike.Win64.Trojan.vh
ALYacGen:Variant.Tedy.488309
Cylanceunsafe
SangforTrojan.Win64.Kryptik.V4yr
K7AntiVirusTrojan ( 005af85d1 )
AlibabaTrojan:Win64/Coinminer.00bc8209
K7GWTrojan ( 005af85d1 )
Cybereasonmalicious.f8953f
ArcabitTrojan.Tedy.D77375
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win64/Kryptik.EDF
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win64.Miner.pef
BitDefenderGen:Variant.Tedy.488309
AvastWin64:Evo-gen [Trj]
TencentWin32.Trojan.Agent.Jajl
SophosMal/Generic-S
F-SecureTrojan.TR/Kryptik.kvygd
VIPREGen:Variant.Tedy.488309
EmsisoftGen:Variant.Tedy.488309 (B)
IkarusTrojan.Win64.Krypt
AviraTR/Kryptik.kvygd
MAXmalware (ai score=87)
Antiy-AVLTrojan/Win64.GenKryptik
GridinsoftTrojan.Win64.CoinMiner.sa
MicrosoftTrojan:Win64/Coinminer.RB!MTB
ViRobotTrojan.Win.Z.Tedy.2598202.A
ZoneAlarmHEUR:Trojan.Win64.Miner.pef
GDataGen:Variant.Tedy.488309
VaristW64/Agent.HWR.gen!Eldorado
AhnLab-V3Dropper/Win.DropperX-gen.R622355
McAfeeArtemis!283BC9467395
MalwarebytesTrojan.Downloader
PandaTrj/GdSda.A
RisingTrojan.Agent!8.B1E (TFE:5:Hq24sHNUm4U)
FortinetW64/GenKryptik.GQCB!tr
AVGWin64:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Trojan:Win64/Coinminer.RB!MTB?

Trojan:Win64/Coinminer.RB!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment