Malware

Win32:Kryptik-MVL [Trj] (file analysis)

Malware Removal

The Win32:Kryptik-MVL [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Kryptik-MVL [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Transacted Hollowing
  • Collects and encrypts information about the computer likely to send to C2 server
  • Collects information to fingerprint the system

How to determine Win32:Kryptik-MVL [Trj]?


File Info:

name: E8F69B11DE826F17AF5D.mlw
path: /opt/CAPEv2/storage/binaries/69885055f4e0136d177b1855b9f849718205b8ecbb0c6c039391b9062aaf145e
crc32: F8C1CA91
md5: e8f69b11de826f17af5db6de7937c2af
sha1: f31c2357e60cb223ca531ee58ba8320166ea2030
sha256: 69885055f4e0136d177b1855b9f849718205b8ecbb0c6c039391b9062aaf145e
sha512: 99bf10943510dbf3abb2cdf8317fcbd4b5396b3202d0c0396b948dfb567900da0df5f9a244e2cac2e0215fdfbbcb5b23cb38be4faed2b3344329628e9960cb3e
ssdeep: 6144:3SH4NMEb+fvIAM84MnQoxXnlw/xfnj5htUBkDiVj3xMHIcxv4UTg:3SH9Eb+fvIAMnE1J4j5hyPty4UTg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18A74E042BFA8A93CD85DC736E4E0D2F44E8706F6F94A9C76D0F8A583D25C8A0057C69D
sha3_384: ba1bf1b136aa41b007c61b6222e3fdabec9aa8295c968ad60701c604a9fda93c9f4697ef6eea61f795d06676789c5f6f
ep_bytes: 558bec81ec180200008b4d08890de827
timestamp: 2013-09-08 17:40:23

Version Info:

CompanyName: Корпорация Майкрософт
FileDescription: Редактор личных символов
Translation: 0x0419 0x04b0

Win32:Kryptik-MVL [Trj] also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Mods.1
MicroWorld-eScanTrojan.Lethic.Gen.11
FireEyeGeneric.mg.e8f69b11de826f17
CAT-QuickHealTrojanDropper.Gepys.A
McAfeePacked-AM!E8F69B11DE82
CylanceUnsafe
ZillyaTrojan.ShipUp.Win32.2499
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005110401 )
K7GWTrojan ( 005110401 )
Cybereasonmalicious.1de826
BitDefenderThetaGen:NN.ZexaF.34294.wG3@a4F@Qebc
CyrenW32/Zaccess.BC.gen!Eldorado
SymantecPacked.Generic.459
ESET-NOD32a variant of Win32/Kryptik.BJZK
TrendMicro-HouseCallTROJ_KRYPTK.SML2
ClamAVWin.Trojan.Modred-1
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Lethic.Gen.11
NANO-AntivirusTrojan.Win32.ShipUp.cqhmzl
SUPERAntiSpywareTrojan.Agent/Gen-Gepys
AvastWin32:Kryptik-MVL [Trj]
TencentTrojan.Win32.ShipUp.a
Ad-AwareTrojan.Lethic.Gen.11
SophosML/PE-A + Troj/ZAccess-QQ
ComodoTrojWare.Win32.Gepys.AA@522ik2
BaiduWin32.Adware.Kryptik.b
VIPRETrojan.Win32.ZAccess.ma (v)
TrendMicroTROJ_KRYPTK.SML2
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.fc
SentinelOneStatic AI – Malicious PE
EmsisoftTrojan.Lethic.Gen.11 (B)
IkarusTrojan.Win32.ShipUp
GDataTrojan.Lethic.Gen.11
JiangminTrojan/ShipUp.vb
AviraTR/Gepys.EB
Antiy-AVLTrojan/Generic.ASMalwS.434B41
MicrosoftTrojanDropper:Win32/Gepys
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zbot.R64039
Acronissuspicious
VBA32Trojan.Redirect
ALYacTrojan.Lethic.Gen.11
MalwarebytesTrojan.Dropper
APEXMalicious
RisingTrojan.Kryptik!1.A949 (CLASSIC)
YandexTrojan.GenAsa!jjVFeXGEOZc
MAXmalware (ai score=83)
FortinetW32/Kryptik.HIJR!tr
AVGWin32:Kryptik-MVL [Trj]
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.ShipUp.gen

How to remove Win32:Kryptik-MVL [Trj]?

Win32:Kryptik-MVL [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment