Malware

About “Win32/Kryptik.HNKJ” infection

Malware Removal

The Win32/Kryptik.HNKJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HNKJ virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Spanish (Paraguay)
  • The binary likely contains encrypted or compressed data.
  • Looks up the external IP address
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • CAPE detected the RedLineDropperAHK malware family
  • Attempts to identify installed AV products by installation directory
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Created network traffic indicative of malicious activity

Related domains:

iplogger.org
warmbeddy.top

How to determine Win32/Kryptik.HNKJ?


File Info:

name: 9F957648863482FE0196.mlw
path: /opt/CAPEv2/storage/binaries/167babea8b4f143b063ca94d7bea4396a0817e7acf111e8f357041e87db1e4ff
crc32: D37AD50E
md5: 9f957648863482fe0196cca5bf3affe8
sha1: 143134d3214ea8abccf2b47e0fbb250bffa77f1b
sha256: 167babea8b4f143b063ca94d7bea4396a0817e7acf111e8f357041e87db1e4ff
sha512: 6d49d24cc8535193886092bad0f872c4bbc9a6e65f22dafd562d97981579726f792c329f3c815b3463e89758a9f3607cf27ea5fa403a277c15890f687e4267a9
ssdeep: 12288:ZaHhfOJdTTofwgcsaAnkHeqCBJp9mZizR9mxRX0aKmemch:ABmdPofwJsxnkIuizzKKMc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E1E4010477A1C039F5B717F499B693A8663E3D615B3894C7A2C52BF996706E0EE3030B
sha3_384: ec092c6bb00c2b390b4f0104fb5cee97e67380c84dd0cb65b537adeecaea447737109b56317e46652cdf65759ea6e3b5
ep_bytes: 8bff558bece806030000e8110000005d
timestamp: 2021-05-27 02:40:55

Version Info:

0: [No Data]

Win32/Kryptik.HNKJ also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Jaik.49513
FireEyeGeneric.mg.9f957648863482fe
McAfeeArtemis!9F9576488634
CylanceUnsafe
K7AntiVirusTrojan ( 0058ac881 )
AlibabaTrojan:Win32/Kryptik.3185529f
K7GWTrojan ( 0058ac881 )
Cybereasonmalicious.3214ea
CyrenW32/Kryptik.FQI.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HNKJ
BaiduWin32.Trojan.Kryptik.jm
TrendMicro-HouseCallTROJ_GEN.R002H0CKN21
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Zenpak.gen
BitDefenderGen:Variant.Jaik.49513
AvastWin32:Trojan-gen
Ad-AwareGen:Variant.Jaik.49513
EmsisoftTrojan.Crypt (A)
DrWebTrojan.Siggen15.50429
McAfee-GW-EditionBehavesLike.Win32.Injector.jc
SophosMal/Generic-R + Troj/Krypt-DY
APEXMalicious
JiangminTrojanSpy.Stealer.igz
eGambitUnsafe.AI_Score_96%
AviraTR/Crypt.Agent.vkfdu
MAXmalware (ai score=83)
KingsoftWin32.Troj.Undef.(kcloud)
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Azorult.RMA!MTB
GDataWin32.Trojan.BSE.WS9D4D
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.MalPe.R418715
Acronissuspicious
VBA32BScope.Trojan.Krypter
ALYacGen:Variant.Jaik.49513
MalwarebytesTrojan.MalPack.GS
IkarusTrojan.Agent
RisingMalware.Obscure/Heur!1.A89F (CLASSIC)
YandexTrojan.Zenpak!ty9QPUU7Hyk
SentinelOneStatic AI – Malicious PE
FortinetW32/GenKryptik.FNWZ!tr
AVGWin32:Trojan-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Win32/Kryptik.HNKJ?

Win32/Kryptik.HNKJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment