Malware

Win32/Kryptik.HQFO malicious file

Malware Removal

The Win32/Kryptik.HQFO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HQFO virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Checks adapter addresses which can be used to detect virtual network interfaces
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Korean
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Enumerates services, possibly for anti-virtualization
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Behavioural detection: Injection (inter-process)
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • CAPE detected the Tofsee malware family
  • Deletes executed files from disk
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/Kryptik.HQFO?


File Info:

name: 8741B961E927C5AEA720.mlw
path: /opt/CAPEv2/storage/binaries/fefb50695751161a0085bb6b7ec4b90891ead04937056329be3f947b22c7fd52
crc32: A3A6EADB
md5: 8741b961e927c5aea720d6aa1fae7678
sha1: 130e2d297ef82b5734414a7ce0a4c128f461f213
sha256: fefb50695751161a0085bb6b7ec4b90891ead04937056329be3f947b22c7fd52
sha512: 081f02863dd8832e5c58870a42ab513dd8f2b1513737c1ed8eb681359e0c9380aaad81539d69289fc57974fe729476696a7aebe8f9e7312523a16296ef17c86b
ssdeep: 6144:r6ZiIPpBRMTMtRZe5g/4bE5UoB8VmniQR+L:G9rGTMDZe5tEuoVn
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FCC6E550BA98E94BD4112D364936C6A25A66FCCBF91517C731C87F1FFC3A6943A22E03
sha3_384: 1e8257d2db09800d304c58d3c7a823fa079f3126f1fdb7404e46c32170278ae22038aaaaa70d1ebe6c679129609403b2
ep_bytes: 8bff558bece896a60000e8110000005d
timestamp: 2021-09-23 05:24:03

Version Info:

Translations: 0x0152 0x036f

Win32/Kryptik.HQFO also known as:

BkavW32.AIDetect.malware2
tehtrisGeneric.Malware
DrWebTrojan.PWS.Siggen3.20109
MicroWorld-eScanTrojan.GenericKDZ.90011
FireEyeGeneric.mg.8741b961e927c5ae
CAT-QuickHealRansom.Stop.P5
McAfeePacked-GEE!8741B961E927
CylanceUnsafe
VIPRETrojan.GenericKDZ.90011
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.1e927c
CyrenW32/Agent.ETY.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HQFO
TrendMicro-HouseCallMal_Tofsee
ClamAVWin.Packed.Generic-9956955-0
KasperskyHEUR:Backdoor.Win32.Tofsee.gen
BitDefenderTrojan.GenericKDZ.90011
NANO-AntivirusTrojan.Win32.Tofsee.jqgnlq
AvastWin32:PWSX-gen [Trj]
Ad-AwareTrojan.GenericKDZ.90011
EmsisoftTrojan.GenericKDZ.90011 (B)
TrendMicroMal_Tofsee
McAfee-GW-EditionBehavesLike.Win32.Dropper.wt
Trapminemalicious.moderate.ml.score
SophosML/PE-A + Troj/Krypt-FV
IkarusTrojan-Ransom.StopCrypt
AviraTR/AD.Tofsee.kxkop
MAXmalware (ai score=83)
Antiy-AVLTrojan/Generic.ASMalwS.769
MicrosoftTrojan:Win32/RedlineStealer.PSA!MTB
ArcabitTrojan.Generic.D15F9B
GDataWin32.Trojan.PSE.10CPGR
CynetMalicious (score: 100)
AhnLab-V3Packed/Win.GEE.R505873
Acronissuspicious
VBA32BScope.Trojan.Crypt
ALYacTrojan.GenericKDZ.90011
MalwarebytesTrojan.MalPack.GS
APEXMalicious
RisingTrojan.Kryptik!1.DF24 (CLASSIC)
YandexTrojan.Kryptik!h6dE/95C7Kw
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Packed.GEE!tr
AVGWin32:PWSX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Kryptik.HQFO?

Win32/Kryptik.HQFO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment