Malware

Win32/Kryptik.DLSC (file analysis)

Malware Removal

The Win32/Kryptik.DLSC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.DLSC virus can do?

  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Romanian
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Win32/Kryptik.DLSC?


File Info:

name: 27803F7E5165805159CD.mlw
path: /opt/CAPEv2/storage/binaries/c67f56c33563540375904da2c675f5978c2bcc6e5ba5daeda6eeb04c29b61083
crc32: EA80E92F
md5: 27803f7e5165805159cd2bd523d3eaef
sha1: 8eb544e2fc61e352202059902f6f0955ed5751b2
sha256: c67f56c33563540375904da2c675f5978c2bcc6e5ba5daeda6eeb04c29b61083
sha512: ef6b7f094140a877c991f9d68bbf7eee3e09f7c591920220c1b558980ee39b3718449405d4bf6076cd78ae0bcc9bd5a5687bed1061b3da313fc2783f650a1699
ssdeep: 768:/zSJcDSWD6z3afvJc0cFOF+Mj0prJyokyWURPF8NQvUIxALeOM:/zLDSWmz3QJhcFOF+Mj0prJyokyWURPV
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19E137166BAD7BE94E4720A3058B2B8711416BF167D32D5CE18613D351B333C26B72E2B
sha3_384: b235df5ff2ef45c0459748c15651b5506d6c10cba0fc193c2b707ee2bff16be450f08938c2fc4227f713a06df56f001a
ep_bytes: 64a100000000558bec6aff6840254000
timestamp: 2014-08-23 06:20:21

Version Info:

CompanyName: TETRO-soft
FileDescription:
FileVersion: 2.3.0.92
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName: TETROScaner
ProductVersion: 3.92
Translation: 0x0409 0x04e4

Win32/Kryptik.DLSC also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader15.37428
MicroWorld-eScanGen:Trojan.Ipatre.1
FireEyeGeneric.mg.27803f7e51658051
CAT-QuickHealTrojanDwnLdr.Upatre.A3
ALYacGen:Trojan.Ipatre.1
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.3542551
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004c75411 )
K7GWTrojan ( 004c75411 )
Cybereasonmalicious.e51658
BitDefenderThetaGen:NN.ZexaF.34294.cq1@a8T0zgfG
CyrenW32/Upatre.BA.gen!Eldorado
SymantecDownloader.Upatre!gen5
ESET-NOD32a variant of Win32/Kryptik.DLSC
TrendMicro-HouseCallTROJ_UPATRE.SM37
ClamAVWin.Packed.Upatre-9771589-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Trojan.Ipatre.1
NANO-AntivirusTrojan.Win32.Upatre.dtghsu
SUPERAntiSpywareTrojan.Agent/Gen-Upatre
AvastWin32:Trojan-gen
TencentTrojan.Win32.BitCoinMiner.la
Ad-AwareGen:Trojan.Ipatre.1
SophosML/PE-A + Mal/Upatre-S
ComodoTrojWare.Win32.TrojanDownloader.Waski.FSA@5su3z8
BaiduWin32.Trojan.Kryptik.jq
VIPRETrojan-Downloader.Win32.Upatre.tfl (v)
TrendMicroTROJ_UPATRE.SM37
McAfee-GW-EditionUpatre-FACH!27803F7E5165
EmsisoftGen:Trojan.Ipatre.1 (B)
IkarusTrojan.Upatre
GDataGen:Trojan.Ipatre.1
JiangminTrojanDownloader.Upatre.qli
MaxSecureTrojan.Upatre.Gen
AviraHEUR/AGEN.1125852
MAXmalware (ai score=88)
Antiy-AVLTrojan/Generic.ASBOL.2092
ViRobotTrojan.Win32.Upatre.35328.FX
MicrosoftVirTool:Win32/CeeInject.GH
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Upatre.R153994
Acronissuspicious
McAfeeUpatre-FACH!27803F7E5165
VBA32TrojanDownloader.Upatre
MalwarebytesMalware.AI.3787238436
APEXMalicious
RisingTrojan.Win32.Kryptik.ae (CLASSIC)
YandexTrojan.GenAsa!W4G5d1mBLY8
eGambitUnsafe.AI_Score_84%
FortinetW32/Waski.A!tr
AVGWin32:Trojan-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Kryptik.DLSC?

Win32/Kryptik.DLSC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment