Threat Database Trojans Trojan.Kraddare.EC

Trojan.Kraddare.EC

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 22,505
Threat Level: 80 % (High)
Infected Computers: 122
First Seen: July 14, 2021
Last Seen: October 29, 2025
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Kraddare.EC
Signature status: No Signature

Known Samples

MD5: 013305b5ea47dfe9d16994e84e9097da
SHA1: 053c90479ed736ed88caf403a1c271ea2ae62cf3
SHA256: BD912B30B3BCF57E95F66B08080F337B15DA87A1362EB95A163E268F43D9EB7C
File Size: 610.30 KB, 610304 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Dynamix, Inc.
File Description Cool Pool.
File Version 1.0.0.27 October 13, 1999
Internal Name Cool Pool
Legal Copyright Copyright © Dynamix, Inc. 1999
Now T H I S Is Fun! 3D Ultra
Original Filename coolpool.exe

File Traits

  • HighEntropy
  • x86

Block Information

Total Blocks: 987
Potentially Malicious Blocks: 623
Whitelisted Blocks: 364
Unknown Blocks: 0

Visual Map

x x x x x 0 x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x 0 x x x 0 x x x x x x x x 0 x x x 0 x x x x x x 0 x x x x x x 0 0 x x 0 x x x x x x x x 1 x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x 0 0 x 0 0 x x x x x x x x x x x x x x x 0 x x x x x 0 0 x x x x 0 x x x x x 0 x x x x x 0 0 0 x x x x x x x 0 x x x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x 0 x x x x x x x x x x 0 0 x 0 x x x x x x x x x x x x x x x x x 0 x x 0 x x x x x 0 x x 0 x x x 0 x x x x 0 0 x x 0 x x x x x x x x x x x x x x 0 x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x 0 x x x x x x x 0 x x 0 x x x x x x x x x x x x 0 x x x 0 0 x x x 0 0 x x x 0 x x x x x x x x x x x x x x x x x 0 0 0 0 0 0 x x x x 0 x x x x x x x x x x x x x x x 0 x x x x x x x x 0 x x x x x x 0 x x x x x x x x x x x x x 0 x 0 0 x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Kraddare.EC

Registry Modifications

Key::Value Data API Name
HKCU\software\sierra on-line\3d ultra cool pool\prefs\network::game_guid E6666EA0-DBB2-11d2-A771-006097C3E986 RegNtPreCreateKey
HKCU\software\sierra on-line\3d ultra cool pool\prefs\network::meta_server1 TCP:coolpool.west.won.net:6003 RegNtPreCreateKey
HKCU\software\sierra on-line\3d ultra cool pool\prefs\network::meta_server2 TCP:coolpool.east.won.net:6003 RegNtPreCreateKey
HKCU\software\sierra on-line\3d ultra cool pool\prefs\network::meta_server3 UDP:cp1m1.masters.dynamix.com:35000 RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\directdraw\mostrecentapplication::name 053c90479ed736ed88caf403a1c271ea2ae62cf3_0000610304 RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\directdraw\mostrecentapplication::id 㠕 RegNtPreCreateKey
HKCU\software\microsoft\windows nt\currentversion\appcompatflags\layers::c:\users\user\downloads\053c90479ed736ed88caf403a1c271ea2ae62cf3_0000610304 DWM8And16BitMitigation RegNtPreCreateKey

Trending

Most Viewed

Loading...