Threat Database Trojans Trojan.Kryptik.CBBK

Trojan.Kryptik.CBBK

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 9,615
Threat Level: 80 % (High)
Infected Computers: 164
First Seen: June 10, 2024
Last Seen: July 17, 2026
OS(es) Affected: Windows

The detection of Trojan.Kryptik.CBBK indicates that a potentially malicious program has been identified on your system. This type of threat is generally classified as a Trojan, which is a broad category of malware that can perform a variety of harmful actions. It's essential to understand the nature of this threat and take immediate action to remove it and prevent further damage.

What Is Trojan.Kryptik.CBBK?

Trojan.Kryptik.CBBK is a type of malware that can compromise the security and integrity of your computer system. The name "Trojan" refers to the fact that this type of malware often disguises itself as a legitimate program or file, allowing it to evade detection and gain access to your system. Once installed, Trojan.Kryptik.CBBK can potentially cause significant harm, including data theft, system crashes, and unauthorized access to your computer.

How Trojan.Kryptik.CBBK Operates

Trojan.Kryptik.CBBK, like other Trojans, can operate in various ways, depending on its intended purpose. It may be designed to steal sensitive information, such as login credentials, credit card numbers, or personal data. It can also be used to install additional malware, create backdoors for remote access, or disrupt system operations. The specific actions of Trojan.Kryptik.CBBK can vary, but its primary goal is to compromise your system's security and exploit its resources for malicious purposes.

Symptoms of Infection

Identifying the symptoms of a Trojan.Kryptik.CBBK infection can be challenging, as it often masquerades as a legitimate program. However, some common indicators of a potential infection include unusual system behavior, such as slow performance, frequent crashes, or unfamiliar programs running in the background. You may also notice suspicious network activity, unexpected changes to your system settings, or unfamiliar icons on your desktop. If you suspect that your system has been infected with Trojan.Kryptik.CBBK, it's crucial to take immediate action to remove the threat.

How to Remove Trojan.Kryptik.CBBK

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for internet access. This will make it easier to download and install removal tools.
  2. Download and install a reputable anti-malware tool, such as SpyHunter, which can detect and remove Trojan.Kryptik.CBBK. Perform a full scan of your system to identify and eliminate all related malware components.
  3. Uninstall any suspicious programs that may be related to the infection. Be cautious when removing programs, as some may be legitimate or required by your system.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings. This can help remove any malicious extensions or add-ons that may have been installed by the malware.
  5. Reboot your computer and perform another full scan with your anti-malware tool to ensure that all remnants of the malware have been removed.

Conclusion

Removing Trojan.Kryptik.CBBK from your system requires careful attention to detail and a thorough understanding of the malware removal process. By following the steps outlined above and using reputable anti-malware tools, you can effectively eliminate this threat and restore your system's security and integrity. It's essential to remain vigilant and take proactive measures to prevent future infections, such as keeping your operating system and software up to date, using strong antivirus protection, and avoiding suspicious downloads and email attachments.

Analysis Report

General information

Family Name: Trojan.Kryptik.CBBK
Signature status: No Signature

Known Samples

MD5: 757670bf9926ce3c3b4d2eff775ead83
SHA1: 22316d48d32a64e586b92f4a124ce07096751e12
SHA256: DB76FEEC47E47698D06844E9D985BA40C6BD4CE28DBE3898027ECF13A30DE327
File Size: 907.78 KB, 907776 bytes
MD5: ba9019551d6d32ccc094d642d16d77fa
SHA1: 36c2678eb9804cc59289bc16a1e8e2c6a9c2de62
SHA256: 68E9B5BE03E2A1BEB24DA0C1E2628A1252EB81D809CC6ACFDDD5851143D3B96F
File Size: 993.28 KB, 993280 bytes
MD5: ef7caeabe7dc4200144a74c3b46aba7b
SHA1: 8a139a18af04d866e24eaddb3e8b36b83b1999cb
SHA256: 6AB2D96A9667D2358F5C47E8CB1E11E51A4480D7F5D667FDE4FF489044DB4A10
File Size: 886.78 KB, 886784 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have resources
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • dll
  • VirtualQueryEx
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 1,985
Potentially Malicious Blocks: 630
Whitelisted Blocks: 1,346
Unknown Blocks: 9

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x ? ? ? 0 x x x 0 x x 0 x x x x 0 x ? ? ? x x x x x x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 x x x 0 0 x x 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x x x x x x x 0 0 x x 0 x x x x x x x x x x x x x x x x x x x x 0 0 x 0 x 0 x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x 0 0 x x 0 x 0 0 x x 0 x 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 x x 0 0 0 0 x x 0 0 0 0 x 0 0 0 0 x 0 0 0 0 x x 0 0 0 0 x 0 0 0 0 x x 0 0 0 0 x 0 0 0 0 x 0 0 0 0 x x 0 0 0 0 x 0 0 0 0 x 0 0 0 0 x 0 0 0 0 x 0 0 0 0 x 0 0 0 0 x 0 0 0 0 x 0 0 0 0 x 0 0 0 0 x x x x x x x x x x x x x x x x x x x 0 0 0 x 0 0 0 0 x 0 0 0 0 x x x x x x x 0 0 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 2 3 1 1 0 1 1 1 0 0 2 0 0 1 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 0 0 0 0 0 0 0 2 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 2 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 0 0 0 1 1 0 0 0 0 0 0 0 0 ? ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Barys.V
  • Kryptik.CBBK

Files Modified

File Attributes
c:\users\user\appdata\local\temp\zpauxpfivqarosexfplvcrxqtycl.txt Generic Write,Read Attributes
c:\users\user\documentsqsnsmotwklovuffl.txt Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\tutk::faisdomkmuhjgjvtgdm WRcihGtiRKBYnTduVgʞ,/ ,ɰ RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\22316d48d32a64e586b92f4a124ce07096751e12_0000907776.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\36c2678eb9804cc59289bc16a1e8e2c6a9c2de62_0000993280.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\8a139a18af04d866e24eaddb3e8b36b83b1999cb_0000886784.,LiQMAxHB

Trending

Most Viewed

Loading...