Malware

Win32/Kryptik.HUBK (file analysis)

Malware Removal

The Win32/Kryptik.HUBK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Kryptik.HUBK virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/Kryptik.HUBK?


File Info:

name: C42DE3199E9FAD126615.mlw
path: /opt/CAPEv2/storage/binaries/8ca4cec16f269251bda2ffbaf19792f4e8f1d65e6e70d3bee49bbc5a0ae13d59
crc32: 4D05C4DF
md5: c42de3199e9fad1266150bfa24662d7f
sha1: 6756ab4a471a134bcf569743ce2bd720380db842
sha256: 8ca4cec16f269251bda2ffbaf19792f4e8f1d65e6e70d3bee49bbc5a0ae13d59
sha512: 5e804224c00589e238454466c10aebd41146eb9756d9cd5300c364129d6f588ab9b58e627dd3589944c8b7bed1e011d8f78400d2f3e6af355718002594a465df
ssdeep: 24576:7JofBUs+b/QwEpl6eCKIwlYUb5wUxO+kjFyEwHWbO66teUeXFYqlBbVTb34k30/V:VKBDwSl6e0wlYUtwUxOrAu3ykji9
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1BF85CFDBE45C197FF4C03E3A83EC67BF6B74722862A86E35931A51611F91B10916322F
sha3_384: a767b341a7fedec48eeeff61f21455eb90ad77e3b4c27017bf766559b06fe429deddc275459e8ef58da08ddd14ebd3eb
ep_bytes: e8a3020000e974feffff558bec8b4508
timestamp: 2023-07-12 23:50:08

Version Info:

0: [No Data]

Win32/Kryptik.HUBK also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Stealer.12!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.68147538
McAfeeArtemis!C42DE3199E9F
VIPRETrojan.GenericKD.68147538
SangforSuspicious.Win32.Save.a
VirITTrojan.Win32.Genus.RZG
CyrenW32/Agent.GSJ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HUBK
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Spy.Win32.Stealer.gen
BitDefenderTrojan.GenericKD.68147538
AvastWin32:TrojanX-gen [Trj]
TencentMalware.Win32.Gencirc.11b47344
EmsisoftTrojan.GenericKD.68147538 (B)
F-SecureHeuristic.HEUR/AGEN.1319849
McAfee-GW-EditionBehavesLike.Win32.Generic.th
FireEyeGeneric.mg.c42de3199e9fad12
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.SHKWXS
AviraHEUR/AGEN.1319849
MAXmalware (ai score=85)
Antiy-AVLTrojan[Spy]/Win32.Stealer
ArcabitTrojan.Generic.D40FD952
ZoneAlarmHEUR:Trojan-Spy.Win32.Stealer.gen
MicrosoftTrojan:Script/Phonzy.B!ml
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R591509
BitDefenderThetaGen:NN.ZexaF.36318.UrZ@auZRE3f
ALYacTrojan.GenericKD.68147538
Cylanceunsafe
PandaTrj/Chgt.AD
RisingTrojan.Kryptik!1.E832 (CLASSIC)
IkarusTrojan.Agent
MaxSecureTrojan.Malware.73793603.susgen
FortinetPossibleThreat.MU
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32/Kryptik.HUBK?

Win32/Kryptik.HUBK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment