Malware

Win32/Kryptik.BMMA malicious file

Malware Removal

The Win32/Kryptik.BMMA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.BMMA virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (53 unique times)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/Kryptik.BMMA?


File Info:

name: D17F796AC60917AD1444.mlw
path: /opt/CAPEv2/storage/binaries/068e609d02885036dd0d0ab19a202e1118a6a090dde27266c23e86e4166e3f7a
crc32: A9459B75
md5: d17f796ac60917ad144446ee03c889b9
sha1: 0816e69e144d97feaf0ea3bbb544d7968eb284e8
sha256: 068e609d02885036dd0d0ab19a202e1118a6a090dde27266c23e86e4166e3f7a
sha512: bcb5186dfc91fa2b7b12508f6a54312f4f38b801c5338eaed9a83b2836d662f79ce207909307255acc44c580d2b946074289386380134846f78d7d55bb7d4ef2
ssdeep: 384:JDh1/Ef6bCkzK4ntRnnnnnnnnnnnnnnnnnnnnnnnnnUdOYSBlgY4+N:HxjbC6+dODYMN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1951338539BAE4439CBE1157303F93B76A0087686221CCC1176B9F915FEAFA568B34393
sha3_384: f5108b7375dc3175fa6c00694ae752defb697c5dd2974d1b10d1b49836ed3d741872cbcd5bafca7c195e6a3ac08731b1
ep_bytes: 5458663d00fffc724a51baaf7fbfff58
timestamp: 2012-08-06 14:00:49

Version Info:

0: [No Data]

Win32/Kryptik.BMMA also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.VIZ.Gen.1
FireEyeGeneric.mg.d17f796ac60917ad
CAT-QuickHealTrojanPWS.Zbot.Gen
ALYacTrojan.VIZ.Gen.1
MalwarebytesMalware.Heuristic.1008
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0040f72a1 )
BitDefenderTrojan.VIZ.Gen.1
K7GWTrojan ( 0040f72a1 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecPacked.Generic.461
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.BMMA
APEXMalicious
SUPERAntiSpywareTrojan.Agent/Gen-Redosdru
Ad-AwareTrojan.VIZ.Gen.1
ComodoTrojWare.Win32.Kryptik.BLUG@546mmt
BitDefenderThetaGen:NN.ZexaF.34786.cqX@aWJQrVfi
VIPRETrojan.VIZ.Gen.1
TrendMicroBKDR_KELIHOS.SMF
Trapminemalicious.moderate.ml.score
AviraTR/Yakes.34832
GDataTrojan.VIZ.Gen.1
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Tepfer.R88825
Acronissuspicious
VBA32Trojan.FakeAV.01657
MAXmalware (ai score=86)
TrendMicro-HouseCallBKDR_KELIHOS.SMF
YandexTrojan.GenAsa!Sh4C3Ztfjn8
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.BDPK!tr
Cybereasonmalicious.ac6091
PandaTrj/Genetic.gen

How to remove Win32/Kryptik.BMMA?

Win32/Kryptik.BMMA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment