Malware

MSIL/Kryptik.AAZZ (file analysis)

Malware Removal

The MSIL/Kryptik.AAZZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.AAZZ virus can do?

  • Presents an Authenticode digital signature
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine MSIL/Kryptik.AAZZ?


File Info:

name: FBF2556CCCF289B9E4BC.mlw
path: /opt/CAPEv2/storage/binaries/e70cd3e7a24f8ec4b57f65edc647a8afe6b7e3e097c99e9a0233d0fdfc9beae9
crc32: 9401422B
md5: fbf2556cccf289b9e4bc196788ecb1bc
sha1: 5f5dea07676383f586504bd84b3a4b82bd2a3018
sha256: e70cd3e7a24f8ec4b57f65edc647a8afe6b7e3e097c99e9a0233d0fdfc9beae9
sha512: 7f05073288e261244558cd4ebc803c49bf854f43f6ab762ffeefbf9f1c6f0e63ecd0470d6fa6989fae6ae2dc80f67a291c4e288db3ee59244b31dd91a968aa28
ssdeep: 6144:9q9Pu4+ubNMbZodAQNVIC3u6wPECRY10q:9UMb+haP7Y15
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T150841915BBA5CFD3C1990BB0E871419C173D9D376A73D32B40A866AEAC753D6FC28182
sha3_384: d8d332faa1c7f8c6c197c6a2c6feafa91c389875ba1362bfc1d606dea0783897bc631336ae1ac99c8abfa39e3289dd33
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-05-19 13:21:30

Version Info:

Translation: 0x0000 0x04b0
Comments: TaskFinishedEventHandler DodSequenceMerge
CompanyName: Constants
FileDescription: OrderedDictionary
FileVersion: 511.734.930.800
InternalName: SmtpSpecifiedPickupDirectoryElement.exe
LegalCopyright: Copyright Constants 2021
LegalTrademarks:
OriginalFilename: SmtpSpecifiedPickupDirectoryElement.exe
ProductName: SHA1Cng FileDialogPermissionAttribute
ProductVersion: 511.734.930.800
Assembly Version: 536.758.273.828

MSIL/Kryptik.AAZZ also known as:

LionicTrojan.MSIL.Reline.i!c
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
FireEyeTrojan.GenericKD.38135424
McAfeePWS-FCYW!FBF2556CCCF2
K7AntiVirusTrojan ( 0057ccac1 )
AlibabaTrojanPSW:MSIL/Reline.559441b2
K7GWTrojan ( 0057ccac1 )
CyrenW32/MSIL_Agent.CAA.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.AAZZ
Paloaltogeneric.ml
KasperskyHEUR:Trojan-PSW.MSIL.Reline.gen
BitDefenderTrojan.GenericKD.38135424
MicroWorld-eScanTrojan.GenericKD.38135424
AvastWin32:Trojan-gen
TencentWin32.Trojan.Falsesign.Eibi
Ad-AwareTrojan.GenericKD.38135424
EmsisoftTrojan.GenericKD.38135424 (B)
TrendMicroTROJ_GEN.R002C0PKS21
McAfee-GW-EditionPWS-FCYW!FBF2556CCCF2
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKD.38135424
JiangminTrojan.PSW.MSIL.cxqj
WebrootW32.Trojan.Dropper
AviraHEUR/AGEN.1144296
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Wacatac.B!ml
MAXmalware (ai score=80)
TrendMicro-HouseCallTROJ_GEN.R002C0PKS21
IkarusTrojan.MSIL.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.ABBF!tr
AVGWin32:Trojan-gen
PandaTrj/GdSda.A

How to remove MSIL/Kryptik.AAZZ?

MSIL/Kryptik.AAZZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment