Trojan

Trojan-PSW.Win32.Predator.hxs (file analysis)

Malware Removal

The Trojan-PSW.Win32.Predator.hxs is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.Win32.Predator.hxs virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the CryptBot malware family

How to determine Trojan-PSW.Win32.Predator.hxs?


File Info:

name: BBE2195E6CAF20750B9B.mlw
path: /opt/CAPEv2/storage/binaries/8546483651e392db66f06025d5cf285295ab0f41d59ec7c8a7aede83b88894f8
crc32: 9660BA1A
md5: bbe2195e6caf20750b9bd6a9c974f84d
sha1: 8e579bf8102858d3cbac7b9876cf68d83e8940cf
sha256: 8546483651e392db66f06025d5cf285295ab0f41d59ec7c8a7aede83b88894f8
sha512: dde81f9eca63dd98189180c9ea48b0690779528ddde6f9a92560b1fff491e1fdef849c3f7a9d6a5c7960bbecc8b9ad21c4f2d0bb01b99eeb5300ff99d210c7bb
ssdeep: 6144:ZOzxP3Xbjh8o45Y+DBOZFDC9BsneQtmLNiSP2Re8J2xiSP2Re8J2xiSP2Re8J2x/:ZOzxPbFC5Y+DBfXVsqsk8k8k8k
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15015AE33B564DD33CC0702B2FF5E46679D86E8908B5E13F39BE46A1A50260E5C6B3A53
sha3_384: 344477c30775c77fe36a224d2a97a5bfdebce1ee631b34573409bcf411dd78500dccbab73f610ef241910415274b1683
ep_bytes: e9d49e0100e9c1150200e949730200e9
timestamp: 2021-12-29 10:37:17

Version Info:

0: [No Data]

Trojan-PSW.Win32.Predator.hxs also known as:

LionicTrojan.Win32.Swizzor.kZ6h
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.48010887
FireEyeGeneric.mg.bbe2195e6caf2075
ALYacTrojan.GenericKD.48010887
CylanceUnsafe
ZillyaTrojan.Inject.Win32.317387
SangforTrojan.Win32.Tiggre.rfn
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.810285
CyrenW32/Kryptik.XKCR-1667
SymantecPacked.Generic.497
ESET-NOD32a variant of Win32/Kryptik.HOAR
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-PSW.Win32.Predator.hxs
BitDefenderTrojan.GenericKD.48010887
AvastFileRepMalware
RisingBackdoor.Mokes!1.CECE (CLOUD)
Ad-AwareTrojan.GenericKD.48010887
EmsisoftTrojan.GenericKD.48010887 (B)
ComodoMalware@#bbjto8d6qas6
F-SecureTrojan.TR/AD.GenSteal.gkqhx
TrendMicroTROJ_GEN.R002C0WAM22
McAfee-GW-EditionBehavesLike.Win32.Generic.ct
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
IkarusTrojan.Win32.Generic
GDataWin32.Trojan.PSE.1S61RI7
JiangminTrojan.PSW.Azorult.hvm
WebrootW32.Trojan.Gen
AviraTR/AD.GenSteal.gkqhx
MAXmalware (ai score=87)
Antiy-AVLTrojan[Banker]/Win32.Gozi
KingsoftWin32.PSWTroj.Undef.(kcloud)
GridinsoftRansom.Win32.AzorUlt.sa
ArcabitTrojan.Generic.D2DC9687
ViRobotTrojan.Win32.Z.Undef.897120
ZoneAlarmTrojan-PSW.Win32.Predator.hxs
MicrosoftTrojan:Win32/Tiggre!rfn
CynetMalicious (score: 100)
AhnLab-V3Infostealer/Win.CryptBot.C4923311
McAfeeGenericRXAA-AA!BBE2195E6CAF
VBA32BScope.TrojanDownloader.Deyma
MalwarebytesSpyware.PasswordStealer
TrendMicro-HouseCallTROJ_GEN.R002C0WAM22
TencentMalware.Win32.Gencirc.10d0052d
YandexTrojan.Agent!1I1Ye8Qy7HE
FortinetW32/Kryptik.HOAR!tr
BitDefenderThetaGen:NN.ZexaF.34232.2uZ@aWm8yHi
AVGFileRepMalware
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.73741539.susgen

How to remove Trojan-PSW.Win32.Predator.hxs?

Trojan-PSW.Win32.Predator.hxs removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment