Malware

MSIL/Kryptik.SOX malicious file

Malware Removal

The MSIL/Kryptik.SOX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/Kryptik.SOX virus can do?

  • CAPE extracted potentially suspicious content
  • .NET file is packed/obfuscated with Confuser
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Binary file triggered YARA rule

How to determine MSIL/Kryptik.SOX?


File Info:

name: A385F2DD1DBEBF562FE0.mlw
path: /opt/CAPEv2/storage/binaries/e8079114d8e7f241323e03c2361161470c8db7df5f0e4bb2d6e51c3489e70213
crc32: 936AB283
md5: a385f2dd1dbebf562fe0b3deeeb7d633
sha1: d27dec46599f3dfe271e523cc69fd2a2f9b743bc
sha256: e8079114d8e7f241323e03c2361161470c8db7df5f0e4bb2d6e51c3489e70213
sha512: 971ab13b32c945ebe410bd37a56e170fbf7bf51033517d42ad1dd976a22984d8a46fb9a49a01f08597ff15210205dec9127a9c9fda09f03194d6f70a945f5846
ssdeep: 6144:kHUoAtrSH8sItpeJhij5xAvgvJbqzLu4wQdBz5G+OL7sqLUo:ujB8JjnAYvtSGQdnnGB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T157741231E3C581B4C548CE7708D715A0AF689291FEB0CB9EFFA9224CCB6A9109F15763
sha3_384: 11a7f898473cc89e5cccbf415923e05dc22adebbae8856dabc0a703be0076f50d26a8c1cf7bc22419522ca80c40e875d
ep_bytes: ff250020400000000000000000000000
timestamp: 2019-08-22 05:01:09

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: MathGame
FileVersion: 1.0.0.0
InternalName: MathGame.exe
LegalCopyright: Copyright © 2018
LegalTrademarks:
OriginalFilename: MathGame.exe
ProductName: MathGame
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

MSIL/Kryptik.SOX also known as:

BkavW32.AIDetectMalware.CS
DrWebTrojan.Inject3.20236
MicroWorld-eScanGen:Heur.MSIL.Vuvazi.7.1
CAT-QuickHealTrojan.MsilFC.S15413486
SkyhighGenericRXIK-ID!A385F2DD1DBE
McAfeeGenericRXIK-ID!A385F2DD1DBE
MalwarebytesGeneric.Malware/Suspicious
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojanPSW:MSIL/Agensla.ab20c27e
K7GWTrojan ( 005567e11 )
K7AntiVirusTrojan ( 005567e11 )
BitDefenderThetaGen:NN.ZemsilF.36802.vm0@amfyfV
VirITTrojan.Win32.MSIL_Heur.A
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Kryptik.SOX
APEXMalicious
KasperskyHEUR:Trojan-PSW.MSIL.Agensla.gen
BitDefenderGen:Heur.MSIL.Vuvazi.7.1
NANO-AntivirusTrojan.Win32.Agensla.fwpqgy
AvastWin32:RATX-gen [Trj]
TencentMsil.Trojan-QQPass.QQRob.Usmw
EmsisoftGen:Heur.MSIL.Vuvazi.7.1 (B)
GoogleDetected
F-SecureHeuristic.HEUR/AGEN.1311153
VIPREGen:Heur.MSIL.Vuvazi.7.1
FireEyeGeneric.mg.a385f2dd1dbebf56
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminTrojan.PSW.MSIL.iqo
VaristW32/MSIL_Kryptik.OA.gen!Eldorado
AviraHEUR/AGEN.1311153
MAXmalware (ai score=80)
Antiy-AVLTrojan/Win32.Sonbokli
Kingsoftmalware.kb.c.1000
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.MSIL.Vuvazi.7.1
ZoneAlarmHEUR:Trojan-PSW.MSIL.Agensla.gen
GDataGen:Heur.MSIL.Vuvazi.7.1
AhnLab-V3Trojan/Win32.Agent.C3444125
Cylanceunsafe
PandaTrj/GdSda.A
RisingMalware.Obfus/MSIL@AI.100 (RDM.MSIL2:psMMtjSIPpJ1gMg+imdrdQ)
YandexTrojan.Igent.bSJXyX.3
IkarusTrojan.MSIL.Krypt
MaxSecureTrojan.Malware.74499699.susgen
FortinetMSIL/GenKryptik.GOSN!tr
AVGWin32:RATX-gen [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan:MSIL/Kryptik.SOX

How to remove MSIL/Kryptik.SOX?

MSIL/Kryptik.SOX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment