Malware

Win32/Kryptik.BIYN (file analysis)

Malware Removal

The Win32/Kryptik.BIYN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.BIYN virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Created a process from a suspicious location
  • Attempts to modify proxy settings

How to determine Win32/Kryptik.BIYN?


File Info:

name: 262523020CF0E5E69091.mlw
path: /opt/CAPEv2/storage/binaries/fe88f8d1cbd940cc909f6fe6370d9180d4a5ce4f3c3543e7b3559ee7f5538889
crc32: D203DC8A
md5: 262523020cf0e5e69091fb3efba60e04
sha1: a1db0f2df5ecb9cf60dcefaf69bc3dc94ea1304d
sha256: fe88f8d1cbd940cc909f6fe6370d9180d4a5ce4f3c3543e7b3559ee7f5538889
sha512: 8c2f9110f39b1c2f97267121e2f49036c9df287a3ed927fe24159764c1245d92661c8109c59c724bf015a80105d122ac6da8d38f1db26c2f6a90387a6773a12b
ssdeep: 1536:dxDDnd1RaqOrsdSCM+qvNYF++28kJDriK+:dxDDd/VOrInM+V
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T168B36038AAE45532D3B7CA7589F651C2BC35B9223E15984F41DA13490C23F92EDB1F2E
sha3_384: 8e8c6c9fad97683c9a003f8b28ea2d52d2cabbfe6a1da0df31bc43e6deec8e128079873e7b0383eb0a4b746e243c9756
ep_bytes: e8db130000e989feffff8bff558bec8b
timestamp: 2013-08-27 16:13:37

Version Info:

0: [No Data]

Win32/Kryptik.BIYN also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoad3.28161
MicroWorld-eScanTrojan.Downloader.JQAP
FireEyeGeneric.mg.262523020cf0e5e6
ALYacTrojan.Downloader.JQAP
VIPRETrojan.Win32.Generic.pak!cobra
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0052964f1 )
BitDefenderTrojan.Downloader.JQAP
K7GWTrojan ( 0052964f1 )
Cybereasonmalicious.20cf0e
BitDefenderThetaGen:NN.ZexaF.34182.gqZ@aulO9rkk
VirITTrojan.Win32.DownLoad3.BPRD
CyrenW32/Upatre.IS.gen!Eldorado
SymantecSMG.Heur!gen
ESET-NOD32a variant of Win32/Kryptik.BIYN
TrendMicro-HouseCallTROJ_GEN.R002C0CB322
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
AlibabaMalware:Win32/km_24ae3.None
NANO-AntivirusTrojan.Win32.DownLoad3.cjdyni
ViRobotTrojan.Win32.Upatre.51256
RisingDownloader.Waski!1.A489 (CLASSIC)
SophosMal/Generic-S
ComodoTrojWare.Win32.TrojanDownloader.Small.PR@5276zr
ZillyaTrojan.Kryptik.Win32.3685627
TrendMicroTROJ_GEN.R002C0CB322
EmsisoftTrojan.Downloader.JQAP (B)
IkarusTrojan.Win32.Crypt
JiangminTrojan/Buzus.bnwn
AviraTR/Crypt.Agent.xdqlq
Antiy-AVLTrojan/Win32.Buzus
GridinsoftRansom.Win32.Zbot.sa
MicrosoftTrojan:Win32/Zbot.DSK!MTB
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan-Downloader.Upatre.BJ
AhnLab-V3Trojan/Win32.Upatre.R284255
McAfeePWSZbot-FEV!262523020CF0
MAXmalware (ai score=84)
VBA32Trojan.Fareit.2883
MalwarebytesTrojan.Upatre.Generic
APEXMalicious
TencentTrojan-Downloader.Win32.Waski.16000151
YandexTrojan.GenAsa!dUSBw1EZjpA
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Upatre.Gen
FortinetW32/Kryptik.BIYN!tr
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Kryptik.BIYN?

Win32/Kryptik.BIYN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment