Virus

Virus:Win32/Hublo.A malicious file

Malware Removal

The Virus:Win32/Hublo.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Hublo.A virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Virus:Win32/Hublo.A?


File Info:

name: 812152AEBC04CE53EB5A.mlw
path: /opt/CAPEv2/storage/binaries/8ec9c469be8790b8a62492758c986fbe7e14934c36c245a4233aac06ee069c08
crc32: 5AE48F95
md5: 812152aebc04ce53eb5a2ca8d1cae6d7
sha1: ec5e19386ec2c471ee2a41e69d4c17edcc216b9c
sha256: 8ec9c469be8790b8a62492758c986fbe7e14934c36c245a4233aac06ee069c08
sha512: 4857db0bb197202acfed31ad0ca0ba608f43dd4005111825544d6df4bfb7573289ee5cc3b16cb6b6bc26c3aefd770269312ac587aa469abb0ea5a63c65f82404
ssdeep: 384:iwcqkFZ7rkHHGNHRS/jyOE8itf6Ixv9tSck4jW5nW8:s7YHGNH4/jREth2ckn
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T12462C095EFEA4462F6E202348ED7A4365138E594D73D8B5D1F99AF0E9C33090972A323
sha3_384: d4ec1727127cef5fb1bd1f18d54a997fc5556edfd9941fa30cfd36d2fff6b628cafd94bccdb662ff0f1b1864af9c7f37
ep_bytes: 60be00a000018dbe0070ffff5783cdff
timestamp: 2001-08-17 20:53:58

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Sort Utility
FileVersion: 5.1.2600.0 (xpclient.010817-1148)
InternalName: Sort
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: Sort.EXE
ProductName: Microsoft® Windows® Operating System
ProductVersion: 5.1.2600.0
Translation: 0x0409 0x04b0

Virus:Win32/Hublo.A also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Crytex.n!c
MicroWorld-eScanWin32.Crytex.A
FireEyeGeneric.mg.812152aebc04ce53
CAT-QuickHealW32.Hublo.A
SkyhighBehavesLike.Win32.Fake.lc
McAfeeArtemis!812152AEBC04
MalwarebytesGeneric.Malware/Suspicious
VIPREWin32.Crytex.A
SangforVirus.Win32.Crytex.V0xh
K7AntiVirusVirus ( 0040f5911 )
K7GWVirus ( 0040f5911 )
Cybereasonmalicious.ebc04c
BitDefenderThetaAI:Packer.6D14AC011F
SymantecTrojan.Gen.6
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Agent.NDW
APEXMalicious
TrendMicro-HouseCallPE_CRYTEX.A
AvastWin32:Cryte
ClamAVWin.Virus.Hublo-1
KasperskyVirus.Win32.Crytex.1290
BitDefenderWin32.Crytex.A
NANO-AntivirusVirus.Win32.Crytex.bzelsx
TencentVirus.Win32.Crytex.a
EmsisoftWin32.Crytex.A (B)
F-SecureMalware.W32/Crytex.1290
DrWebWin32.Siggen.15
ZillyaVirus.Geksone.Win32.1
TrendMicroPE_CRYTEX.A
SophosW32/NGVCK-W
IkarusVirus.Win32.Virut
MAXmalware (ai score=85)
GoogleDetected
AviraW32/Crytex.1290
VaristW32/Crytex.1290
Antiy-AVLVirus/Win32.Crytex.1290
KingsoftWin32.Infected.AutoInfector.a
MicrosoftVirus:Win32/Hublo.A
XcitiumVirus.Win32.Crytex.1290@4wzy41
ArcabitWin32.Crytex.A
ZoneAlarmVirus.Win32.Crytex.1290
GDataWin32.Virus.Golem.A
CynetMalicious (score: 99)
AhnLab-V3Win32/Crytex.1290.X977
VBA32Virus.Win32.Crytex.1290
ALYacWin32.Crytex.A
Cylanceunsafe
RisingVirus.Geksone!1.AD16 (CLASSIC)
SentinelOneStatic AI – Malicious PE
FortinetW32/Geksone.B
AVGWin32:Cryte
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_70% (D)
alibabacloudVirus:Win/Hublo!hublo.HO

How to remove Virus:Win32/Hublo.A?

Virus:Win32/Hublo.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment