Malware

About “Win32/Kryptik.GLTL” infection

Malware Removal

The Win32/Kryptik.GLTL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GLTL virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Kazak
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Attempts to remove evidence of file being downloaded from the Internet
  • Attempts to restart the guest VM
  • Deletes its original binary from disk
  • Attempts to stop active services
  • Installs itself for autorun at Windows startup
  • Attempts to disable Windows Defender
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/Kryptik.GLTL?


File Info:

name: BD8B6A2E47B74E432DF6.mlw
path: /opt/CAPEv2/storage/binaries/e0eca407b5ac2b90c3c170fc19d09252c51bbd5b2e3513a32e069db4843fed96
crc32: BDB3A930
md5: bd8b6a2e47b74e432df67fa7a2b035c7
sha1: 96fe57abdbe9fb720d35761d3a495fbb5a6aeb57
sha256: e0eca407b5ac2b90c3c170fc19d09252c51bbd5b2e3513a32e069db4843fed96
sha512: 4ccbcd0bf144a6d07c29e93f1371972d68ab4c094b75be5541d0b317af46561c4a563f5a5f97ec5e1d3a596571afa4cf41cf9e7d6e0ef8ef63a135a668275800
ssdeep: 6144:XxCmihMpJzS6uPXrqsbrIyuaE9gYQSw1oKWUm0R5i+OFebc/q0A/oae:tihKzcZwmEu9U4mw5FvbCfAo1
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CA84E0167F8AD023C0B1473C4D90D541FF9EF969A2991742FBAC316F89326C359B628B
sha3_384: 871c97279ebde7b0775b457e29a63ed878e79e5f3fbbb55284a21d9cc7f81cd7154f1cc7434a227afb4e67dbc6ca570f
ep_bytes: e8ff460000e978feffffcccccccccccc
timestamp: 2018-04-20 14:05:39

Version Info:

FileVersion: 1.0.0.2
ProductVersion: 1.0.0.1
Translation: 0x0809 0x04b0

Win32/Kryptik.GLTL also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Brsecmon.1
FireEyeGeneric.mg.bd8b6a2e47b74e43
McAfeeTrojan-FPST!BD8B6A2E47B7
CylanceUnsafe
ZillyaTrojan.Agent.Win32.1243114
K7AntiVirusTrojan ( 0053fa031 )
K7GWTrojan ( 0053fa031 )
Cybereasonmalicious.e47b74
BitDefenderThetaGen:NN.ZexaF.34062.yu1@a4yeMamO
CyrenW32/Trojan.EHBG-3229
ESET-NOD32a variant of Win32/Kryptik.GLTL
TrendMicro-HouseCallTrojan.Win32.SODINOK.SM.hp
KasperskyVHO:Backdoor.Win32.Mokes.gen
BitDefenderTrojan.Brsecmon.1
NANO-AntivirusTrojan.Win32.Chapak.fjkeoi
AvastWin32:Trojan-gen
Ad-AwareTrojan.Brsecmon.1
SophosML/PE-A + Mal/GandCrab-G
DrWebTrojan.Siggen9.53670
TrendMicroTrojan.Win32.SODINOK.SM.hp
SentinelOneStatic AI – Malicious PE
EmsisoftTrojan.Brsecmon.1 (B)
APEXMalicious
GDataTrojan.Brsecmon.1
JiangminTrojanSpy.Ursnif.bpz
eGambitUnsafe.AI_Score_95%
AviraHEUR/AGEN.1102756
MAXmalware (ai score=86)
Antiy-AVLTrojan/Generic.ASMalwS.28B692A
ArcabitTrojan.Brsecmon.1
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Gandcrab.C2774136
VBA32BScope.Trojan.Encoder
ALYacTrojan.Brsecmon.1
MalwarebytesTrojan.Downloader
RisingTrojan.Generic@ML.100 (RDMK:UH7Q/lwW+tTj3mDkYPUMOA)
YandexTrojan.GenAsa!yXSvocT5aAI
IkarusTrojan.Win32.Ranumbot
MaxSecureRansomeware.CRAB.gen
FortinetW32/GenKryptik.CPYR!tr
AVGWin32:Trojan-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Win32/Kryptik.GLTL?

Win32/Kryptik.GLTL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment