Malware

Win32/Kryptik.HFFP malicious file

Malware Removal

The Win32/Kryptik.HFFP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HFFP virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Looks up the external IP address
  • Deletes its original binary from disk
  • Installs an hook procedure to monitor for mouse events
  • Sniffs keystrokes
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

myexternalip.com
api.ipify.org
ocsp.pki.goog
crl.pki.goog

How to determine Win32/Kryptik.HFFP?


File Info:

crc32: ABA381DE
md5: 063949817bf2434ce131e192e8d3c07f
name: bit.exe
sha1: c69546370bbc4bcdffad17dd191c9913fcd60fee
sha256: 632483224534295727a446bd0269d0bc3cff83c589391ccc9f53d9de8380687a
sha512: db9d43ca74d1f1891d07771ad771e62f241bf7ce62a03587c807efe50ca36f1a2495df064762fe6b8a53f645119e21484e9872c86ad7f8ab7db87bb6d51eaded
ssdeep: 49152:1Ye6AvScMetD6NGtfCiCzJLq3v0hcr+L+yQE3/9Wxefy7Ho281Wvu7R:mvAKcztkCCiCzJLq37SL6kWYfyb81hR
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: efhsjyrg.ufr
ProductionVersus: 1.0.6.23
Copyrights: Copyrighds (C) 2020, hjdk
FileV: 1.0.3
TranslationUsi: 0x0872 0x08ef

Win32/Kryptik.HFFP also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
FireEyeGeneric.mg.063949817bf2434c
McAfeePacked-GAO!063949817BF2
CylanceUnsafe
AegisLabTrojan.Multi.Generic.4!c
SangforMalware
BitDefenderTrojan.GenericKD.34255442
Cybereasonmalicious.70bbc4
Invinceaheuristic
SymantecML.Attribute.HighConfidence
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:DangerousObject.Multi.Generic
AlibabaTrojan:Win32/Kryptik.ae8061a8
MicroWorld-eScanGen:Heur.Dreidel.@r0@xm9tF4
RisingTrojan.Kryptik!1.C98B (CLOUD)
Ad-AwareGen:Heur.Dreidel.@r0@xm9tF4
EmsisoftTrojan.GenericKD.34255442 (B)
DrWebTrojan.Siggen9.62948
FortinetW32/Kryptik.HEZN!tr
SentinelOneDFI – Suspicious PE
JiangminBackdoor.Tofsee.cqj
MAXmalware (ai score=86)
ArcabitTrojan.Dreidel.E3FA9A
ZoneAlarmUDS:DangerousObject.Multi.Generic
MicrosoftTrojan:Win32/Caynamer.A!ml
AhnLab-V3Trojan/Win32.MalPe.R346007
Acronissuspicious
VBA32BScope.Trojan.Caynamer
MalwarebytesSpyware.PasswordStealer
ESET-NOD32a variant of Win32/Kryptik.HFFP
IkarusTrojan-Banker.IcedID
eGambitUnsafe.AI_Score_98%
GDataWin32.Packed.Kryptik.PMYC85
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Generic/HEUR/QVM10.2.E528.Malware.Gen

How to remove Win32/Kryptik.HFFP?

Win32/Kryptik.HFFP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment