Malware

Win32/Kryptik.HDLD information

Malware Removal

The Win32/Kryptik.HDLD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HDLD virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Enumerates services, possibly for anti-virtualization
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Behavioural detection: Injection (inter-process)
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

yahoo.com
mail.ru

How to determine Win32/Kryptik.HDLD?


File Info:

name: D9DD18495CC967C41A25.mlw
path: /opt/CAPEv2/storage/binaries/74c2ee92a8c4c9ad3974c50081c35240277ef90b4e9a08b5c7da99b06a69c2da
crc32: 03082B94
md5: d9dd18495cc967c41a25d710c3b386a9
sha1: 317a564fd0d807177a0655442f7b4c319edad031
sha256: 74c2ee92a8c4c9ad3974c50081c35240277ef90b4e9a08b5c7da99b06a69c2da
sha512: e6e4f600f576812afa39a018084dc2da68467477bf3e1ed748ca4fe9fc06dd9747230f90e368a4c7607b01bac39805bb839b724fd6b82e9367f6462a8aab4f85
ssdeep: 6144:W9TrOBeTQVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVf:v
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18BD64A05B394E46AEBA17B71DC7BD6ED2266BC49CE0742CB381D3F4B3C722416C52266
sha3_384: bbe8aaa3b2d1eab1105d24c892b166ed76105c0e24a8f267ced06740b3a60e1d3a12a7cf6b47893b6e7b04e82eaede79
ep_bytes: e8f02c0000e978feffffcccccccccccc
timestamp: 2019-04-23 13:21:20

Version Info:

FileVersionBeer: 1.3.23.4
InternalName: dvezejza.em
LegalCopyrighz: Copyrighz (C) 2020, jlfvjz
ProductVersions: 1.7.514
TranslationBeer: 0x0811 0x0528

Win32/Kryptik.HDLD also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Siggen15.48059
MicroWorld-eScanGen:Heur.Mint.Titirez.@t0@JSuULvaG
FireEyeGeneric.mg.d9dd18495cc967c4
McAfeePacked-GBE!D9DD18495CC9
CylanceUnsafe
K7AntiVirusTrojan ( 0056809d1 )
K7GWTrojan ( 00566f541 )
Cybereasonmalicious.95cc96
BitDefenderThetaGen:NN.ZexaF.34294.@t0@aSuULvaG
CyrenW32/GandCrab.BC.gen!Eldorado
ESET-NOD32a variant of Win32/Kryptik.HDLD
ClamAVWin.Dropper.Bunitu-7868369-0
KasperskyHEUR:Backdoor.Win32.Tofsee.pef
BitDefenderGen:Heur.Mint.Titirez.@t0@JSuULvaG
NANO-AntivirusTrojan.Win32.Tofsee.hknhku
AvastWin32:CoinminerX-gen [Trj]
Ad-AwareGen:Heur.Mint.Titirez.@t0@JSuULvaG
EmsisoftGen:Heur.Mint.Titirez.@t0@JSuULvaG (B)
ZillyaTrojan.Kryptik.Win32.2037179
McAfee-GW-EditionBehavesLike.Win32.Packed.rm
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
GDataGen:Heur.Mint.Titirez.@t0@JSuULvaG
JiangminBackdoor.Tofsee.cej
AviraHEUR/AGEN.1134391
MAXmalware (ai score=83)
Antiy-AVLTrojan/Generic.ASMalwS.307997F
MicrosoftTrojan:Win32/Tofsee.GM!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.MalPe.X2068
Acronissuspicious
VBA32BScope.Trojan.AET.281105
ALYacGen:Heur.Mint.Titirez.@t0@JSuULvaG
MalwarebytesTrojan.MalPack.GS
APEXMalicious
RisingTrojan.Kryptik!1.C46C (CLASSIC)
YandexTrojan.Kryptik!niFQ14QSdg4
IkarusTrojan.Win32.Crypt
FortinetW32/GenKryptik.ELQV!tr
AVGWin32:CoinminerX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_80% (D)
MaxSecureTrojan.Malware.300983.susgen

How to remove Win32/Kryptik.HDLD?

Win32/Kryptik.HDLD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment