Malware

Python/Kryptik.AU malicious file

Malware Removal

The Python/Kryptik.AU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Python/Kryptik.AU virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the PyInstaller malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Python/Kryptik.AU?


File Info:

name: 80C573DE11D6215C15F3.mlw
path: /opt/CAPEv2/storage/binaries/06a000c6d80fd9b9b540be6fe297e83c750ef10beb6b296571609222ab05eec2
crc32: B8D585B7
md5: 80c573de11d6215c15f31d51e6cf0c21
sha1: 3e9ec781bef5e3f6b9aa35cd031bbd445335c049
sha256: 06a000c6d80fd9b9b540be6fe297e83c750ef10beb6b296571609222ab05eec2
sha512: 350bfac7961d583063f8c3c47fe27266c717d533394f18c24b279a350e47d299923f0605a9d9e5e957a55064deec82a2f04544b1e9cb37b71e4429ec74777ec8
ssdeep: 196608:aUViGLoP1HOXfZ8bnt0g7tbYPvbJQlHw58C/AYIc9CrNc:aUVeP1IR8JDkJQlylC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10886334BFAC1B434D2972736A2A1D03A55697D0437F02DBB9FE738A4D8BA2D47E74024
sha3_384: da61bb369d963b06666dd14e08d53aaf12ccb308e7571d9afbe33334b60d1df39ce04d32fa68e96188aee9302e3e1b96
ep_bytes: e838050000e98efeffffcccccc575653
timestamp: 2020-01-05 12:16:35

Version Info:

0: [No Data]

Python/Kryptik.AU also known as:

BkavW32.Common.07EAC30E
Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.GenericKD.71684892
FireEyeGeneric.mg.80c573de11d6215c
SkyhighBehavesLike.Win32.Generic.wc
ALYacTrojan.GenericKD.71684892
Cylanceunsafe
VIPRETrojan.GenericKD.71684892
SangforTrojan.Win32.Kryptik.Vg39
AlibabaTrojan:Win32/Kryptik.e961ac66
ArcabitTrojan.Generic.D445D31C
SymantecTrojan.Gen.MBT
ESET-NOD32Python/Kryptik.AU
APEXMalicious
BitDefenderTrojan.GenericKD.71684892
AvastWin32:Trojan-gen
SophosMal/Generic-S
F-SecureTrojan.TR/Kryptik.dbope
TrendMicroTrojanSpy.Win32.RHADAMANTHYS.YXEBSZ
EmsisoftTrojan.GenericKD.71684892 (B)
AviraTR/Kryptik.dbope
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataTrojan.GenericKD.71684892
McAfeeArtemis!80C573DE11D6
MAXmalware (ai score=86)
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/Chgt.AD
TrendMicro-HouseCallTrojanSpy.Win32.RHADAMANTHYS.YXEBSZ
MaxSecureTrojan.Malware.234041372.susgen
FortinetW32/Kryptik.AU!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.1bef5e
DeepInstinctMALICIOUS

How to remove Python/Kryptik.AU?

Python/Kryptik.AU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment