Trojan

Trojan.TeslaCrypt.D (file analysis)

Malware Removal

The Trojan.TeslaCrypt.D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.TeslaCrypt.D virus can do?

  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan.TeslaCrypt.D?


File Info:

name: AB262B0839CDB84C6431.mlw
path: /opt/CAPEv2/storage/binaries/71da55272ae678530bbc7e4868f204726c7784c0663e7ecec3d2d2899b8b0d0f
crc32: A563D927
md5: ab262b0839cdb84c6431190078546c25
sha1: b4adee05b2b62368736547710b03745f57c56ac1
sha256: 71da55272ae678530bbc7e4868f204726c7784c0663e7ecec3d2d2899b8b0d0f
sha512: 19879dcb99174bf661919ee4ed29982696acb5cf12a611d33a4b11a1186067b30d081f50b0c8b1dd78af264c906207760932cda24a30a703f4a07f175c0a282b
ssdeep: 6144:SwVIUYVV7VSafv2JpOSb2me9Pi3lcqZmdEb1P+5HzjGU2yMyVV7VSafv2JpOSb2d:S6IUzaG372MzmMU2yYaG372M
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1ADA402B0390A4EB6DE6926BF50C2327784C1D5418E40DD1BD985E6CD96C22C3DA7D3AF
sha3_384: 86c898c83f0721163200e258f7021bbc2071bbffc4f1d43b2994b77911435bb80549c8c1ff14f68847e0628f94f1294d
ep_bytes: 558bec6aff6888cc4300686cbb430064
timestamp: 2004-01-25 20:14:42

Version Info:

Comments:
CompanyName: Powerware
FileDescription: Decimate Consummately Categorise
FileVersion: 134, 34, 231, 120
InternalName: Fadeout
LegalCopyright: Copyright (C) 2013
LegalTrademarks:
OriginalFilename: Classifyl.EXE
PrivateBuild:
ProductName: Commendations Dispensing
ProductVersion: 107, 125, 99, 226
SpecialBuild:

Trojan.TeslaCrypt.D also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Bitman.tn27
Elasticmalicious (high confidence)
ClamAVWin.Trojan.Teslacrypt-2
CAT-QuickHealRansom.TeslaCrypt.C5
McAfeeRansomware-FBK!AB262B0839CD
CylanceUnsafe
Sangfor[ARMADILLO V1.71]
K7AntiVirusTrojan ( 004b56ff1 )
AlibabaPacked:Win32/TeslaCrypt.584c5244
K7GWTrojan ( 004b56ff1 )
Cybereasonmalicious.839cdb
BaiduWin32.Trojan.Filecoder.k
VirITTrojan.Win32.TeslaCrypt.AD
CyrenW32/Trojan.LJBF-6883
SymantecRansom.TeslaCrypt!g1
tehtrisGeneric.Malware
ESET-NOD32Win32/Filecoder.TeslaCrypt.I
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyUDS:Packed.Win32.Tpyn
BitDefenderTrojan.TeslaCrypt.D
NANO-AntivirusTrojan.Win32.AVKill.dzejmp
MicroWorld-eScanTrojan.TeslaCrypt.D
RisingTrojan.Ransom-Tesla!1.A322 (CLOUD)
Ad-AwareTrojan.TeslaCrypt.D
EmsisoftTrojan.TeslaCrypt.D (B)
ComodoTrojWare.Win32.Ransom.Tescrypt.B@652jfw
DrWebTrojan.AVKill.59621
ZillyaAdware.MutiBar.Win32.895
TrendMicroRansom_HPLOCKY.SM1
McAfee-GW-EditionRansomware-FBK!AB262B0839CD
FireEyeGeneric.mg.ab262b0839cdb84c
SophosML/PE-A + Troj/TeslaC-A
IkarusTrojan-Ransom.CryptoWall3
GDataTrojan.TeslaCrypt.D
JiangminTrojan.Bitman.as
WebrootW32.Trojan.Gen
AviraTR/Crypt.XPACK.340503
MAXmalware (ai score=84)
ArcabitTrojan.TeslaCrypt.D
ViRobotTrojan.Win32.U.Agent.454656.G
MicrosoftRansom:Win32/Tescrypt!rfn
AhnLab-V3Trojan/Win32.Teslacrypt.R173404
Acronissuspicious
BitDefenderThetaGen:NN.ZexaE.34666.Bq0@aa9dbnii
ALYacTrojan.TeslaCrypt.D
VBA32Hoax.Bitman
TrendMicro-HouseCallRansom_HPLOCKY.SM1
TencentMalware.Win32.Gencirc.10c4cc77
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AC.331AEC!tr
AVGWin32:TeslaCrypt-E [Trj]
AvastWin32:TeslaCrypt-E [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.TeslaCrypt.D?

Trojan.TeslaCrypt.D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment