Malware

Win32/Kryptik.HKSI malicious file

Malware Removal

The Win32/Kryptik.HKSI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HKSI virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (6 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Malay (Brunei Darussalam)
  • The binary likely contains encrypted or compressed data.
  • Looks up the external IP address
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Network activity contains more than one unique useragent.
  • Collects information about installed applications
  • Creates a hidden or system file
  • Attempts to identify installed AV products by installation directory
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Attempts to access Bitcoin/ALTCoin wallets
  • Harvests information related to installed instant messenger clients
  • Attempts to create or modify system certificates
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
g-clean.in
sulvxl02.top
nailedpizza.top
api.ipify.org
iplogger.org
truzen.space

How to determine Win32/Kryptik.HKSI?


File Info:

crc32: 18C48D1B
md5: 6a37fa585bfd1ac9e6ca94ce01626a58
name: 6A37FA585BFD1AC9E6CA94CE01626A58.mlw
sha1: 668ffc4c0524999211f75a63f6f875c4c20d4a98
sha256: 8a9ed010aa3db217f81dfa4d928863eef5cac1165dab6c03258948b8ef019435
sha512: 2cec9efc73e90f86c6083738058540cb3c2ba913821ba9ce6f08293a000164eefb812f914d3fec6d3d5251301b5e16eaa23fc21863e92bcbebcec0f7370ade76
ssdeep: 6144:7SWHQFmgeqO1/4kjckQHafCQWQAusuMAvYeGkRabcUyI2sazgnZaN8:THQFmgeqOlwkea6rubgeGkucUyIRwgZ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

ProductVersus: 1.9.37.29
FileVersion: 1.0.52.18
Translations: 0x0386 0x01d6

Win32/Kryptik.HKSI also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0057bf641 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Siggen2.64892
CynetMalicious (score: 100)
ALYacTrojan.GenericKDZ.74974
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Glupteba.2f98f7b2
K7GWTrojan ( 0057bf641 )
Cybereasonmalicious.c05249
CyrenW32/Kryptik.EAC.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HKSI
APEXMalicious
AvastWin32:PWSX-gen [Trj]
ClamAVWin.Packed.Pwsx-9859723-0
KasperskyHEUR:Trojan-Ransom.Win32.Stop.gen
BitDefenderTrojan.GenericKDZ.74974
ViRobotTrojan.Win32.Z.Pwsx.380928
MicroWorld-eScanTrojan.GenericKDZ.74974
Ad-AwareTrojan.GenericKDZ.74974
SophosMal/Generic-R + Mal/GandCrypt-A
BitDefenderThetaGen:NN.ZexaF.34688.xu0@a0lFnpkO
TrendMicroTrojanSpy.Win32.STOP.USMANEA21
McAfee-GW-EditionBehavesLike.Win32.Lockbit.fh
FireEyeGeneric.mg.6a37fa585bfd1ac9
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraTR/Crypt.Agent.bopfv
eGambitUnsafe.AI_Score_51%
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Glupteba.PW!MTB
ArcabitTrojan.Generic.D124DE
AegisLabTrojan.Win32.Stop.j!c
ZoneAlarmHEUR:Trojan-Ransom.Win32.Stop.gen
GDataTrojan.GenericKDZ.74974
AhnLab-V3Trojan/Win.MalPE.R419150
Acronissuspicious
McAfeeArtemis!6A37FA585BFD
MAXmalware (ai score=87)
VBA32BScope.Backdoor.Convagent
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojanSpy.Win32.STOP.USMANEA21
RisingTrojan.Kryptik!1.D5B4 (CLOUD)
IkarusTrojan.Win32.Azorult
FortinetW32/Kryptik.HKSS!tr
AVGWin32:PWSX-gen [Trj]

How to remove Win32/Kryptik.HKSI?

Win32/Kryptik.HKSI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment