Malware

Win32/Kryptik.HNIN (file analysis)

Malware Removal

The Win32/Kryptik.HNIN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HNIN virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Divehi
  • The binary likely contains encrypted or compressed data.
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

postbackstat.biz
forwardstorage.biz

How to determine Win32/Kryptik.HNIN?


File Info:

crc32: 48CD358E
md5: bae32df2bed6a03c9b1a973bf23de6ee
name: BAE32DF2BED6A03C9B1A973BF23DE6EE.mlw
sha1: 3e3ddbc0f1b40702403431321508ac8bf99a6735
sha256: 485ac78c493a9b98cb4759f52e12898f820cafb6b5b2e41e27f764a253d3dfe5
sha512: 9bdc685e3938f30aeb683808ca509d6bbf7c6617e228ea13f68a2e6b96e411c3389fdbf71404c2cd6cfd50b5e18162a299e16303382209243afd303c8d14f9cf
ssdeep: 12288:qpplCLY0Q9+gNVKr9aSNUlZgnxrh2A8hVC:qRODF0VKsSNagn2F
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translations: 0x0522 0x023c

Win32/Kryptik.HNIN also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
ClamAVWin.Packed.Generic-9910074-0
McAfeePacked-GDT!BAE32DF2BED6
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
K7GWRiskware ( 0040eff71 )
BaiduWin32.Trojan.Kryptik.jm
CyrenW32/Kryptik.FSC.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HNIN
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Bsymem.gen
BitDefenderTrojan.GenericKDZ.80234
MicroWorld-eScanTrojan.GenericKDZ.80234
TencentWin32.Trojan.Ulise.Pjnf
Ad-AwareTrojan.GenericKDZ.80234
SophosML/PE-A + Troj/Krypt-DY
FireEyeGeneric.mg.bae32df2bed6a03c
EmsisoftTrojan.GenericKDZ.80234 (B)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_96%
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftRansom:Win32/StopCrypt.MTK!MTB
ArcabitTrojan.Generic.D1396A
GDataWin32.Trojan.BSE.WS9D4D
AhnLab-V3CoinMiner/Win.Glupteba.R450745
Acronissuspicious
VBA32BScope.Backdoor.Agent
MAXmalware (ai score=85)
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
RisingTrojan.Generic@ML.90 (RDML:QPKPxsL4J01kMMtwlO/RLw)
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.FNRJ!tr
AVGWin32:TrojanX-gen [Trj]

How to remove Win32/Kryptik.HNIN?

Win32/Kryptik.HNIN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment