Trojan

Trojan.KatushaIH.S19399313 information

Malware Removal

The Trojan.KatushaIH.S19399313 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.KatushaIH.S19399313 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Queries information on disks, possibly for anti-virtualization
  • Behavior consistent with a dropper attempting to download the next stage.
  • Detects the presence of Wine emulator via registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
static.43.47.69.159.clients.your-server.de

How to determine Trojan.KatushaIH.S19399313?


File Info:

crc32: F54D4A68
md5: 7b9eef0f857fabe6dbed19d94936f195
name: 7B9EEF0F857FABE6DBED19D94936F195.mlw
sha1: 5a9a8e99fecb7cac8dbd0f66aca05832896fb51c
sha256: 1a2fa8e036973da3ba8d464e6da8406e24880d970f0ea09e9470976b035fccc5
sha512: 96df362d8c5ba8a9cf93f7eb940b1432ac2bf048a8ebc6ec84e97e78c83d3c8be4b16232d890f70b2b6791914cfa31a33ee5b7254e8a7c2876b944ab1a952908
ssdeep: 49152:9dd0ty8hYcD3+HuaJ0ooAkqPDsPGmt4SOGeMVwKFG:9dWtYc6bJ0J4oPGmtGMtG
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 1998-2001 Orland Software Corporation
InternalName: WSDLIMP
FileVersion: 7.0.4.453
CompanyName: Orland Software Corporation
ProductName: Orland WSDL Import Utility
ProductVersion: 7.0.4.453
FileDescription: Orland Type Library Exporter
OriginalFilename: WSDLIMP.EXE
Translation: 0x0409 0x04e4

Trojan.KatushaIH.S19399313 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00537eb21 )
LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.InstallCube.3557
CynetMalicious (score: 100)
CAT-QuickHealTrojan.KatushaIH.S19399313
ALYacGen:Variant.Ser.Symmi.274
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.1459502
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaTrojan:Win32/Katusha.f2d5b3fb
K7GWTrojan ( 00537eb21 )
Cybereasonmalicious.f857fa
CyrenW32/S-8d843ca2!Eldorado
SymantecPUA.ICLoader
ESET-NOD32a variant of Win32/Kryptik.GIWZ
APEXMalicious
AvastWin32:ICLoader-X [Adw]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ser.Symmi.274
NANO-AntivirusTrojan.Win32.Ekstak.ffkkbu
MicroWorld-eScanGen:Variant.Ser.Symmi.274
TencentTrojan.Win32.Kryptik.gitv
Ad-AwareGen:Variant.Ser.Symmi.274
SophosMal/Generic-S
ComodoApplication.Win32.ICLoader.GS@84429a
BitDefenderThetaGen:NN.ZexaF.34236.@r0@ae1gqRoi
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.7b9eef0f857fabe6
EmsisoftGen:Variant.Ser.Symmi.274 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Ekstak.mdo
AviraTR/ICLoader.Gen8
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASBOL.C50A
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:Packed.Win32.Katusha.gen
GDataWin32.Application.ICLoader.F
TACHYONTrojan/W32.Agent.2093056.EB
AhnLab-V3PUP/Win32.ICLoader.R231998
Acronissuspicious
McAfeePacked-FHK!7B9EEF0F857F
VBA32Backdoor.IRCBot
MalwarebytesAdware.InstallCube
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.AA23 (CLASSIC)
YandexTrojan.GenAsa!q7RpYYwjWMg
IkarusTrojan.Win32.Crypt
FortinetW32/CoinMiner.GYQC!tr
AVGWin32:ICLoader-X [Adw]
Paloaltogeneric.ml

How to remove Trojan.KatushaIH.S19399313?

Trojan.KatushaIH.S19399313 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment