Hi_Kitty_2.exe

Classification: Malicious

Hi_Kitty_2.exe is a malicious file sample. Linked to Hellokitty malware. Reported by 3 threat sources, last seen 2026-06-15. Detected by 56 antivirus engines.

Detection summary

  • 56 antivirus detections (84% detection ratio)
  • 0 IDS alerts
  • 144 processes observed
  • 0 contacted hosts
  • 0 DNS requests

MITRE ATT&CK associations

Malware families: HELLOKITTY (S0617)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Hellokitty Triage 2026-06-15 17:02:32 2026-06-15 17:02:32 malicious-activity S0617 HELLOKITTY
HelloKitty MalwareBazaar Abuse.ch 2025-04-10 08:27:53 2025-04-10 08:27:53 malicious-activity S0617 HELLOKITTY
Trojan.AntiAV Hybrid-Analysis 2021-03-10 07:30:26 2021-03-10 07:30:26

Tags

hellokitty defense_evasion discovery ransomware

Sample information

Filenames
Hi_Kitty_2.exe, 501487b025f25ddf1ca32deb57a2b4db43ccf6635c1edc74b9cff54ce0e5bcfe, 501487b025f25ddf1ca32deb57a2b4db43ccf6635c1edc74b9cff54ce0e5bcfe.exe
File type
PE32 executable (GUI) Intel 80386, for MS Windows
Size
160849 bytes
MD5
136bd70f7aa98f52861879d7dca03cf2
SHA-1
fadd8d7c13a18c251ded1f645ffea18a37f1c2de
SHA-256
501487b025f25ddf1ca32deb57a2b4db43ccf6635c1edc74b9cff54ce0e5bcfe
First indexed
2021-03-10 07:30:26
Last updated
2026-06-19 13:44:07

Antivirus detections

EngineDetection
Elasticmalicious (high confidence)
ClamAVWin.Ransomware.Kitty-9822510-0
CAT-QuickHealTrojan.AntiAV
McAfeeRDN/Ransom
MalwarebytesRansom.HelloKitty
ZillyaTrojan.AntiAV.Win32.13751
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00570ef31 )
AlibabaRansom:Win32/generic.ali2000010
K7GWTrojan ( 00570ef31 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Trojan.UFDC-2449
ESET-NOD32a variant of Win32/Filecoder.DeathRansom.C
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.AntiAV
BitDefenderGeneric.Malware.PfVPk!12.299C21F3
NANO-AntivirusTrojan.Win32.AntiAV.iiwmmt
ViRobotTrojan.Win32.Z.Antiav.160849
MicroWorld-eScanGeneric.Malware.PfVPk!12.299C21F3
AvastWin32:HelloKitty-A [Ransom]
RisingRansom.Death!8.11553 (CLOUD)
Ad-AwareGeneric.Malware.PfVPk!12.299C21F3
EmsisoftGeneric.Malware.PfVPk!12.299C21F3 (B)
ComodoMalware@#1ctsznmiwm3c7
F-SecureTrojan.TR/AD.DeathRansom.pvcwt
DrWebTrojan.Encoder.33464
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_Death.R002C0DBI21
McAfee-GW-EditionBehavesLike.Win32.Generic.cm
FireEyeGeneric.mg.136bd70f7aa98f52
SophosMal/Generic-S
SentinelOneStatic AI - Malicious PE
WebrootW32.Trojan.Agent.Gen
AviraTR/AD.DeathRansom.pvcwt
Antiy-AVLTrojan/Win32.AntiAV
MicrosoftRansom:Win32/Death.DB!MTB
GridinsoftRansom.Win32.DeathRansom.sa
ArcabitGeneric.Malware.PfVPk!12.299C21F3
AegisLabTrojan.Win32.AntiAV.4!c
ZoneAlarmHEUR:Trojan.Win32.AntiAV
GDataWin32.Trojan-Ransom.Death.A
AhnLab-V3Malware/Win32.Generic.C4241507
VBA32BScope.TrojanRansom.Encoder
ALYacTrojan.Ransom.DEATHRansom
MAXmalware (ai score=100)
CylanceUnsafe
TrendMicro-HouseCallRansom_Death.R002C0DBI21
YandexTrojan.AntiAV!EjEbOB8rL6Q
IkarusTrojan-Ransom.DeathRansom
FortinetW32/DeathRansom.C!tr.ransom
BitDefenderThetaGen:NN.ZexaF.34608.jqX@a0yMkEe
AVGWin32:HelloKitty-A [Ransom]
PandaTrj/GdSda.A
Qihoo-360Win32/Trojan.AntiAV.HgIASPQA

Process list

NameCommand line
501487b025f25ddf1ca32deb57a2b4db43ccf6635c1edc74b9cff54ce0e5bcfe.exe
taskkill.exe/f /im mysql*
taskkill.exe/f /im dsa*
taskkill.exe/f /im Ntrtscan*
taskkill.exe/f /im ds_monitor*
taskkill.exe/f /im Notifier*
taskkill.exe/f /im TmListen*
taskkill.exe/f /im iVPAgent*
taskkill.exe/f /im CNTAoSMgr*
taskkill.exe/f /im IBM*
taskkill.exe/f /im bes10*
taskkill.exe/f /im black*
taskkill.exe/f /im robo*
taskkill.exe/f /im copy*
taskkill.exe/f /im store.exe
taskkill.exe/f /im sql*
taskkill.exe/f /im vee*
taskkill.exe/f /im wrsa*
taskkill.exe/f /im wrsa.exe
taskkill.exe/f /im postg*
taskkill.exe/f /im sage*
net.exestop MSSQLServerADHelper100
net1.exe%WINDIR%\system32\net1 stop MSSQLServerADHelper100
net.exestop MSSQL$ISARS
net1.exe%WINDIR%\system32\net1 stop MSSQL$ISARS
net.exestop MSSQL$MSFW
net1.exe%WINDIR%\system32\net1 stop MSSQL$MSFW
net.exestop SQLAgent$ISARS
net1.exe%WINDIR%\system32\net1 stop SQLAgent$ISARS
net.exestop SQLAgent$MSFW