Malware

Win32/Kryptik.AZE (file analysis)

Malware Removal

The Win32/Kryptik.AZE is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.AZE virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Win32/Kryptik.AZE?


File Info:

name: 3CCE624AEA127BC9C8C3.mlw
path: /opt/CAPEv2/storage/binaries/e1061230b29db4cea5b612e9075da279bf656e8eafe3c8fda6c575dd4b87d721
crc32: 55BAE5E3
md5: 3cce624aea127bc9c8c369598267bf85
sha1: 88fb39af03b8495b07f2a5ab9ac1d2a9192f8fdb
sha256: e1061230b29db4cea5b612e9075da279bf656e8eafe3c8fda6c575dd4b87d721
sha512: 5bc32d6550ab732e9356e4cbdd5c51437e25e57f70e115d639fcba795abf73cda73b3de4948e2b660b92534882237a91c73b19944e15b687d693fe31f75ab1f9
ssdeep: 768:4yNDNzH4gZB8UJBgJ+9Gz7XTHJYdQId1jy:vNzH4g7LkogSy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T198C29D51320402EEF36A0773384B85761772BC215AC386D699E07A667EA35F74F2B734
sha3_384: c97e996288df30c044bc40f40f229012ce54b1a14abd249078ab2dd4a023bb469e4308cfea111f229208fbbdeac713cd
ep_bytes: 558bec8bf94a43424703d62bd9eb793d
timestamp: 2005-02-04 01:33:45

Version Info:

CompanyName: vVP6agwWJnV
FileDescription: UB3cIR3IYSOBNXlD8d
FileVersion: vOfkIQVoiV4
InternalName: ppJtg3PjP64g
LegalCopyright: hsyuQllPbXh
OriginalFilename: bIO35IIhEljNibK1g6
ProductName: qjroohGBO6OtDPNc3I
ProductVersion: u5qJFjXa881NG
Translation: 0x0800 0x04b0

Win32/Kryptik.AZE also known as:

LionicHacktool.Win32.Krap.kZ3u
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Packed.Hiloti.Gen.3
FireEyeGeneric.mg.3cce624aea127bc9
McAfeeDownloader-CAQ
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005223351 )
AlibabaVirTool:Win32/Obfuscator.d491e7ce
K7GWTrojan ( 005223351 )
CrowdStrikewin/malicious_confidence_100% (D)
VirITTrojan.Win32.Packed.BAL
CyrenW32/SuspPack.BH.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.AZE
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Packed.Hiloti.Gen.3
NANO-AntivirusTrojan.Win32.Crypted.dfawxk
AvastWin32:Bredolab-AP [Trj]
TencentWin32.Trojan.Generic.Lnys
Ad-AwareTrojan.Packed.Hiloti.Gen.3
SophosMal/Generic-R + Mal/BredoPk-B
ComodoTrojWare.Win32.Downloader.Fraudload.fv@4lnkgu
DrWebTrojan.Packed.687
VIPRELooksLike.Win32.Malware!B (v)
TrendMicroTROJ_BREDLAB.SMJ
McAfee-GW-EditionDownloader-CAQ
EmsisoftTrojan.Packed.Hiloti.Gen.3 (B)
GDataTrojan.Packed.Hiloti.Gen.3
JiangminTrojanDownloader.Genome.hpa
WebrootW32.Malware.Downloader
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.2AC8EA9
GridinsoftRansom.Win32.Zbot.sa
MicrosoftTrojanDownloader:Win32/Waledac.C
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Hiloti.Gen
Acronissuspicious
BitDefenderThetaAI:Packer.94770E4E1F
ALYacTrojan.Packed.Hiloti.Gen.3
MAXmalware (ai score=100)
VBA32Trojan.Zeus.EA.0999
TrendMicro-HouseCallTROJ_BREDLAB.SMJ
RisingTrojan.Win32.Waledac.fu (CLOUD)
YandexTrojan.DL.Waledac!FiwbJ8YsNRY
SentinelOneStatic AI – Malicious PE
AVGWin32:Bredolab-AP [Trj]
Cybereasonmalicious.aea127
PandaTrj/Genetic.gen
MaxSecureTrojan.Malware.7164915.susgen

How to remove Win32/Kryptik.AZE?

Win32/Kryptik.AZE removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment