Trojan

Trojan.Krypter information

Malware Removal

The Trojan.Krypter is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Krypter virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Latvian
  • The binary likely contains encrypted or compressed data.
  • Looks up the external IP address
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Network activity contains more than one unique useragent.
  • CAPE detected the OnlyLogger malware family
  • Attempts to modify proxy settings
  • Created network traffic indicative of malicious activity
  • Uses suspicious command line tools or Windows utilities

Related domains:

hypecreator.top
iplogger.org
api.ip.sb
freegeoip.app

How to determine Trojan.Krypter?


File Info:

name: 746A477A2D6A5738FB7C.mlw
path: /opt/CAPEv2/storage/binaries/7f6081a5ef470a34491982145f673bd035be944b0524bf93bc7c10d772606958
crc32: 0A3E6AA7
md5: 746a477a2d6a5738fb7c39cf1a8b8bf2
sha1: fa0a4b7e64052d382411cecf08eb5ade7565b9fd
sha256: 7f6081a5ef470a34491982145f673bd035be944b0524bf93bc7c10d772606958
sha512: ab959cd43ab2823b4a71727bdead43776ee18ee5a3ef7d613deaa5ea22ec9b993b67877d825b4989eeaa1a63823cdcf947b64c274b95ff04a4b5561fd84e4cce
ssdeep: 6144:TeTp4UZKd+O5l/TOwUpTDoHLASm87T1GoQoeD:Tep4UZ6tdTOddBSm8hQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11E54F11036F0D8B2DAE76B302834CA965DFFBC716935814B2769322A2F717D08979793
sha3_384: 37c40f37d59056140ed892163a4af994b597acdf652a4c0e2d6ecbd9e2c2b0b063a3acdb8565fadeac4fc505fa74806d
ep_bytes: e8d02a0000e989feffff8bff558bec68
timestamp: 2021-02-25 13:17:26

Version Info:

InternalName: bomgpiaruci.iwa
Copyright: Copyrighz (C) 2021, fudkat
ProductVersion: 13.54.77.25
Translation: 0x0114 0x046a

Trojan.Krypter also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.47471681
FireEyeGeneric.mg.746a477a2d6a5738
ALYacTrojan.GenericKD.47471681
CylanceUnsafe
K7AntiVirusTrojan ( 00589d2d1 )
AlibabaTrojanDownloader:Win32/Raccrypt.6ab6ccee
K7GWTrojan ( 00589d2d1 )
Cybereasonmalicious.e64052
CyrenW32/StopCrypt.B.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HNKH
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Downloader.Win32.Upatre.gen
BitDefenderTrojan.GenericKD.47471681
AvastWin32:CrypterX-gen [Trj]
Ad-AwareTrojan.GenericKD.47471681
EmsisoftTrojan.Crypt (A)
DrWebTrojan.Siggen15.50227
TrendMicroTROJ_GEN.R002C0DKP21
McAfee-GW-EditionBehavesLike.Win32.Trojan.dc
SophosMal/Generic-R + Mal/Agent-AWV
IkarusTrojan-Ransom.StopCrypt
WebrootW32.Trojan.Gen
AviraTR/AD.Chapak.cvqrc
Antiy-AVLTrojan/Generic.ASMalwS.34D6BDD
GridinsoftRansom.Win32.STOP.sa
MicrosoftTrojan:Win32/Azorult.RT!MTB
GDataWin32.Trojan.BSE.OT0ZCL
CynetMalicious (score: 100)
AhnLab-V3CoinMiner/Win.Glupteba.R452303
Acronissuspicious
McAfeeLockbit-FSWW!746A477A2D6A
MAXmalware (ai score=86)
VBA32Trojan.Krypter
MalwarebytesTrojan.MalPack.GS
TrendMicro-HouseCallTROJ_GEN.R002C0DKP21
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.PSE!tr
BitDefenderThetaGen:NN.ZexaF.34294.rq0@ayERdtmI
AVGWin32:CrypterX-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Krypter?

Trojan.Krypter removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment