Malware

What is “Win32/Kryptik.HAWU”?

Malware Removal

The Win32/Kryptik.HAWU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HAWU virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Attempts to identify installed AV products by installation directory
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering

How to determine Win32/Kryptik.HAWU?


File Info:

name: 5C842C3E406AE35AEFB7.mlw
path: /opt/CAPEv2/storage/binaries/c5253cac69ff9dae1d1f9a5887523e155a228cbeb15c948e224d1a1ac62a7f50
crc32: E13C0A02
md5: 5c842c3e406ae35aefb7e04efccb5de4
sha1: b528d823b36ec1aa54e3b14810b01b119b8edf8b
sha256: c5253cac69ff9dae1d1f9a5887523e155a228cbeb15c948e224d1a1ac62a7f50
sha512: 2528bb871ac56bbcf298529595c9a66cd9b21114eed239c60b6a281fae5cdc81bc2410aa1ecf6f5702c8d51d00f528ad641183fc597aab77be06990497033453
ssdeep: 24576:rg/MiTsLWy98tDfPDZXK44mIj+eGJ6SQTSlZG:kUpLf98tD3pGNe8SWSl0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18115238EE3D29A3CD95441FFB5173E0F890ED9749EB5093C26D613A1AA7D0628483D2F
sha3_384: 45e5609d15cb4adf97b5d59253af2d3271a378307252d0b34158264b1906ab144fb68f344989087dca3f27338625b4d1
ep_bytes: 60be006052008dbe00b0edff57eb0b90
timestamp: 2020-02-04 00:15:49

Version Info:

LegalCopyright: (C)Cylance
PrivateBuild: 6.6.6.2
CompanyName: Cylance
Comments: Wares Pulsed Apc
ProductName: Themaths
FileDescription: Wares Pulsed Apc
OriginalFilename: Themaths
ProductVersion: 6.6.6.2
Translation: 0x0409 0x04b0

Win32/Kryptik.HAWU also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
FireEyeGeneric.mg.5c842c3e406ae35a
McAfeeArtemis!5C842C3E406A
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Agent.xgdhf
K7AntiVirusTrojan ( 004f9a3c1 )
AlibabaTrojanDownloader:Win32/Deyma.a8aa7303
K7GWTrojan ( 004f9a3c1 )
Cybereasonmalicious.e406ae
BitDefenderThetaGen:NN.ZexaF.34212.2mKfaq!lAuci
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Kryptik.HAWU
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan-Downloader.Win32.Deyma.azg
NANO-AntivirusTrojan.Win32.DownLoad4.gzndtb
TencentWin32.Trojan-downloader.Deyma.Syie
DrWebTrojan.DownLoad4.13575
McAfee-GW-EditionBehavesLike.Win32.Pluto.cc
SophosMal/Generic-S
AviraHEUR/AGEN.1230305
Antiy-AVLTrojan/Generic.ASMalwS.3056EAE
ZoneAlarmTrojan-Downloader.Win32.Deyma.azg
MicrosoftTrojan:Win32/Occamy.C
VBA32Trojan.Download
RisingStealer.Amadey!1.BC27 (CLOUD)
YandexTrojan.Kryptik!26EmDaXC5MI
FortinetW32/Deyma.AZG!tr.dldr
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Kryptik.HAWU?

Win32/Kryptik.HAWU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment