Malware

What is “Win32:TeslaCrypt-N [Trj]”?

Malware Removal

The Win32:TeslaCrypt-N [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:TeslaCrypt-N [Trj] virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Performs some HTTP requests
  • Looks up the external IP address
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to remove evidence of file being downloaded from the Internet
  • Attempts to delete volume shadow copies
  • Exhibits behavior characteristic of Alphacrypt/Teslacrypt ransomware
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Attempts to identify installed AV products by registry key
  • Attempts to modify proxy settings
  • Connects to Tor Hidden Services through a Tor gateway
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

myexternalip.com
ocsp.pki.goog
levant.hr
comercialelgolf.com
dpaulick.de
crl.pki.goog
crls.pki.goog
diem.com.ar
virtualconnection.com.br
3st7uyjfocyourll.onion.to

How to determine Win32:TeslaCrypt-N [Trj]?


File Info:

crc32: 279800E2
md5: 34d5aad2b40da13581711775d74d9322
name: 34D5AAD2B40DA13581711775D74D9322.mlw
sha1: acd07f9103dda499d41ae5d4131a1dcaf1a31ebe
sha256: 13dca73236c9fc20b386f265c62ef613637a695cb1b1f50851da7176ee653b55
sha512: 7e09a0e64a2c051b90eb729a5962fcc6815880b69e21bfbbb6c236e8e05fa1c8c4739e8d32b2fb764f2af08366bc5c32308b1d6842c1b8c325f8575915cb2881
ssdeep: 12288:sivxy9mkm4OhMj/7hUTu6hN+7iUX2+Yq0kyHmjZ/ku7QlGYkEdKdlS+G5vJ1BIv:siv3Nh+G5vm39uVuOuH
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Dissolved (C) 2014
InternalName: Documentation
FileVersion: 107, 211, 255, 70
CompanyName: Smartpipes, Inc.
ProductName: Forgone Curricular
FileDescription: Crusade
OriginalFilename: Idealisations.exe

Win32:TeslaCrypt-N [Trj] also known as:

K7AntiVirusTrojan ( 0055e3ef1 )
Elasticmalicious (high confidence)
DrWebTrojan.AVKill.38022
CynetMalicious (score: 100)
CylanceUnsafe
ZillyaWorm.Allaple.Win32.26944
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 0055e3ef1 )
Cybereasonmalicious.2b40da
SymantecTrojan.Gen
ESET-NOD32Win32/Filecoder.TeslaCrypt.I
APEXMalicious
AvastWin32:TeslaCrypt-N [Trj]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Cripack.Gen.1
NANO-AntivirusTrojan.Win32.AVKill.dyiqvb
ViRobotTrojan.Win32.TeslaCrypt.Gen.B
MicroWorld-eScanTrojan.Cripack.Gen.1
TencentMalware.Win32.Gencirc.114c613d
Ad-AwareTrojan.Cripack.Gen.1
SophosML/PE-A + Troj/Ransom-BRV
F-SecureHeuristic.HEUR/AGEN.1123563
BitDefenderThetaGen:NN.ZexaF.34142.yq0@amBr5Gni
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CRYPTESLA.SM0
McAfee-GW-EditionBehavesLike.Win32.Trickbot.fh
FireEyeGeneric.mg.34d5aad2b40da135
EmsisoftTrojan.Cripack.Gen.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.SpyEyes.lrl
AviraHEUR/AGEN.1123563
Antiy-AVLTrojan[Spy]/Win32.SpyEyes
MicrosoftRansom:Win32/Tescrypt.C
ArcabitTrojan.Cripack.Gen.1
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Cripack.Gen.1
AhnLab-V3Trojan/Win32.Teslacrypt.R168154
Acronissuspicious
McAfeeGenericR-EWL!34D5AAD2B40D
MAXmalware (ai score=81)
VBA32TrojanSpy.SpyEyes
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_CRYPTESLA.SM0
RisingTrojan.Generic@ML.98 (RDML:13ZrxQV4VYyKM6m0PIeT7A)
YandexTrojanSpy.SpyEyes!Yr5y49XXrNE
IkarusTrojan.Win32.Filecoder
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.EQEH!tr
AVGWin32:TeslaCrypt-N [Trj]
Paloaltogeneric.ml

How to remove Win32:TeslaCrypt-N [Trj]?

Win32:TeslaCrypt-N [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment