Malware

Win32/Kryptik.HDNW (file analysis)

Malware Removal

The Win32/Kryptik.HDNW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HDNW virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Maori
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Behavior consistent with a dropper attempting to download the next stage.
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
23d8s23hs89j239sj23.com
3reh8rd23js9.com
4f394j89d3j4d89j34d.com
d823hrd9239sdj2.com
js823hs23js.com
oidjweidj34rd3.com

How to determine Win32/Kryptik.HDNW?


File Info:

crc32: EF05D338
md5: 8c6810ccbf8b94ad18edabe648ffd504
name: readme.exe
sha1: 9f3770c114956fb31d04ec3020fe4da03a8ac2d4
sha256: b8f848f137a23fe046b4701a67d07c8e7e1a8fdb066f318424caede7a1e69530
sha512: 7bf15296bbdce5aee540b9a6738c65a3f54b773f6aa50b27a98ad8c33544ff60625f650c8bb90fa17a0c60e8b799a88536f5609b41a94784fcb283b810f0b7b9
ssdeep: 6144:UMLeUFXXI8t9K/uN6qmhCaHA5DZNyI187cMsU5wgsbZv+:JesY8t9KQ6q9WAZNVOAzzr+
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.HDNW also known as:

BkavHW32.Packed.
McAfeePacked-GAM!8C6810CCBF8B
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_90% (W)
Invinceaheuristic
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HDNW
APEXMalicious
KasperskyUDS:DangerousObject.Multi.Generic
AegisLabTrojan.Win32.Generic.4!c
Endgamemalicious (high confidence)
EmsisoftTrojan.Miner (A)
DrWebTrojan.Siggen9.48214
McAfee-GW-EditionBehavesLike.Win32.Upatre.fh
FireEyeGeneric.mg.8c6810ccbf8b94ad
SophosMal/Generic-S
IkarusWin32.Outbreak
MicrosoftTrojan:Win32/Wacatac.D!ml
ZoneAlarmUDS:DangerousObject.Multi.Generic
Acronissuspicious
VBA32Malware-Cryptor.Limpopo
RisingMalware.Heuristic!ET#87% (RDMK:cmRtazrDPLeVmyL7Jg5URubJaKxY)
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_84%
FortinetW32/Kryptik.HDNW!tr
BitDefenderThetaGen:NN.ZexaF.34122.vqW@aK3DuwaG
Cybereasonmalicious.114956
Paloaltogeneric.ml
Qihoo-360HEUR/QVM10.1.6108.Malware.Gen

How to remove Win32/Kryptik.HDNW?

Win32/Kryptik.HDNW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment