Threat Database Trojans Trojan.Krypt.Gen.GW

Trojan.Krypt.Gen.GW

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.Krypt.Gen.GW
Signature status: No Signature

Known Samples

MD5: ce98e4530615cfee98c7598a5d4bb3f0
SHA1: f14a1344365c835123d6abebc2846371979e6887
SHA256: 43B98CB9944F3551D4C20FCD0D736AF5639304ED197E37F862524223F2096C52
File Size: 2.11 MB, 2113536 bytes
MD5: 45aa6ffd75c9263fe60e3b49e5c473ab
SHA1: 5545b0f8df99c37a29942935f8883100ed1c05d9
SHA256: CDEEDAA08502C28254EC25F0AD2C8754F360078A404204253E347EE942441B85
File Size: 3.96 MB, 3956736 bytes
MD5: 6667f2760c34a88b80c3fc54074fbab1
SHA1: 50d945dd221b305f950601219bf7e4f8b071dee6
SHA256: A585E86A7D7CED52EF757B3963A1AE3D0919F51AE2FA4659B102C2D2AB34A3D9
File Size: 1.95 MB, 1946624 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have security information
  • File has exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments
  • back uper - If we parse the protocol, we can get to the SMS protocol through the mobile SMS protocol!
  • Built with bypass program
  • THX program - Use the 1080p SMTP system, then you can bypass the 1080p system!
Company Name
  • Dibbert Group
  • Haag LLC
  • Kuphal LLC
Company Short Name
  • Dibbert
  • Haag
  • Kuphal
File Description
  • back uper Mouse
  • calculating Slovakia (Slovak Republic) Computer
  • THX program Shoes
File Version
  • 3.0.7157.64
  • 2.6.2763.110
  • 1.11.7198.297
Internal Name
  • back uper (x86)
  • calculating Slovakia (Slovak Republic) (x86)
  • THX program (x86)
Legal Copyright
  • Copyright © 2019-2026 Kuphal LLC. All rights reserved.
  • Copyright © 2022-2026 Haag LLC. All rights reserved.
  • Copyright © 2024-2026 Dibbert Group. All rights reserved.
Legal Trademarks
  • back uper is a trademark of Kuphal LLC
  • Dibbert Group proprietary technology
  • Haag LLC proprietary technology
Original Filename
  • backuper64.exe
  • calculatingSlovakia(SlovakRepublic)707.exe
  • THXprogram890.exe
Product Name
  • back uper
  • calculating Slovakia (Slovak Republic)
  • THX program
Product Short Name
  • backuper
  • calculatingSlovakia(SlovakRepublic)
  • THXprogram
Product Version
  • 2.16.714.476
  • 2.4.6906.891
  • 1.11.7198.297

File Traits

  • HighEntropy
  • x86

Block Information

Total Blocks: 214
Potentially Malicious Blocks: 132
Whitelisted Blocks: 78
Unknown Blocks: 4

Visual Map

x x x x x x x 0 x x x 0 x x x x x x 0 x 0 x x x x x x x x x 0 ? x x x x x x x x x x x x x x x x 0 x x x ? x x x x 0 x x x x x x 0 x ? x 0 x x x x x x x x x x x ? x x x x x x x 0 x x x x x x 0 x 0 0 x x x x x 0 x x 0 x x x x 0 x x x x x x x x x x x x x 0 x x x x x x x x 0 0 x 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 x 0 0 x x x x x x x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

Trending

Most Viewed

Loading...