Threat Database Trojans Trojan.Kryptik.BGK

Trojan.Kryptik.BGK

Trojan.Kryptik.BGK is a detection name used to identify a malicious program classified under the broad "Kryptik" family of Trojans. Threats in this family are typically packed or obfuscated to make them harder for security tools to analyze and to disguise their true purpose. As with most Trojans, Trojan.Kryptik.BGK does not announce itself to the user; instead, it tries to operate quietly in the background while carrying out actions that can compromise the security, privacy, or stability of an infected device.

What Trojan.Kryptik.BGK Does

While the exact capabilities of any specific Kryptik variant can vary, threats detected under this family name typically behave like generic Trojans. This commonly includes attempting to download or install additional malicious components, modifying system settings to maintain a foothold on the infected machine, and attempting to evade detection by security software through code obfuscation or packing techniques. Some Kryptik-type Trojans are designed to collect information from the infected system, while others may act as a delivery mechanism for further malware, such as ransomware, spyware, or other unwanted programs. Because the "Kryptik" label mainly refers to the obfuscation technique used rather than a single fixed behavior, the precise actions of this Trojan can differ from one infected system to another.

How It Usually Spreads

Trojans like Trojan.Kryptik.BGK typically find their way onto computers through common infection vectors. These often include malicious email attachments or links, bundled downloads from untrustworthy or pirated software sources, fake software updates, cracked applications, and deceptive advertisements that prompt users to download or run a file. In many cases, the user is tricked into manually executing the malicious file because it is disguised as something legitimate, such as a document, installer, or media file.

Risks for the User

Because Trojans in this category are built to operate covertly and can serve multiple malicious purposes, an infected computer may be exposed to several risks. These typically include theft of personal or financial information, unauthorized remote access to the system, installation of additional malware, degraded system performance, and compromised online privacy. In some cases, an infected machine may be used as part of a larger malicious operation without the owner's knowledge.

Signs of Infection

Trojans are designed to be stealthy, so visible symptoms are not always present. However, typical warning signs associated with this type of threat can include unexpected slowdowns, unfamiliar processes running in the background, increased network activity without a clear cause, security software being disabled or malfunctioning, new or unfamiliar programs appearing on the system, and unusual pop-ups or browser behavior.

How to Stay Protected

To reduce the risk of encountering threats like Trojan.Kryptik.BGK, users should avoid downloading software from unofficial or untrusted sources, be cautious with email attachments and links from unknown senders, keep the operating system and installed applications up to date, and avoid using cracked or pirated software. Regularly backing up important data, using a reputable and updated security solution, and staying alert to unusual system behavior can also help detect and prevent infections before they cause significant harm. If a Trojan infection is suspected, running a full system scan with updated security software is typically recommended to identify and remove the threat.

Analysis Report

General information

Family Name: Trojan.Kryptik.BGK
Signature status: No Signature

Known Samples

MD5: 7dd653ea6bc5abbbeaaa1289e80d24f6
SHA1: ad36ca517b78a384f5aea4e6f4aba29875bc1f43
SHA256: BF743DE62F47A8B09DAF4F7E42F28E3B2ADCB5E73793682C12ED91B6864D1BEE
File Size: 1.02 MB, 1017856 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Befalora, Corp.
File Description Befalora
File Version 10.1.8.25162
Internal Name befalora.exe
Legal Copyright Copyright © 2016 Befalora, Corp.. All rights reserved.
Original Filename befalora.exe
Product Name Befalora
Product Version 10.1.8.25162

File Traits

  • ntdll
  • x64

Block Information

Total Blocks: 897
Potentially Malicious Blocks: 145
Whitelisted Blocks: 610
Unknown Blocks: 142

Visual Map

x x 0 0 ? ? ? x ? ? x x 0 x 0 ? 0 x ? 0 x 0 0 0 x x 0 0 0 0 0 ? ? ? ? ? ? ? x ? ? ? ? x 0 ? 0 ? 0 ? ? 0 x 0 ? 0 ? x ? ? ? ? x 0 ? ? x x ? 0 0 0 0 ? ? ? ? ? 0 x x x x 0 x 0 ? 0 ? x 0 x 0 x x ? 0 0 ? x x x 0 0 0 x 0 x x x x 0 x x x 0 x x ? x 0 x 0 x 0 0 x ? 0 0 0 x 0 x 0 0 x 0 x 0 0 0 0 ? ? x ? ? x 0 ? 0 x ? 0 ? ? ? ? x x x 0 x 0 0 0 x x 0 0 0 0 0 0 0 0 0 ? x ? 0 0 x 0 0 0 0 0 x x 0 0 x 0 0 0 x 0 0 0 x x 0 0 0 x 0 0 0 x x ? 0 0 0 x x ? 0 ? ? 0 ? ? x 0 ? ? x x 0 x ? 0 x ? 0 0 x 0 ? 0 ? x x 0 0 0 x ? 0 0 0 0 0 0 x ? ? x ? x 0 0 0 0 ? 0 ? x 0 ? 0 ? 0 ? 0 ? 0 x ? 0 x 0 0 0 x 0 0 0 x ? 0 ? 0 0 0 ? ? 0 ? x 0 0 0 x 0 ? x x ? 0 x ? 0 0 x 0 x x ? x ? ? x ? 0 ? 0 x x ? 0 ? x 0 x 0 ? ? 0 ? 0 ? 0 x 0 0 x 0 x x x 0 0 x 0 ? ? ? ? ? 0 ? 0 ? 0 0 0 ? ? ? ? 0 ? ? ? ? ? x x x x 0 ? ? 0 0 x ? x 0 x x 0 ? x x ? x ? 0 ? 0 x 0 x 0 ? ? ? 0 ? x ? ? ? ? ? x 0 0 0 x x x 0 x 0 0 x 0 x x x x x 0 x 0 0 x x x x ? 0 x x 0 x x ? ? ? 0 ? ? ? ? ? 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 2 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? x x ? 0 x x 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Trojan.Kryptik.Gen.KPF

Files Modified

File Attributes
c:\program files (x86)\tableplus\schmieuviutch.txt Generic Write,Read Attributes
c:\programdata\mantissas\swiohnist.dat Generic Write,Read Attributes

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtWriteFile
  • UNKNOWN
User Data Access
  • GetComputerName