Malware

Win32/Kryptik.HIXA (file analysis)

Malware Removal

The Win32/Kryptik.HIXA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HIXA virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Serbian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/Kryptik.HIXA?


File Info:

crc32: DF7F0D74
md5: f0f1a843b50f76e7236cc32dedf1d65d
name: F0F1A843B50F76E7236CC32DEDF1D65D.mlw
sha1: f84f30a93355d46bbdbebfedc760188879b6db0b
sha256: 3ed3126cfc3094e0f1a5736369cc55f68feb9bf6c9e31ba6e00e36f11917bc18
sha512: f856db58b39aacbc858a248a7352ee20e63ac3a50966ebb9a95bcacad6221d98eff7a8f4024fae08badfc45396a7312a8bf70e69e5802777b7e34ef6e48342a2
ssdeep: 6144:wX1hMsbYGsac7MH+ZJAjs0s7Smyv7tAxi1iJ1In32f:wZYqc7k0Jd0sOBtr0qa
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifor.occ
FileVersion: 6.26.343
Copyright: Copyrighz (C) 2020, wodkagude
ProductVersion: 1.13.22
TranslationUsa: 0x0173 0x00e1

Win32/Kryptik.HIXA also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45548722
FireEyeGeneric.mg.f0f1a843b50f76e7
McAfeeArtemis!F0F1A843B50F
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 005766661 )
BitDefenderTrojan.GenericKD.45548722
K7GWTrojan ( 005766661 )
Cybereasonmalicious.93355d
BitDefenderThetaGen:NN.ZexaF.34780.rmLfauUx7GnG
CyrenW32/Kryptik.DBB.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HIXA
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
KasperskyTrojan-Spy.Win32.Noon.bauh
AlibabaTrojanSpy:Win32/Azorult.e577bf5b
ViRobotTrojan.Win32.Z.Kryptik.283136.BE
AegisLabTrojan.Win32.Malicious.4!c
RisingTrojan.Kryptik!8.8 (TFE:5:yLLlZ3TYilR)
Ad-AwareTrojan.GenericKD.45548722
SophosMal/Generic-S
ComodoMalware@#1gccov7dzqpc6
DrWebTrojan.Siggen11.58945
TrendMicroTROJ_FRS.0NA103AK21
McAfee-GW-EditionBehavesLike.Win32.Trojan.dc
EmsisoftTrojan.GenericKD.45548722 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/AD.Swotter.yecpv
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Azorult.MU!MTB
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.Generic.D2B704B2
AhnLab-V3Malware/Win32.Generic.C4304547
ZoneAlarmTrojan-Spy.Win32.Noon.bauh
GDataTrojan.GenericKD.45548722
CynetMalicious (score: 100)
Acronissuspicious
VBA32BScope.Trojan.Azorult
ALYacTrojan.GenericKD.45548722
MalwarebytesGeneric.Trojan.Malicious.DDS
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_FRS.0NA103AK21
TencentWin32.Trojan-spy.Noon.Edwz
IkarusTrojan.Win32.Crypt
eGambitUnsafe.AI_Score_84%
FortinetW32/Kryptik.HIRY!tr
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.Spy.e42

How to remove Win32/Kryptik.HIXA?

Win32/Kryptik.HIXA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment