Malware

Win32/Kryptik.DUTA information

Malware Removal

The Win32/Kryptik.DUTA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.DUTA virus can do?

  • Executable code extraction
  • Compression (or decompression)
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Hongkong)
  • Looks up the external IP address
  • Uses Windows utilities for basic functionality
  • Attempts to remove evidence of file being downloaded from the Internet
  • Attempts to delete volume shadow copies
  • Exhibits behavior characteristic of Alphacrypt/Teslacrypt ransomware
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Connects to Tor Hidden Services through a Tor gateway
  • Creates a known TeslaCrypt/AlphaCrypt ransomware decryption instruction / key file.
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
ipinfo.io
flagman-gpm.com
cssforwordpress.com
splitarcondicionado.net
fgainterests.com
serenitynowbooksandgifts.com
www.serenitynowbooksandgifts.com
wls3uapur3zjm5gm.onion.to
wls3uapur3zjm5gm.tor2web.org

How to determine Win32/Kryptik.DUTA?


File Info:

crc32: 688A31CA
md5: 179a81e1174983c3e0daa57cb85d745d
name: 179A81E1174983C3E0DAA57CB85D745D.mlw
sha1: 656b2b7cb178f2cef1ada8dc2197587e680740af
sha256: 332c59bfef437e08870e955030bfbbd2e56b3ccf257b87f38c3318f39860de58
sha512: 2f0ec1974759cbc3294691d45e50fd66854b6199f35e64743eaad60540cf03f26c001fd229c05b1ecc0300744e76aeeb7967e391dd0b6ecf50984ea788846a59
ssdeep: 6144:X44EAEGxYSNuwZN+P0GUcjfmlqLErpeKmDXmBSs0AKUEURq7X13SvPHg:X42pYSJ+Pq8+lh/mDXy0AKUHEz1Cvvg
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Incas xa9 2039
InternalName: Fifty
FileVersion: 170, 11, 203, 209
CompanyName: Atheros Communications, Inc.
ProductName: Hangings Message
FileDescription: Openers
OriginalFilename: Interceptions.exe

Win32/Kryptik.DUTA also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004d41c61 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.1710
CynetMalicious (score: 100)
CAT-QuickHealRansom.Tescrypt.MUE.A4
CylanceUnsafe
ZillyaTrojan.Deshacop.Win32.213
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/generic.ali2000010
K7GWTrojan ( 004d41c61 )
Cybereasonmalicious.117498
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.DUTA
APEXMalicious
AvastWin32:TeslaCrypt-EE [Trj]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Cripack.Gen.1
NANO-AntivirusTrojan.Win32.Deshacop.dvtpoc
SUPERAntiSpywareTrojan.Agent/Gen-Malagent
MicroWorld-eScanTrojan.Cripack.Gen.1
TencentMalware.Win32.Gencirc.10c6f96c
Ad-AwareTrojan.Cripack.Gen.1
SophosMal/Generic-R + Mal/Tinba-L
ComodoMalware@#19njgrmm60az3
BitDefenderThetaGen:NN.ZexaF.34692.vq3@amvMDcCb
VIPRETrojan.Win32.Generic!BT
TrendMicroCryp_HpMyApp
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
FireEyeGeneric.mg.179a81e1174983c3
EmsisoftTrojan.Cripack.Gen.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Deshacop.fb
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1120692
eGambitGeneric.Malware
Antiy-AVLTrojan/Generic.ASMalwS.13E30B9
KingsoftWin32.Troj.GenericKD.v.(kcloud)
MicrosoftRansom:Win32/Tescrypt.C
ArcabitTrojan.Cripack.Gen.1
AegisLabTrojan.Win32.Generic.4!c
GDataTrojan.Cripack.Gen.1
AhnLab-V3Win-Trojan/Lockycrypt.Gen
Acronissuspicious
McAfeeTeslaCrypt!179A81E11749
MAXmalware (ai score=100)
VBA32Trojan.Encoder
MalwarebytesTrojan.Agent.QDD
PandaTrj/Genetic.gen
TrendMicro-HouseCallCryp_HpMyApp
RisingRansom.Tescrypt!8.3AF (CLOUD)
YandexTrojan.Deshacop!Zmne007EihA
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Deshacop.XO!tr
AVGWin32:TeslaCrypt-EE [Trj]
Paloaltogeneric.ml

How to remove Win32/Kryptik.DUTA?

Win32/Kryptik.DUTA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment