Banco de Dados de Ameaças Troianos Trojan.Kryptik.AFPA

Trojan.Kryptik.AFPA

Trojan.Kryptik.AFPA é um nome de detecção usado para identificar uma ameaça trojan que se comporta de maneira típica da família de malware "Kryptik". O rótulo "Kryptik" geralmente se refere a trojans compactados ou ofuscados para dificultar a análise e detecção por ferramentas de segurança, em vez de um único malware específico com um propósito fixo. Como os dados públicos detalhados sobre essa variante específica são limitados, este artigo descreve o comportamento típico de trojans dessa categoria, em vez de apresentar detalhes não confirmados como fatos comprovados.

O que essa ameaça faz

Como a maioria dos trojans, o Trojan.Kryptik.AFPA foi projetado para se disfarçar de arquivo legítimo ou inofensivo enquanto executa ações maliciosas secretamente em segundo plano. Trojans dessa categoria geralmente tentam baixar componentes maliciosos adicionais, modificar configurações do sistema, coletar informações do dispositivo infectado ou conceder a invasores remotos algum nível de controle sobre a máquina comprometida. Algumas variantes também podem tentar desativar ou interferir no software de segurança para evitar detecção e remoção, e muitas são construídas com técnicas de ofuscação especificamente para burlar a verificação antivírus.

Como geralmente chega aos computadores

Os cavalos de Troia desse tipo geralmente se espalham por métodos comuns à categoria mais ampla de cavalos de Troia. Esses métodos geralmente incluem anexos maliciosos em e-mails, links enganosos em mensagens de spam ou phishing, downloads agrupados de fontes de software não confiáveis ou pirateadas, atualizações de software falsas e anúncios maliciosos. Os usuários podem instalar o cavalo de Troia sem saber ao abrir um arquivo infectado, habilitar macros em um documento malicioso ou baixar software crackeado ou geradores de chaves de sites não oficiais.

Riscos para o usuário

Uma vez ativo em um sistema, um trojan como esse pode expor o usuário a uma série de riscos. Esses riscos geralmente incluem roubo de informações pessoais ou financeiras, acesso remoto não autorizado ao dispositivo infectado, instalação de outros malwares, como ransomware ou spyware, degradação do desempenho do sistema e potencial perda de controle sobre contas pessoais caso as credenciais de login sejam capturadas. Como os trojans operam silenciosamente, os danos podem se acumular antes que o usuário perceba que algo está errado.

Sinais de infecção

As infecções por Trojan são frequentemente difíceis de detectar porque são projetadas para permanecerem ocultas, mas existem alguns sinais de alerta típicos dessa categoria de ameaça:

  • Quedas inesperadas no desempenho do sistema ou aumento no uso da CPU e da memória.
  • Processos desconhecidos em execução em segundo plano
  • O software de segurança está desativado ou não atualiza.
  • Atividade de rede ou uso de dados incomuns
  • Novos programas ou programas inesperados que aparecem sem o conhecimento do usuário.
  • Alterações nas configurações do navegador ou na página inicial que não foram feitas pelo usuário.

Como se manter protegido

A proteção contra trojans como este envolve a adoção consistente de hábitos seguros de computação. Os usuários devem evitar abrir anexos de e-mail ou clicar em links de remetentes desconhecidos ou inesperados, baixar softwares apenas de fontes oficiais ou verificadas e manter o sistema operacional e os aplicativos atualizados com os patches de segurança mais recentes. Utilizar softwares de segurança confiáveis e atualizados, além de realizar verificações regulares do sistema, pode ajudar a detectar e remover ameaças antes que causem danos significativos. Manter backups regulares de arquivos importantes também reduz o impacto de qualquer infecção por malware, já que os dados comprometidos podem ser restaurados sem a necessidade de pagar os invasores ou perder informações valiosas.

Relatório de análise

Informação geral

Nome de família: Trojan.Kryptik.AFPA
Status da assinatura: No Signature

Amostras conhecidas

MD5: b16fadffd6e923f951397b70d89578cc
SHA1: 7e66511d43e4562a9749b1cadb848505141015d9
SHA256: F41C9A278474BE33AE2AA6744E12A77D3F12F189AA516AD4057BFEDE7E007698
Tamanho do Arquivo: 6.44 MB.6440448 bytes

Atributos do executável portátil do Windows

  • File doesn't have "Rich" header
  • File doesn't have resources
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Mostrar mais
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Características do arquivo

  • dll
  • imgui
  • x64

Informações do bloco

Total de blocos: 12,162
Blocos potencialmente maliciosos: 3,038
Blocos permitidos: 8,440
Blocos desconhecidos: 684

Mapa visual

0 0 0 x x x x x x x x x x x x 0 0 x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x 0 ? 0 0 0 0 ? x 0 0 x x x x x x x x x x x x x x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x x x 0 0 x 0 x x x x x 0 0 0 0 0 0 x ? 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x x x x 0 0 0 x x 0 x 0 x x x x x x x x x x x x x x x 0 x 0 0 0 0 0 0 0 0 0 x x x x x x x x x x x x x x ? x 0 x x x 0 x x 0 0 x x x x 0 0 x 0 0 x x x x x 0 ? 0 x x 0 ? 0 0 x 0 x 0 x x 0 0 0 x x x x x 0 x x 0 0 x x x 0 x x 0 x 0 0 x x 0 x x 0 0 0 x x x x 0 0 x x x x x 0 x x x 0 x 0 0 x ? ? ? x 0 ? x 0 x ? ? ? ? ? 0 0 x ? ? x x 0 ? 0 0 x x 0 x x x x ? x ? ? 0 x x ? ? 0 ? 0 0 x x x x x 0 x ? ? 0 x ? x 0 x x 0 0 x 0 0 x x 0 x x x 0 0 x x 0 0 x ? ? 0 x 0 x 0 0 x 0 0 0 x 0 x 0 ? 0 x 0 x 0 0 x 0 x 0 x 0 x x x 0 ? 0 0 x ? 0 ? x 0 ? x 0 x ? 0 x 0 x x 0 x 0 0 x 0 x ? 0 0 0 x 0 0 0 x 0 x x 0 x 0 0 0 x 0 x x 0 x 0 0 0 x 0 x x x x x x x x 0 x x ? 0 x x x 0 x x ? ? x x x x x x ? x 0 x x x 0 ? 0 0 x ? x 0 ? x 0 x 0 0 x x 0 x ? ? 0 0 x x x x x x 0 x 0 0 x x 0 x 0 0 0 x x 0 x 0 0 0 x 0 0 x x 0 x x 0 x x x 0 x x x 0 x x x 0 x x 0 x x x 0 ? x 0 ? x x 0 x x 0 x x 0 x x 0 x x 0 x x x 0 x x 0 x x 0 0 x 0 ? 0 x x x x 0 x 0 x ? 0 x 0 x 0 0 x 0 x x x 0 x x 0 x 0 0 x 0 x x 0 x x ? x 0 x x 0 x x 0 x x 0 x x 0 x x x x x x 0 x x 0 x 0 0 x x 0 x x 0 x x 0 x 0 x 0 x 0 0 x x x 0 x x 0 x 0 x x 0 ? x 0 x x 0 x x 0 x x 0 x x 0 ? x 0 ? x x x 0 ? ? 0 ? x x 0 ? x 0 x x 0 x x 0 x x 0 x ? 0 x x 0 x 0 x x 0 x 0 0 x x 0 x 0 0 x ? 0 x ? 0 0 x 0 0 x x 0 ? 0 0 x x 0 x x 0 x x 0 x ? ? ? ? ? 0 0 x 0 0 x x x 0 0 x x x x x x x 0 x x x x x 0 x 0 x x 0 x x x 0 x x 0 x x 0 x 0 0 x 0 x 0 x 0 x 0 x x x x x x x 0 x x x 0 x x x 0 x x x x 0 x x x x x x x x x x x x x x 0 x 0 x x x ? x x x ? ? ? ? 0 ? 0 ? 0 ? x x ? x x 0 x 0 ? x x 0 x ? 0 0 ? 0 x x x x x x 0 x x x x 0 x x x 0 x 0 x x x x x x x x x x x x x x x x 0 0 x x x x x x x x x x 0 x x x ? ? x x 0 x ? ? x 0 x ? 0 x x x x 0 x x x x x x 0 x 0 x x x x ? x x ? x x x x ? x x x x x x ? 0 x x x x x x x ? x x x x 0 ? x x x x x x x ? x 0 x x 0 0 x x 0 x x 0 x x ? x x x x 0 x x 0 x 0 0 x x x x x 0 x ? x x x x x 0 ? 0 0 ? ? ? ? ? 0 ? x 0 x x 0 x 0 0 x x 0 x x 0 x x 0 x ? x x x 0 x ? 0 ? ? x 0 ? x 0 ? x 0 x x 0 x ? ? 0 ? 0 0 0 x 0 x 0 ? x ? ? ? ? ? ? ? ? ? 0 ? ? x ? 0 x ? 0 x ? ? x x x x x x x x x x 0 0 0 0 0 0 x ? ? ? 0 0 x 0 ? ? 0 x 0 x x x x x x ? x x x x x x 0 0 0 x x x x x x x 1 x x x 1 0 x ? x 0 x x 0 x 0 x x ? x 0 x ? x 0 ? x x x x 0 x x 0 x x 0 x x x 0 0 x x 0 x x x x 0 x 0 ? 0 x 0 1 x x x x x x x 0 0 x x 0 ? ? 0 x x x x 0 x 0 x x 0 ? 0 0 0 0 0 0 x x x x 0 0 0 x x x x x 0 0 x x 0 x 0 0 x x x x ? ? x x x 0 x x 0 x x x x x 0 ? x x x x x x x 0 x x x x 0 x x x x x ? x x x 0 0 x x ? 0 ? 0 x 0 ? 0 0 x ? 0 ? 0 x 0 ? 0 0 x x 0 x x 0 ? 0 0 0 x x x 0 x 0 ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 x 0 x 0 0 0 ? x x ? ? 0 ? ? 0 0 x 0 ? 0 0 x x 0 x x x x x 0 0 x ? ? ? ? ? ? ? ? ? ? ? x x x ? ? 0 ? ? x x ? 0 ? 0 0 0 0 ? x x ? ? ? ? x 0 x x x x x 0 x 1 x x x x x x ? x ? x x 0 0 0 0 ? x 0 x ? ? ? ? 0 0 ? ? ? ? ? ? ? ? 0 x x x ? ? 0 0 ? 0 x x x 0 0 x x x 0 x x 0 ? x 0 0 ? 0 1 0 x 0 ? 0 ? ? ? ? ? 0 0 x ? x 0 x ? ? x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x x x x x 0 x x ? 0 0 x 0 0 x 0 0 x 0 x 0 0 0 0 0 x x x 0 x 0 0 x 0 0 0 0 0 ? ? ? ? ? x 0 ? 0 ? ? x x x x x x 0 0 x x x x x x x x x 0 x x 0 x x x x x 0 0 0 x x x 0 x 0 x x x x x x x 0 0 x x x 0 x 0 x x x x 0 x 0 x x 0 x 0 0 x x 0 x 0 0 x 0 x 0 0 x 0 x 0 0 x 0 x x 0 ? x x ? 0 ? 0 0 0 0 0 0 x 0 0 0 0 0 0 x x x x x 0 x x 0 x 0 x x 0 x 0 x x x x 0 0 ? x ? ? 1 0 0 0 x x x x x x x x x x x 0 0 x x 0 x x x ? ? 0 0 0 x x x x x x x x x x x x x 0 x x 0 0 0 ? x x 0 0 x 0 0 x 0 x 0 0 0 x x 0 x x 0 ? ? x x 0 x 0 x 0 ? ? x ? 0 x x x ? 0 x x x x x x x 0 ? ? x ? ? 0 x ? 0 0 0 ? ? x x x x 0 x 0 ? x 0 ? ? x x ? 0 x x 0 ? ? x x x x x 0 x ? ? 0 ? 0 ? 0 0 x x x x x x 0 0 x x x 0 0 x x x x 0 0 0 x x x x x x 0 x x x x x 0 ? x x ? 0 x ? 0 ? ? x x ? x 0 ? ? ? 1 x 0 ? x ? ? ? 0 ? 0 x 0 x ? x ? 0 ? 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? x ? ? ? 0 ? ? 0 0 ? ? ? x 0 0 0 0 0 x 0 x x ? 0 x x ? 0 x x ? 0 x x x 0 x x x 0 x x 0 x x x x ? x 0 x 0 0 ? ? x ? x x 0 ? x ? x x 0 ? x ? x x 0 ? x ? x x 0 ? ? x ? x x 0 ? x ? x x 0 x x x 0 0 x x 0 0 0 x
... Dados truncados
0 - Bloco Provavelmente Seguro
? - Bloco Desconhecido
x - Bloco Potencialmente Malicioso

Famílias semelhantes

  • Kryptik.AFPA

Arquivos modificados

Arquivo Atributos
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.1.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.2.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data

Modificações no Registro

Chave::Valor Dados Nome da API
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\cmd.exe ꑵԾ佦ǝ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 椓Ճ佦ǝ RegNtPreCreateKey

Utilização da API do Windows

Categoria API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcAcceptConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreatePort
  • ntdll.dll!NtAlpcOpenSenderProcess
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
Mostrar mais
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtDeleteValueKey
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFindAtom
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenMutant
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtUnsubscribeWnfStateChange
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Process Terminate
  • TerminateProcess