Threat Database Trojans Trojan.Krypt.CLB

Trojan.Krypt.CLB

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 11,621
Threat Level: 80 % (High)
Infected Computers: 4,324
First Seen: February 13, 2023
Last Seen: April 21, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Krypt.CLB
Signature status: No Signature

Known Samples

MD5: 273b9ceed37515b5935474d22ffae366
SHA1: 6d65c698dff40d28ce4a8929b3afb30c1392e0b0
File Size: 3.00 MB, 2996487 bytes
MD5: 2767f2b3ebd19c87079daf3503127829
SHA1: 735179caa65503345fc8869266c24a7c6a9fac37
File Size: 3.43 MB, 3425199 bytes
MD5: abd72969760a8b6062d0ca3cacf0c938
SHA1: f213ac41e6fa7a27b937d08a1ecfd696eeae7004
SHA256: 7C718EB24F7172D5FB8C8E3F1DE0E10DAE5F33B6853AECBC8754507EC35F13BF
File Size: 3.16 MB, 3162109 bytes
MD5: 52bbb433634eae312f85421195b62847
SHA1: e29cbcdbf44ec28be42c9b1eac17f0992c44ff3e
SHA256: 14DDB3BD607A56E6B80128EAF72020404D7C5728A859AC98382E77E49BDDAA14
File Size: 3.35 MB, 3345491 bytes
MD5: a5846c99a521066c7e524823d1003f0b
SHA1: 977cf804d738b2c967af22395938361dac658ca5
SHA256: 642EACA79694B9CC154DFA6DEF47B8EC9178A3E6BC86FFEA2FCE21DB988A1958
File Size: 4.60 MB, 4599680 bytes
Show More
MD5: 06d1d3fd6cb29a6e21357f93161ccf66
SHA1: 90d2e4f0712b39c73cac777d35232495df3582e3
SHA256: 6EA46B4AC8F8E1776036E4BF380CF271A4BFA160109D45D06ADCF6D6E13AC29C
File Size: 4.61 MB, 4607997 bytes
MD5: 7c30e730e46c2e56256b39ce728cee37
SHA1: f8cfb6156e36728de7f0c737537087f92eddee37
SHA256: 8E65C54E32A786B996C2B70DB26EFF2A31EE2A00D8380473DA9B9C1F50857767
File Size: 3.27 MB, 3268608 bytes
MD5: c31d25691f2c6496eb20f7e193d5f783
SHA1: d6bf95065ff96060da556c5a198f76cba6ba3df9
SHA256: 5F82900C2D0EA056BA324E170D990E5B71FEC467E333107F6A34B106EF9BF385
File Size: 4.50 MB, 4497406 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • ACE Lab
  • Puran Software
File Description
  • CCngBackup
  • Disk Check
  • Disk Files
  • DYngBackup
  • S.M.A.R.T. Vision Service Application
File Version
  • 1.2.7.20
  • 1.2.7.17
  • 1.2.7.12
  • 1.2.6.18
  • 1.2.0.0
  • 1.0.5.29
  • 1.0.4.14
  • 1.0.0.62
Internal Name
  • CCngBackup
  • Disk Check.exe
  • Disk Files.exe
  • DYngBackup
  • S.M.A.R.T. Vision Service
Legal Copyright (c) Puran Software. All rights reserved.
Original Filename
  • CCngBackup
  • Disk Check.exe
  • Disk Files.exe
  • DYngBackup
  • S.M.A.R.T. Vision Service
Product Name
  • CCngBackup
  • Disk Check
  • Disk Files
  • DYngBackup
  • S.M.A.R.T. Vision Service
Product Version
  • 1.2.7.20
  • 1.2.7.17
  • 1.2.7.12
  • 1.2.6.18
  • 1.2.0.0
  • 1.0.5.29
  • 1.0.4.14
  • 1.0.0.62

File Traits

  • 2+ executable sections
  • HighEntropy
  • VirtualQueryEx
  • x86

Block Information

Total Blocks: 1,736
Potentially Malicious Blocks: 56
Whitelisted Blocks: 1,094
Unknown Blocks: 586

Visual Map

? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 ? ? x ? x ? ? x x ? ? ? 0 0 x ? ? ? x x 0 0 0 0 ? 0 ? 0 ? ? ? 0 0 0 0 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? 0 0 ? 0 0 ? ? 0 ? ? ? ? 0 ? ? x ? ? ? x 0 ? ? x 0 ? ? x ? ? 0 0 0 ? ? ? x ? ? ? ? ? ? 0 0 ? 0 ? ? ? ? ? ? ? x 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? 0 0 ? x ? 0 x ? ? x ? ? ? 0 0 0 0 ? ? ? ? 0 ? ? 0 ? 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? ? ? 0 ? ? 0 ? ? ? ? 0 ? x x ? 0 0 0 0 ? ? ? 0 ? ? ? 0 ? ? ? ? ? 0 0 0 0 ? ? 0 x 0 ? ? 0 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? x 0 ? 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 0 ? 0 ? 0 x ? ? ? x ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? 0 ? x 0 0 0 0 ? ? ? ? ? ? x ? 0 0 ? ? ? ? ? ? ? ? ? ? ? x ? ? x ? ? ? ? ? ? x 0 0 0 0 ? ? ? 0 0 ? 0 ? 0 0 ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? 0 ? 0 ? ? ? ? ? ? x x ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? x ? ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 0 0 ? 0 ? ? ? ? ? ? ? ? x ? ? x ? ? 0 x 0 ? 0 ? 0 ? ? ? 0 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 0 ? ? ? ? x 0 0 ? ? ? ? x ? ? ? 0 0 ? x 0 0 0 ? ? ? ? 0 ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? x x ? 0 0 ? ? x ? x ? ? 0 ? ? ? ? ? ? ? x x ? ? ? ? ? ? ? ? 0 0 ? 0 0 ? ? 0 ? ? 0 0 0 0 ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? x ? ? ? 0 0 ? ? ? 0 0 ? x ? ? ? ? x ? ? ? 0 x ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? 0 x ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? 0 0 0 0 ? ? 0 ? 0 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? x 0 ? ? 0 x ? ? 0 0 0 ? ? ? ? ? ? ? ? 0 ? 0 0 0 0 ? 0 0 ? ? ? ? ? x ? 0 0 ? 0 ? ? ? ? ? 0 ? 0 0 0 0 ? ? ? 0 ? 0 ? 0 ? ? x 0 ? ? ? ? ? 0 ? 0 ? 0 ? ? 0 ? ? 0 0 ? ? ? ? x ? 0 0 0 ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Network Winsock
  • send

Trending

Most Viewed

Loading...