Trojan

Trojan.Win32.Cryprar.wb (file analysis)

Malware Removal

The Trojan.Win32.Cryprar.wb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Cryprar.wb virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location
  • A script process created a new process
  • Appears to use command line obfuscation
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.Win32.Cryprar.wb?


File Info:

name: 8B2CB41E2C5E14C8F404.mlw
path: /opt/CAPEv2/storage/binaries/9447370ec5063045867e083af4b5ee94702686effa7a765b42a4c9762d3f4056
crc32: B0616C45
md5: 8b2cb41e2c5e14c8f404aba2a0f7b307
sha1: 133186977cf0a3ff1f99743d48f5ea3e890b0d14
sha256: 9447370ec5063045867e083af4b5ee94702686effa7a765b42a4c9762d3f4056
sha512: 8a79ef15d6363da67e54f529a374f817d86427f00a95376d8f56dea2fdb5cab011c9a1767424cdd82dc059617ad6732cf0583414ea82502aaaa586fac93d6b5e
ssdeep: 24576:+DWHSb4Nc0GGrXxhUNPYNRvvRlCf6KCvspCMQTk5RwPAad2826xijK9WSmzjRHgm:t84kGb4PYLn/vsQpoRwI76xaSmzjBgm
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T192651211AAC699B2C0722D32A529FA7464797E201F349EDFB3E8552DD9301C1EF347A3
sha3_384: 5feef1ce5ffa468c56af767324683d44f9c285b348e2fb9ed07734e0a3a295e4eaa245ca9566b47fb7e1044d084b6952
ep_bytes: e864040000e988feffff3b0d68e64300
timestamp: 2021-06-11 09:16:47

Version Info:

0: [No Data]

Trojan.Win32.Cryprar.wb also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.NanoBot.trQD
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.47515062
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (W)
K7GWTrojan ( 0057bde51 )
K7AntiVirusTrojan ( 0057bde51 )
SymantecTrojan.Gen.MBT
ESET-NOD32RAR/Agent.DJ
APEXMalicious
AvastSFX:Runner-C [Bd]
KasperskyTrojan.Win32.Cryprar.wb
BitDefenderTrojan.GenericKD.47515062
NANO-AntivirusTrojan.Win32.Cryprar.jimbkt
MicroWorld-eScanTrojan.GenericKD.47515062
RisingMalware.AbnormalScript/SFX!1.D9B9 (CLASSIC)
Ad-AwareTrojan.GenericKD.47515062
SophosGeneric ML PUA (PUA)
DrWebTrojan.MulDrop19.9077
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.8b2cb41e2c5e14c8
EmsisoftTrojan.GenericKD.47515062 (B)
GDataTrojan.GenericKD.47515062
AviraTR/Agent.bdjmj
ArcabitTrojan.Generic.D2D505B6
MicrosoftTrojan:Win32/Woreflint.A!cl
McAfeeArtemis!8B2CB41E2C5E
MAXmalware (ai score=88)
VBA32Trojan.Cryprar
MalwarebytesTrojan.Dropper.SFX
ZonerProbably Heur.RARAutorun
TrendMicro-HouseCallTROJ_GEN.R002H0DKT21
TencentWin32.Trojan.Cryprar.Eank
IkarusTrojan.Agent
AVGSFX:Runner-C [Bd]
Cybereasonmalicious.77cf0a
Paloaltogeneric.ml

How to remove Trojan.Win32.Cryprar.wb?

Trojan.Win32.Cryprar.wb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment