Malware

Win32/Kryptik.HBNA malicious file

Malware Removal

The Win32/Kryptik.HBNA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HBNA virus can do?

  • Executable code extraction
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Expresses interest in specific running processes
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • A scripting utility was executed
  • Attempts to remove evidence of file being downloaded from the Internet
  • Code injection with CreateRemoteThread in a remote process
  • Installs itself for autorun at Windows startup

How to determine Win32/Kryptik.HBNA?


File Info:

crc32: 547952D0
md5: f34df8b69256348f1055b9897a9a4fd0
name: sample.exe
sha1: e1b871b174cea5d51b92c92f84e9dd85fe5f1efb
sha256: cff0f108778e643ddf234c5134c3e065556c601b65a088fab7518c15adbd7b7f
sha512: 423c67c99469f0e168007fd4e36f0cd8f47cd33f3356eb5f8cbadfc9ddea39a4046ec00a9f1d3a2433dfe0391ceb735dfcfd7d785a75d6fb63940739f86fabe2
ssdeep: 6144:RjemHnxbkTowrJWff/iXswzLsb98fduJIFSMSAkyxfrqIhRAecRsOB2y4SBqCJ4:AmHneT3JWfpFCgJZW21eKfmiqCyzv
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Win32/Kryptik.HBNA also known as:

BkavW32.AIDetectVM.malware
FireEyeGeneric.mg.f34df8b69256348f
McAfeeRDN/Generic.cf
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 005616cd1 )
K7GWTrojan ( 005616cd1 )
Cybereasonmalicious.174cea
TrendMicroTROJ_GEN.R011C0PC120
APEXMalicious
Paloaltogeneric.ml
GDataWin32.Backdoor.AMRat.S73XGA
KasperskyTrojan.Win32.Injuke.brx
AlibabaTrojan:Win32/Injuke.2dc429ba
AegisLabTrojan.Win32.Malicious.4!c
AvastWin32:Trojan-gen
TencentWin32.Trojan.Injuke.Eawr
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1031595
DrWebTrojan.Inject3.35585
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.jh
Trapminemalicious.high.ml.score
IkarusTrojan.Win32.Crypt
JiangminTrojan.Agent.cpii
Antiy-AVLTrojan/Win32.Wacatac
Endgamemalicious (moderate confidence)
ZoneAlarmTrojan.Win32.Injuke.brx
MicrosoftTrojan:Win32/Occamy.C
BitDefenderThetaGen:NN.ZexaF.34096.LmGfauNbeVli
ESET-NOD32a variant of Win32/Kryptik.HBNA
TrendMicro-HouseCallTROJ_GEN.R011C0PC120
RisingTrojan.Kryptik!8.8 (CLOUD)
SentinelOneDFI – Suspicious PE
FortinetW32/Kryptik.HBNA!tr
AVGWin32:Trojan-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Win32/Kryptik.HBNA?

Win32/Kryptik.HBNA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment