Trojan

About “Trojan.Agent.Delf.Krypt” infection

Malware Removal

The Trojan.Agent.Delf.Krypt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Agent.Delf.Krypt virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the Azorult malware family
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Trojan.Agent.Delf.Krypt?


File Info:

name: 3A711232982B00835C53.mlw
path: /opt/CAPEv2/storage/binaries/c0c3b6ce4cb7070677c13f9432f87dc5901194636793202a60417bdde3909bbe
crc32: BEF2D651
md5: 3a711232982b00835c53070e8766b132
sha1: 359ed981812912376082ed4698d9c5de3c6b34d8
sha256: c0c3b6ce4cb7070677c13f9432f87dc5901194636793202a60417bdde3909bbe
sha512: 088bb84863e3ca282a8390c8683e1483a2b655daac091f057d363de70a8c19bbc57ec97b61320ba3379a96bcfbff193ffb2a1195f48113e8dd7d99a76345a3ad
ssdeep: 3072:tuOSXpMx7ZAlHsbfUkolNGti7lfqeSxM3SpyEYnE/Zxg/:Zzx7ZApszolIo7lf/ipT/Z
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12AB3197AF6C19672E02808BDCD46D1B6912D76302D3918B6B2DA4F8CD5F95C26E2C3C7
sha3_384: 317d2be8876a360a4cc3e0539e732a3bb6cd0156808f6583275be895afb3ac6022bd9acdf81023408f9ef88d30f8acb2
ep_bytes: 558bec83c4f0b890a04100e854abfeff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Trojan.Agent.Delf.Krypt also known as:

LionicTrojan.Win32.Lmir.laiL
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.26517
MicroWorld-eScanTrojan.PWS.ZNN
FireEyeGeneric.mg.3a711232982b0083
CAT-QuickHealTrojan.Sigmal.S3989901
McAfeeGenericRXGI-KI!3A711232982B
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforRansom.Win32.Foreign_18.se
K7AntiVirusPassword-Stealer ( 0052f96e1 )
AlibabaTrojanPSW:Win32/Blocker.28f857ef
K7GWPassword-Stealer ( 0052f96e1 )
Cybereasonmalicious.2982b0
BitDefenderThetaAI:Packer.F1D56E081D
VirITTrojan.Win32.Stealer.BJYQ
CyrenW32/Delf_Troj.D.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32Win32/PSW.Delf.OSF
TrendMicro-HouseCallTrojanSpy.Win32.CLIPBANKER.SMMR
AvastWin32:PWSX-gen [Trj]
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Blocker.lckf
BitDefenderTrojan.PWS.ZNN
NANO-AntivirusTrojan.Win32.Stealer.fflqpr
TencentMalware.Win32.Gencirc.10b0cce1
EmsisoftTrojan-Spy.Agent (A)
ComodoTrojWare.Win32.PWS.Stimilina.O@8037s1
ZillyaTrojan.Blocker.Win32.40079
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
SophosMal/Generic-R + Troj/PWS-CJJ
Paloaltogeneric.ml
JiangminTrojan.PSW.Coins.buh
WebrootW32.Trojan.Gen
AviraTR/AD.MoksSteal.elw
Antiy-AVLTrojan/Generic.ASMalwS.27044F8
KingsoftWin32.Troj.Undef.(kcloud)
GridinsoftRansom.Win32.Azorult.sa
MicrosoftPWS:Win32/Delf.R!MTB
ViRobotTrojan.Win32.Z.Delf.115200.AL
ZoneAlarmTrojan-Ransom.Win32.Blocker.lckf
GDataWin32.Trojan-Stealer.KBot.B
TACHYONTrojan-PWS/W32.DP-InfoStealer.115200
AhnLab-V3Trojan/Win32.Delf.R255889
ALYacTrojan.Agent.Delf.Krypt
MAXmalware (ai score=100)
VBA32BScope.TrojanPSW.Stealer
MalwarebytesSpyware.AzorUlt
APEXMalicious
RisingStealer.AZORult!1.B7AE (CLOUD)
YandexTrojan.GenAsa!zpkWsvf3gpo
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Delf.OSF!tr
AVGWin32:PWSX-gen [Trj]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Agent.Delf.Krypt?

Trojan.Agent.Delf.Krypt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment