Trojan

Trojan.Lethic.Gen.14 malicious file

Malware Removal

The Trojan.Lethic.Gen.14 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Lethic.Gen.14 virus can do?

  • At least one process apparently crashed during execution
  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • A named pipe was used for inter-process communication
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Russian
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Code injection with CreateRemoteThread in a remote process
  • Crashed cuckoomon during analysis. Report this error to the Github repo.
  • A process attempted to delay the analysis task by a long amount of time.
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Installs itself for autorun at Windows startup
  • Checks the system manufacturer, likely for anti-virtualization
  • Zeus P2P (Banking Trojan)
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
api.wipmania.com

How to determine Trojan.Lethic.Gen.14?


File Info:

crc32: 28B7C9C1
md5: b236ebf23c08d3e77eb794cbefc76240
name: B236EBF23C08D3E77EB794CBEFC76240.mlw
sha1: 92689950c4249c3eb6a83219f0a54cf298fcbdbb
sha256: d7ace115d6eaedc1de88adaa960fc34f04bb215568396465704204ee568681f0
sha512: 618ffae4b32360a2d2954aab5767c6a3ca5477be33c7e30fa573f51b607f0e1dfa53de313905d7ef922b2e269533504922fc56099a52b4943bdf597fdd87f29e
ssdeep: 3072:mr/fviN6BpiZmvZhs8nl+hPcvEZKX1LIBeE6niLQtBbsM72EgpxU2EfeFM964hLQ:mziNJZmRQmEZ01Lnf7H2q2Eh6qjPPQ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Lethic.Gen.14 also known as:

BkavW32.FamVT.RazyNHmC.Trojan
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader19.40718
MicroWorld-eScanTrojan.Lethic.Gen.14
CAT-QuickHealRansom.Tescrypt.A4
McAfeeRansom-Tescrypt!B236EBF23C08
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004dfe911 )
BitDefenderTrojan.Lethic.Gen.14
K7GWTrojan ( 004dfe911 )
Cybereasonmalicious.23c08d
BitDefenderThetaAI:Packer.90414F6020
CyrenW32/Ransom.FDDJ-3076
SymantecPacked.Generic.521
APEXMalicious
AvastWin32:Dorder-W [Trj]
ClamAVWin.Trojan.Gamarue-6824215-0
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Kryptik.03c8126f
NANO-AntivirusTrojan.Win32.Ngrbot.eaxzqv
RisingWorm.Ngrbot!8.7DD (CLOUD)
Ad-AwareTrojan.Lethic.Gen.14
EmsisoftTrojan.Lethic.Gen.14 (B)
ComodoMalware@#1lr7j5p8ycn4h
F-SecureHeuristic.HEUR/AGEN.1127189
BaiduWin32.Trojan.Kryptik.aio
ZillyaTrojan.Kryptik.Win32.868405
TrendMicroRansom_CRYPTESLA.SMA6
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
FireEyeGeneric.mg.b236ebf23c08d3e7
SophosML/PE-A + Mal/Wonton-BZ
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Bublik.avj
AviraHEUR/AGEN.1127189
Antiy-AVLTrojan[Proxy]/Win32.Lethic
KingsoftWin32.Troj.Generic_a.c.(kcloud)
MicrosoftTrojan:Win32/Bagsu!rfn
ArcabitTrojan.Lethic.Gen.14
SUPERAntiSpywareTrojan.Agent/Gen-Ransom
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Lethic.Gen.14
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.MDA.R175807
Acronissuspicious
VBA32BScope.Trojan.Downloader
ALYacTrojan.Lethic.Gen.14
MAXmalware (ai score=86)
MalwarebytesRansom.TeslaCrypt
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.EQBY
TrendMicro-HouseCallRansom_CRYPTESLA.SMA6
TencentWin32.Trojan.Generic.Pcig
YandexTrojan.GenAsa!rIS9S6NeDtU
IkarusTrojan-Ransom.TeslaCrypt
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.EPMF!tr
WebrootW32.Trojan.Gen
AVGWin32:Dorder-W [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.Lethic.HykCK2MA

How to remove Trojan.Lethic.Gen.14?

Trojan.Lethic.Gen.14 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment