Malware

Win32/Kryptik.HMAX malicious file

Malware Removal

The Win32/Kryptik.HMAX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HMAX virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Looks up the external IP address
  • Executed a process and injected code into it, probably while unpacking
  • Steals private information from local Internet browsers
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a file
  • Detects VMware through the presence of a file
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

icanhazip.com

How to determine Win32/Kryptik.HMAX?


File Info:

crc32: CE2302F0
md5: 6f0df16188d51b39c387df210a1077df
name: 6F0DF16188D51B39C387DF210A1077DF.mlw
sha1: abe98a6755bab5b01c2becd90a586829afcb9336
sha256: e29247ccbd64ef5da34a09b073f1f638c23bd7d280724feabf900e6ac786af52
sha512: 9a2441c332a605893f8b192e42ef61a68d395cc86358d7f4d96dbd592668cbcdf3701bb3a581f011632e66c33a58c7235ec433011bb1c092603457efed84973e
ssdeep: 12288:ZDmzAbVSux7iVK+G2L4SkX8CzdBTAKl2cEGff3kvZp1FXbd4Ga/pzP:0QVSuAVK+G2pkDdBT7l3EW4Trtah
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Kryptik.HMAX also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (W)
ESET-NOD32a variant of Win32/Kryptik.HMAX
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyUDS:Trojan.Win32.Zenpak.gen
SophosMal/Generic-R
BitDefenderThetaGen:NN.ZexaF.34058.PqZ@aiXiD6fi
McAfee-GW-EditionBehavesLike.Win32.Emotet.jh
FireEyeGeneric.mg.6f0df16188d51b39
MicrosoftTrojan:Win32/Tnega!ml
McAfeeArtemis!6F0DF16188D5
VBA32BScope.Trojan-Dropper.Injector
RisingTrojan.Kryptik!1.D84E (CLASSIC)
IkarusWin32.Outbreak
FortinetW32/Kryptik.HLWI!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml

How to remove Win32/Kryptik.HMAX?

Win32/Kryptik.HMAX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment