Malware

Win32/Kryptik.HQHC information

Malware Removal

The Win32/Kryptik.HQHC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HQHC virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Checks adapter addresses which can be used to detect virtual network interfaces
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Enumerates running processes
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Korean
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Writes a potential ransom message to disk
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Transacted Hollowing
  • Created a process from a suspicious location
  • Collects and encrypts information about the computer likely to send to C2 server
  • Installs itself for autorun at Windows startup
  • STOP ransomware registry artifacts detected
  • Likely virus infection of existing system binary
  • CAPE detected the STOP malware family
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Creates a known STOP-Djvu ransomware decryption instruction / key file.
  • Creates a known STOP ransomware variant mutex
  • STOP ransomware command line behavior detected
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/Kryptik.HQHC?


File Info:

name: 6DC02B77F132B1F62186.mlw
path: /opt/CAPEv2/storage/binaries/44d0f7681d902511068e55ce142430fd1ad71ed1ea2b1ea1383477364cede6b1
crc32: 19027E9B
md5: 6dc02b77f132b1f6218616a6013d3244
sha1: a447dbb98bab7f4023d77dda297be76bf121cc65
sha256: 44d0f7681d902511068e55ce142430fd1ad71ed1ea2b1ea1383477364cede6b1
sha512: b102140772a4aa4928bc41d737687eb859e56aeae2cce3f87a606c7a6852092782d576a099d8dd87ac8446c32889d0f441b7c75a66f103457ea498a83072056b
ssdeep: 12288:5scmFFPym5Z0p9faf5ZYWT2oR0hFBTZGPzzgz7VDLeonGKM8x47qQGuFH9lqBsH:qFPyuomLcVThVDLeonPMBDBH9lqm
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T179050200BA90D831F9F612F546BAC3A8B92E7EE15B2455CF12D516DE1B39AE1EC30317
sha3_384: 5a53e8b57a7182d3a3043abed7852ee4d95ea1cf8339b453fa4453ce20e230ed379a449a6cb5e0fe5c5b3ad668f1a917
ep_bytes: 8bff558bece8468e0000e8110000005d
timestamp: 2021-10-01 15:33:32

Version Info:

Translations: 0x0353 0x036f

Win32/Kryptik.HQHC also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Convagent.4!c
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKD.61077074
ALYacTrojan.Ransom.Stop
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 00584baa1 )
AlibabaTrojan:Win32/Raccoon.80fb2ede
K7GWRiskware ( 00584baa1 )
Cybereasonmalicious.98bab7
CyrenW32/Kryptik.HDO.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HQHC
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Crypterx-9954995-0
KasperskyHEUR:Trojan.Win32.Scarsi.gen
BitDefenderTrojan.GenericKD.61077074
AvastWin32:Malware-gen
TencentWin32.Trojan.Scarsi.Wtdw
Ad-AwareTrojan.GenericKD.61077074
EmsisoftTrojan.GenericKD.61077074 (B)
DrWebTrojan.PWS.Siggen3.20438
VIPRETrojan.GenericKD.61077074
McAfee-GW-EditionBehavesLike.Win32.Lockbit.cc
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.6dc02b77f132b1f6
SophosMal/Generic-R + Troj/Krypt-FV
IkarusTrojan.SmokeLoader
GDataWin32.Trojan.PSE.10CPGR
AviraTR/Redcap.hzibx
Antiy-AVLTrojan/Generic.ASMalwS.8149
ArcabitTrojan.Generic.D3A3F652
MicrosoftTrojan:Win32/Raccoon.RD!MTB
CynetMalicious (score: 100)
AhnLab-V3Infostealer/Win.Raccoon.R507211
Acronissuspicious
McAfeePacked-GEE!6DC02B77F132
MalwarebytesTrojan.MalPack.GS
TrendMicro-HouseCallTROJ_GEN.R002H01GS22
RisingTrojan.Generic@AI.94 (RDML:RA7pgX2bNqeodvgb2R5ADA)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Kryptik.HQHC?

Win32/Kryptik.HQHC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment