Threat Database Trojans Trojan.Kryptik.BGU

Trojan.Kryptik.BGU

Trojan.Kryptik.BGU is a detection name used to identify a Trojan horse threat. Like most threats in the "Kryptik" family, this detection name is typically applied to malicious files that have been obfuscated or packed in a way that disguises their true purpose and makes them harder for security tools to analyze. Because specific technical details about this exact variant are not confirmed, the information below reflects the typical behavior of Trojan threats in this category, and should be understood as a general guide rather than a confirmed description of this particular file.

What This Threat Does

Trojans like Trojan.Kryptik.BGU are designed to appear harmless while secretly performing malicious actions in the background. Typical behavior for threats in this category includes allowing a remote attacker to gain unauthorized access to an infected computer, downloading and installing additional malicious software, collecting sensitive information such as login credentials or system data, and modifying system settings without the user's consent. Because the "Kryptik" naming convention is generally associated with obfuscated or encrypted malware code, threats detected under this name are often difficult for traditional scanning methods to fully analyze until they are decrypted or executed in a controlled environment.

How It Usually Gets Onto Computers

Trojans in this category commonly spread through methods typical of this type of malware, such as:

  • Malicious email attachments or links disguised as invoices, receipts, or other legitimate documents
  • Bundled downloads from untrustworthy or pirated software sources
  • Fake software updates or cracked application installers
  • Compromised or malicious websites that trigger automatic downloads
  • Infected external drives or shared network resources

Once a user opens the infected file or enables content such as macros, the Trojan can silently install itself and begin running in the background.

Risks for the User

Infections from Trojans similar to Trojan.Kryptik.BGU can expose users to a range of serious risks, including:

  • Theft of personal, financial, or login information
  • Unauthorized remote access to the infected device
  • Installation of additional malware, such as ransomware or spyware
  • Reduced system performance due to background malicious processes
  • Compromised online accounts and potential identity theft

Signs of Infection

Because Trojans are built to operate stealthily, many infections show few or no obvious symptoms. However, users may notice warning signs typical of this threat category, such as:

  • Unexplained slowdowns or high CPU/memory usage
  • Unexpected pop-ups, crashes, or error messages
  • New or unfamiliar programs appearing on the system
  • Security software being disabled without user action
  • Unusual network activity or data usage

How to Stay Protected

To reduce the risk of infection from threats like Trojan.Kryptik.BGU, users should follow standard cybersecurity best practices:

  • Avoid opening email attachments or clicking links from unknown or unexpected senders
  • Download software only from official or verified sources
  • Keep the operating system and all installed applications updated with the latest security patches
  • Use reputable security software and keep it updated to detect and block emerging threats
  • Regularly back up important files to protect against data loss
  • Be cautious of unsolicited pop-ups, fake update prompts, or too-good-to-be-true offers online

Staying alert and practicing safe browsing habits remains one of the most effective ways to prevent Trojan infections and protect personal data from being compromised.

Analysis Report

General information

Family Name: Trojan.Kryptik.BGU
Signature status: No Signature

Known Samples

MD5: b9b8c3dc5ae1f1b6a9b6eb1e7f86816e
SHA1: 2e49178325b62a8ee9ee8135861b0af505a842ba
SHA256: BC237A2248556CEFBD333042EC4071086A4B67C0221AD9E0A2801C71455BE151
File Size: 1.04 MB, 1035871 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Flisloash Software
File Description Flisloash
File Version 9.9.5.5077
Internal Name flisloash.exe
Legal Copyright Copyright © 2019 Flisloash Software. All rights reserved.
Original Filename flisloash.exe
Product Name Flisloash
Product Version 9.9.5.5077

File Traits

  • ntdll
  • x64

Block Information

Total Blocks: 1,093
Potentially Malicious Blocks: 230
Whitelisted Blocks: 703
Unknown Blocks: 160

Visual Map

? x x 0 x 0 0 0 0 0 0 ? ? ? x 0 0 ? x ? 0 0 ? ? x ? x x x 0 0 x 0 ? 0 ? 0 x 0 x ? ? x x x 0 0 ? ? x ? 0 ? x x 0 x 0 ? ? 0 ? ? ? x x 0 x 0 x ? ? ? ? ? ? x ? ? x ? ? ? 0 ? ? ? ? x 0 x x 0 x 0 x 0 x x 0 0 x x 0 0 x ? x 0 0 0 x x 0 x x 0 0 0 0 0 x 0 ? ? 0 0 0 x x x 0 x 0 0 0 x 0 x ? x 0 0 x 0 x x 0 x ? 0 x 0 x 0 x x 0 x 0 0 0 0 0 x x x 0 0 0 0 0 0 0 x x 0 x x x x 0 x ? x x ? 0 0 x x x x ? x 0 0 0 0 0 x 0 0 0 x x 0 ? x x ? 0 ? ? x x 0 ? 0 0 0 x x x x x 0 x x 0 ? 0 0 ? x x 0 x ? ? x 0 x ? x x 0 0 0 ? x 0 x x x x x ? 0 0 0 ? 0 x x ? 0 x 0 0 ? x ? 0 ? ? 0 x 0 ? 0 ? x 0 0 x ? ? x x ? 0 x 0 ? x x ? 0 0 ? ? 0 x 0 x 0 x x x 0 0 ? x x 0 x 0 x 0 0 ? x 0 0 ? ? 0 ? x 0 ? 0 0 0 ? x ? ? x 0 0 x x ? x 0 ? ? 0 x x x 0 0 0 0 x x x 0 x x ? 0 0 x 0 0 0 ? 0 ? ? 0 0 0 x x ? 0 0 x 0 0 x ? 0 0 x x ? ? ? 0 0 0 0 x 0 0 0 x ? 0 0 0 0 x 0 ? 0 ? x x 0 x x ? 0 0 0 ? ? 0 x ? ? 0 0 0 x ? 0 0 x x x 0 0 0 ? 0 x 0 ? ? ? x 0 ? x ? x 0 x ? x 0 x x ? x x x ? x ? ? x ? ? 0 0 0 0 0 0 x 0 0 0 0 x 0 x x ? ? x x ? ? ? ? ? ? x ? ? ? ? x x 0 0 x 0 x 0 x x 0 0 x 0 0 0 x x x 0 x 0 0 0 x 0 ? x x x x 0 ? x 0 x 0 0 0 0 0 0 0 x 0 0 ? x x 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 x ? x x 0 x 0 x 0 0 x ? 0 0 0 0 x 0 0 x 0 0 0 ? ? x ? ? 0 x ? ? x x 0 0 0 ? 0 ? x 0 ? x ? x 0 0 x x 0 ? 0 x x x 0 x 0 0 x ? x 0 0 0 0 x 0 0 0 ? ? 0 ? x x ? ? 0 0 ? 0 ? 0 ? ? ? x 0 ? 0 0 x x ? 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 2 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? x 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQuerySecurityAttributesToken
Show More
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation