Classification: Malicious
Hi_Kitty_2.exe is a malicious file sample. Linked to Hellokitty malware. Reported by 3 threat sources, last seen 2026-06-15. Detected by 56 antivirus engines.
Detection summary
- 56 antivirus detections (84% detection ratio)
- 0 IDS alerts
- 144 processes observed
- 0 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Hellokitty |
Triage |
2026-06-15 17:02:32 |
2026-06-15 17:02:32 |
malicious-activity
|
S0617 HELLOKITTY
|
| HelloKitty |
MalwareBazaar Abuse.ch |
2025-04-10 08:27:53 |
2025-04-10 08:27:53 |
malicious-activity
|
S0617 HELLOKITTY
|
| Trojan.AntiAV |
Hybrid-Analysis |
2021-03-10 07:30:26 |
2021-03-10 07:30:26 |
|
|
Tags
hellokitty
defense_evasion
discovery
ransomware
Sample information
- Filenames
- Hi_Kitty_2.exe, 501487b025f25ddf1ca32deb57a2b4db43ccf6635c1edc74b9cff54ce0e5bcfe, 501487b025f25ddf1ca32deb57a2b4db43ccf6635c1edc74b9cff54ce0e5bcfe.exe
- File type
- PE32 executable (GUI) Intel 80386, for MS Windows
- Size
- 160849 bytes
- MD5
136bd70f7aa98f52861879d7dca03cf2
- SHA-1
fadd8d7c13a18c251ded1f645ffea18a37f1c2de
- SHA-256
501487b025f25ddf1ca32deb57a2b4db43ccf6635c1edc74b9cff54ce0e5bcfe
- First indexed
- 2021-03-10 07:30:26
- Last updated
- 2026-06-19 13:44:07
Antivirus detections
| Engine | Detection |
| Elastic | malicious (high confidence) |
| ClamAV | Win.Ransomware.Kitty-9822510-0 |
| CAT-QuickHeal | Trojan.AntiAV |
| McAfee | RDN/Ransom |
| Malwarebytes | Ransom.HelloKitty |
| Zillya | Trojan.AntiAV.Win32.13751 |
| Sangfor | Trojan.Win32.Save.a |
| K7AntiVirus | Trojan ( 00570ef31 ) |
| Alibaba | Ransom:Win32/generic.ali2000010 |
| K7GW | Trojan ( 00570ef31 ) |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cyren | W32/Trojan.UFDC-2449 |
| ESET-NOD32 | a variant of Win32/Filecoder.DeathRansom.C |
| APEX | Malicious |
| Paloalto | generic.ml |
| Cynet | Malicious (score: 100) |
| Kaspersky | HEUR:Trojan.Win32.AntiAV |
| BitDefender | Generic.Malware.PfVPk!12.299C21F3 |
| NANO-Antivirus | Trojan.Win32.AntiAV.iiwmmt |
| ViRobot | Trojan.Win32.Z.Antiav.160849 |
| MicroWorld-eScan | Generic.Malware.PfVPk!12.299C21F3 |
| Avast | Win32:HelloKitty-A [Ransom] |
| Rising | Ransom.Death!8.11553 (CLOUD) |
| Ad-Aware | Generic.Malware.PfVPk!12.299C21F3 |
| Emsisoft | Generic.Malware.PfVPk!12.299C21F3 (B) |
| Comodo | Malware@#1ctsznmiwm3c7 |
| F-Secure | Trojan.TR/AD.DeathRansom.pvcwt |
| DrWeb | Trojan.Encoder.33464 |
| VIPRE | Trojan.Win32.Generic!BT |
| TrendMicro | Ransom_Death.R002C0DBI21 |
| McAfee-GW-Edition | BehavesLike.Win32.Generic.cm |
| FireEye | Generic.mg.136bd70f7aa98f52 |
| Sophos | Mal/Generic-S |
| SentinelOne | Static AI - Malicious PE |
| Webroot | W32.Trojan.Agent.Gen |
| Avira | TR/AD.DeathRansom.pvcwt |
| Antiy-AVL | Trojan/Win32.AntiAV |
| Microsoft | Ransom:Win32/Death.DB!MTB |
| Gridinsoft | Ransom.Win32.DeathRansom.sa |
| Arcabit | Generic.Malware.PfVPk!12.299C21F3 |
| AegisLab | Trojan.Win32.AntiAV.4!c |
| ZoneAlarm | HEUR:Trojan.Win32.AntiAV |
| GData | Win32.Trojan-Ransom.Death.A |
| AhnLab-V3 | Malware/Win32.Generic.C4241507 |
| VBA32 | BScope.TrojanRansom.Encoder |
| ALYac | Trojan.Ransom.DEATHRansom |
| MAX | malware (ai score=100) |
| Cylance | Unsafe |
| TrendMicro-HouseCall | Ransom_Death.R002C0DBI21 |
| Yandex | Trojan.AntiAV!EjEbOB8rL6Q |
| Ikarus | Trojan-Ransom.DeathRansom |
| Fortinet | W32/DeathRansom.C!tr.ransom |
| BitDefenderTheta | Gen:NN.ZexaF.34608.jqX@a0yMkEe |
| AVG | Win32:HelloKitty-A [Ransom] |
| Panda | Trj/GdSda.A |
| Qihoo-360 | Win32/Trojan.AntiAV.HgIASPQA |
Process list
| Name | Command line |
| 501487b025f25ddf1ca32deb57a2b4db43ccf6635c1edc74b9cff54ce0e5bcfe.exe | |
| taskkill.exe | /f /im mysql* |
| taskkill.exe | /f /im dsa* |
| taskkill.exe | /f /im Ntrtscan* |
| taskkill.exe | /f /im ds_monitor* |
| taskkill.exe | /f /im Notifier* |
| taskkill.exe | /f /im TmListen* |
| taskkill.exe | /f /im iVPAgent* |
| taskkill.exe | /f /im CNTAoSMgr* |
| taskkill.exe | /f /im IBM* |
| taskkill.exe | /f /im bes10* |
| taskkill.exe | /f /im black* |
| taskkill.exe | /f /im robo* |
| taskkill.exe | /f /im copy* |
| taskkill.exe | /f /im store.exe |
| taskkill.exe | /f /im sql* |
| taskkill.exe | /f /im vee* |
| taskkill.exe | /f /im wrsa* |
| taskkill.exe | /f /im wrsa.exe |
| taskkill.exe | /f /im postg* |
| taskkill.exe | /f /im sage* |
| net.exe | stop MSSQLServerADHelper100 |
| net1.exe | %WINDIR%\system32\net1 stop MSSQLServerADHelper100 |
| net.exe | stop MSSQL$ISARS |
| net1.exe | %WINDIR%\system32\net1 stop MSSQL$ISARS |
| net.exe | stop MSSQL$MSFW |
| net1.exe | %WINDIR%\system32\net1 stop MSSQL$MSFW |
| net.exe | stop SQLAgent$ISARS |
| net1.exe | %WINDIR%\system32\net1 stop SQLAgent$ISARS |
| net.exe | stop SQLAgent$MSFW |