Malware

What is “Win32/Kryptik.GAQN”?

Malware Removal

The Win32/Kryptik.GAQN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.GAQN virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/Kryptik.GAQN?


File Info:

name: 873C3739BC86F50DFF8A.mlw
path: /opt/CAPEv2/storage/binaries/664b1eed13a4aab083ee58ad004e08a9a230d33596b4a062d849e1326e4c7924
crc32: 12F26DCC
md5: 873c3739bc86f50dff8a0f52971c76d7
sha1: 6de867fb2e80808492f4ec91567545a3085ea368
sha256: 664b1eed13a4aab083ee58ad004e08a9a230d33596b4a062d849e1326e4c7924
sha512: 778e34e3a3618ba390c3659941afa50d19dd4eae36be7348f6fefbaa29d87211d7476de80cbb5f56f7a7e8e25546bea3f811e7093da2b85a2292869a3650a051
ssdeep: 768:a9O8uUlbUpnLvfOLnUKiZX4rdw30xVYrSgX/c2kEVnzEcMqXHJUqA:0O8uibKnjOLnZTLYpcJEVzRMpq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D033AE3FD80B9D2DE01AC9B2507082B5B97D0CB4F6C585EBEFC4FD1EA592998C9E9004
sha3_384: 453bd1305872027b057e2c64b6d611401acfaf907f5a35d28b5cfff1e8e545ac1a045b7506ea242210f73e06fbb79260
ep_bytes: e847050000e99ffdffffcccccc8bff55
timestamp: 2021-11-23 13:36:14

Version Info:

0: [No Data]

Win32/Kryptik.GAQN also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.lzY7
Elasticmalicious (high confidence)
ClamAVWin.Malware.Gh0stRAT-7459717-1
CAT-QuickHealTrojan.Siscos
McAfeeGenericRXFX-BG!873C3739BC86
CylanceUnsafe
K7AntiVirusTrojan ( 0052df311 )
AlibabaTrojan:Win32/Siscos.d8caa671
K7GWTrojan ( 0052df311 )
CrowdStrikewin/malicious_confidence_80% (W)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GAQN
APEXMalicious
CynetMalicious (score: 99)
KasperskyHEUR:Trojan.Win32.Siscos.gen
BitDefenderGen:Variant.Graftor.491093
MicroWorld-eScanGen:Variant.Graftor.491093
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.11d9241f
Ad-AwareGen:Variant.Graftor.491093
EmsisoftGen:Variant.Graftor.491093 (B)
DrWebBackDoor.Spy.422
TrendMicroTROJ_GEN.R002C0PKR21
McAfee-GW-EditionGenericRXFX-BG!873C3739BC86
FireEyeGeneric.mg.873c3739bc86f50d
SophosMal/Generic-S
IkarusTrojan.Win32.Crypt
GDataGen:Variant.Graftor.491093
AviraTR/Crypt.Agent.lszjr
MAXmalware (ai score=89)
GridinsoftRansom.Win32.Gen.sa
ArcabitTrojan.Graftor.D77E55
MicrosoftTrojan:Win32/Woreflint.A!cl
ALYacGen:Variant.Graftor.491093
MalwarebytesMalware.AI.376072309
TrendMicro-HouseCallTROJ_GEN.R002C0PKR21
YandexTrojan.Siscos!Ab3otPUrwDk
FortinetW32/Graftor.485753!tr
BitDefenderThetaGen:NN.ZexaE.34294.duW@aKqBtUmi
AVGWin32:Trojan-gen
Cybereasonmalicious.9bc86f
PandaTrj/GdSda.A

How to remove Win32/Kryptik.GAQN?

Win32/Kryptik.GAQN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment