Ransom Trojan

What is “Trojan.Ransom.KrakenCryptor”?

Malware Removal

The Trojan.Ransom.KrakenCryptor is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ransom.KrakenCryptor virus can do?

  • Uses Windows utilities for basic functionality
  • Uses Windows utilities to enumerate running processes
  • Authenticode signature is invalid
  • Deletes executed files from disk
  • Uses csc.exe C# compiler to build and execute code
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Ransom.KrakenCryptor?


File Info:

name: E1AEE9EF64D71E0C9BB8.mlw
path: /opt/CAPEv2/storage/binaries/0857d5f714e88a2347affff4a440d9c76e6ddd18265e1c9a7d1c9966b0bfe61a
crc32: 6CE099D6
md5: e1aee9ef64d71e0c9bb8eee9742efdef
sha1: 1ef57a935a60c5fb7a046693652ea0f1f6db2f71
sha256: 0857d5f714e88a2347affff4a440d9c76e6ddd18265e1c9a7d1c9966b0bfe61a
sha512: dfd7399ad9c4cadbbdc2a33533e136ab49fad7bfc2b37526b0fce12e21cf42d1c8894f34fe76a18f7630a257f74a64df9eb6586d15f08bc53e8cf2342c9ccb3b
ssdeep: 3072:wMwaC5chbz3lEztKGvO7pUlCEPbAA5QX6Y:bwYbTlEztKt7pr6bv5+6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16CD3E83EDB0A2D14C7AD10B9B4456E15E8F1960F0121D12B7E7EAACF4F262EDE6060E5
sha3_384: 95d996cd689625e78878959b836d9d55fc4acf511500bc8a0beff5145a56add6c1ed7ab93dd81b08ac3339e544dbaa37
ep_bytes: ff250020400000000000000000000000
timestamp: 2018-11-04 15:00:13

Version Info:

Translation: 0x0000 0x04b0
Comments: Bitberry
CompanyName:
FileDescription: www.bitberry.net
FileVersion: 0.0.2.2
InternalName: bitberry.exe
LegalCopyright: Bitberry - All right reserved.
LegalTrademarks:
OriginalFilename: bitberry.exe
ProductName:
ProductVersion: 0.0.2.2
Assembly Version: 0.0.2.2

Trojan.Ransom.KrakenCryptor also known as:

BkavW32.AIDetectMalware.CS
LionicTrojan.Win32.Kraken.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.MSIL.Ubibila.1
SkyhighBehavesLike.Win32.Generic.ch
McAfeeRDN/Ransom
Cylanceunsafe
ZillyaTrojan.SelfDel.Win32.59862
SangforRansom.Win32.Save.a
K7AntiVirusTrojan ( 0053c9261 )
AlibabaTrojan:MSIL/SelfDel.d84ad46c
K7GWTrojan ( 0053c9261 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.MSIL.Ubibila.1
SymantecRansom.Kraken!gen1
ESET-NOD32a variant of MSIL/Filecoder.PI
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Ransomware.DotNetCryptor-6959671-0
KasperskyHEUR:Trojan.MSIL.SelfDel.gen
BitDefenderGen:Heur.MSIL.Ubibila.1
AvastWin32:RansomX-gen [Ransom]
TencentMalware.Win32.Gencirc.13b7bb94
EmsisoftGen:Heur.MSIL.Ubibila.1 (B)
F-SecureHeuristic.HEUR/AGEN.1351133
DrWebTrojan.MulDrop21.38504
VIPREGen:Heur.MSIL.Ubibila.1
TrendMicroRansom.MSIL.KRAKEN.SM
SophosMal/Generic-S
IkarusTrojan-Ransom.FileCrypter
JiangminTrojan.MSIL.knsk
WebrootW32.Ransom.Kraken
VaristW32/Filecoder.CD.gen!Eldorado
AviraHEUR/AGEN.1351133
Antiy-AVLTrojan/MSIL.SelfDel
XcitiumMalware@#37zfgsmqt9ynf
MicrosoftRansom:MSIL/Kraken
ViRobotTrojan.Win32.S.Agent.139264.AMN
ZoneAlarmHEUR:Trojan.MSIL.SelfDel.gen
GDataGen:Heur.MSIL.Ubibila.1
GoogleDetected
AhnLab-V3Trojan/Win32.Kraken.R243190
BitDefenderThetaGen:NN.ZemsilF.36680.im0@a4z3VWg
ALYacTrojan.Ransom.KrakenCryptor
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom.MSIL.KRAKEN.SM
RisingRansom.Kraken!8.10106 (C64:YzY0OgzXl+fp2NEKcQ)
YandexTrojan.SelfDel!2P2Cumb9ITA
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.73709937.susgen
FortinetMSIL/Filecoder.PI!tr.ransom
AVGWin32:RansomX-gen [Ransom]
Cybereasonmalicious.35a60c
DeepInstinctMALICIOUS

How to remove Trojan.Ransom.KrakenCryptor?

Trojan.Ransom.KrakenCryptor removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment