Threat Scorecard

Ranking: 14,380
Threat Level: 90 % (High)
Infected Computers: 17
First Seen: January 23, 2013
Last Seen: July 16, 2023
OS(es) Affected: Windows

Win32/Kryptik.ARTR is a Trojan that is distributed via a compromised e-commerce website Cybercrooks are exploiting to spread and affect targeted PCs with Win32/Kryptik.ARTR. Scammers use spam emails to spread Win32/Kryptik.ARTR with the subject line ' gift voucher code', which notifies the PC user that Stella has gifted him/her a voucher worth EUR 100, whose code can be found inside an added attachment. The bogus email asks the computer user to click on the hyperlink to confirm his/her account to get a EUR 100 deposited into the same. The fraudulent email strives to appear legitimate to the PC user so the message gives several offers to use the gift coupon. The malevolent .ZIP attachment, although appearing like a harmless screensaver, added to the bogus email carries a file called 'voucher.scr', which is found as Win32/Kryptik.ARTR.

File System Details

Win32/Kryptik.ARTR may create the following file(s):
# File Name MD5 Detections
1. voucher.scr
2. ddmlxjwy.exe 3f42268f7aee2362462fc384d01a13ab 0
3. stheyoa6.dl ce06410e605d6aca9dec2ec2396b4476 0
4. 1014e02e2ee8fc51ec5ee2cdd7ee5fb7 1014e02e2ee8fc51ec5ee2cdd7ee5fb7 0
5. 648b02cb624137faccd4310a860 648b02cb624137faccd4310a8602d579 0
6. socks.exe d9f93384197ed2213d8c59efa1aed7de 0


