Threat Database Trojans Trojan.Kryptik.CBBN

Trojan.Kryptik.CBBN

By CagedTech in Trojans

The detection of Trojan.Kryptik.CBBN on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the security and integrity of your computer, and it's essential to understand its nature and take steps to remove it.

What Is Trojan.Kryptik.CBBN?

Trojan.Kryptik.CBBN is a type of Trojan horse malware, which is a broad category of malicious software that disguises itself as legitimate programs or files. The name "Trojan" refers to the way this malware operates, by deceiving users into installing or executing it, often by exploiting vulnerabilities or using social engineering tactics. The specific characteristics and behaviors of Trojan.Kryptik.CBBN are not unique to a known malware family, but its detection suggests a serious security risk.

How Trojan.Kryptik.CBBN Operates

Trojan.Kryptik.CBBN, like other Trojans, is designed to operate stealthily, often without noticeable symptoms. It may use various techniques to evade detection, such as encrypting its communications, hiding in temporary files, or disguising itself as a system process. Once installed, it can potentially allow unauthorized access to your system, steal sensitive information, or install additional malware. The exact mechanisms and goals of Trojan.Kryptik.CBBN are not specified, but its presence is a clear indication of a security breach.

Symptoms of Infection

While Trojan.Kryptik.CBBN may not always exhibit obvious symptoms, some common signs of a Trojan infection include slow system performance, unexpected pop-ups or ads, unfamiliar programs or icons, and unusual network activity. You may also notice that your browser settings have changed, or that your system is behaving erratically. However, some Trojans can remain dormant or hidden, making them difficult to detect without proper security software.

How to Remove Trojan.Kryptik.CBBN

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for a more effective removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. This will help identify and remove all associated malware components.
  3. Uninstall any suspicious programs or applications that you don't recognize or that were installed around the time of the infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or settings changes.
  5. Reboot your system and perform another full scan with your anti-malware tool to ensure that all malware has been removed.

Conclusion

Removing Trojan.Kryptik.CBBN requires a thorough and careful approach to ensure that all associated malware components are eliminated. By following the steps outlined above and maintaining good security practices, such as keeping your operating system and software up to date, using strong antivirus software, and being cautious when clicking on links or downloading files, you can help protect your system from future infections. Remember, the detection of Trojan.Kryptik.CBBN is a serious security alert that demands immediate action to safeguard your digital security and privacy.

Analysis Report

General information

Family Name: Trojan.Kryptik.CBBN
Signature status: No Signature

Known Samples

MD5: 66828b61fb93bb191dc84d04d2ba83a4
SHA1: d085fe898ae542d95b392d59611319aa5f09a1bb
SHA256: 911B5A883C32ADA0B9352261252293AD5ECB1B9E339B64A45C355EA944CFF5EC
File Size: 1.42 MB, 1416684 bytes
MD5: b5a19eeb83183582d55c9ad27f940b6d
SHA1: 38fe8c66a692353eb9c8ddabddf381ebc952d0d8
SHA256: 37CE97430861BA9F13EC25516AE4FDDE0E7962A465DC72E42A8CEA3B224B8547
File Size: 980.48 KB, 980480 bytes
MD5: b365242055693992669d89e34d445b40
SHA1: 7724d2e8a4f108483df573f31f4d17ad664a8691
SHA256: 51184DD76E0240D08A77481B3BA4A09A9FE0DDAB07218AA65850E203353C4A45
File Size: 4.26 MB, 4263936 bytes
MD5: 177982616a080c1997207db378498044
SHA1: ceefe73f62044e807234983ddff5cfc7a979d60f
SHA256: A45C5A38D6E6B6C458B93FAAE91B637717C1A6831A9CC54842E96D43B322E30A
File Size: 1.40 MB, 1399378 bytes
MD5: e730829e44bf1e02e685d0d27f8fb9f9
SHA1: 62eaf2c7d771dcf6b92767edb8d22c774ecb1c6b
SHA256: 50C626E3F37B9E9253A27411D1FEFB798A1F2005D7774C540923B9BC2E2F632C
File Size: 6.44 MB, 6439424 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have resources
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
Show More
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
File Description
  • instally-scaffold
  • ZeroBot - Updater
File Version
  • 0.1.0
  • 0.0.0
Product Name
  • instally-scaffold
  • ZeroBot
Product Version
  • 0.1.0
  • 0.0.0

Digital Signatures

Signer Root Status
Adobe Inc. DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Hash Mismatch

File Traits

  • big overlay
  • HighEntropy
  • imgui
  • Installer Version
  • No Version Info
  • ntdll
  • VirtualQueryEx
  • x86

Block Information

Total Blocks: 14,579
Potentially Malicious Blocks: 341
Whitelisted Blocks: 7,609
Unknown Blocks: 6,629

Visual Map

? ? 0 ? ? ? ? 0 ? 0 ? ? ? ? ? ? 0 ? 0 ? ? ? ? 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? ? ? ? ? ? ? 0 0 0 0 0 ? 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 ? 0 ? ? 0 0 ? ? ? ? 0 ? 0 ? 0 ? 0 0 0 ? ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 ? ? ? ? ? ? ? ? ? 0 x x ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? ? 0 ? 0 0 ? 0 ? 0 0 ? 0 ? 0 ? ? ? 0 ? 0 0 0 0 ? ? ? 0 0 ? 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 0 ? ? ? 0 ? 0 ? ? 0 0 ? ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x ? 0 0 ? 0 0 ? 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 ? 0 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? 0 ? ? ? ? 0 ? ? 0 ? 0 ? ? ? ? ? ? 0 ? 0 0 0 ? ? 0 ? ? 0 x 0 0 0 0 0 0 0 0 0 ? 0 0 ? ? 0 ? 0 0 0 x 0 0 ? 0 0 0 ? 0 ? ? 0 ? 0 ? 0 0 0 ? ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? ? ? 0 0 ? 0 ? 0 0 ? 0 0 0 0 ? 0 ? ? 0 ? 0 0 ? ? 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 ? 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? 0 ? ? 0 0 0 0 0 0 ? 0 ? ? 0 0 0 ? 0 0 0 0 0 0 0 0 ? 0 ? 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? x ? ? ? 0 x 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x 0 0 x 0 x 0 0 x 0 x 0 0 0 0 0 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 ? 0 0 0 0 0 0 ? 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? ? ? ? ? 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 0 1 0 0 0 0 0 ? 0 0 0 ? 0 0 0 0 0 0 ? 0 ? ? ? ? 0 0 ? ? ? ? 0 ? ? 0 ? ? ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? ? 0 0 0 ? 0 ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? 0 0 ? ? ? ? ? 0 ? 0 ? 0 0 0 0 ? 0 0 ? 0 0 0 0 ? ? 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? ? 0 0 ? 0 ? 0 0 ? ? 0 ? ? ? 0 ? 0 0 0 ? 0 ? 0 ? 0 0 ? 0 0 ? 0 0 ? 0 ? ? ? ? ? ? 0 0 ? 0 ? ? ? 0 ? ? 0 ? ? 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? 0 0 ? 0 0 x ? ? ? ? ? 0 ? ? ? 0 0 ? 0 ? ? ? ? 0 ? 0 0 ? ? ? ? ? ? 0 ? ? 0 0 0 0 x 0 0 0 x 0 0 x 0 0 0 0 0 0 0 ? 0 0 x ? ? ? 0 0 x ? ? ? 0 0 ? 0 0 0 0 0 0 0 0 x 0 0 ? ? ? ? ? ? 0 ? ? 0 ? ? 0 0 ? ? 0 ? 0 0 ? 0 0 ? ? ? 0 0 0 0 0 ? 0 0 0 ? 0 0 0 ? 0 0 ? 0 0 0 ? 0 0 ? 0 0 0 ? 0 ? 0 ? 0 0 ? 0 0 ? 0 ? 0 0 ? 0 ? 0 ? 0 ? ? 0 ? 0 ? 0 ? ? 0 ? ? 0 0 ? 0 ? ? ? ? 0 ? ? 0 x ? ? ? ? 0 ? ? ? ? 0 0 ? 0 ? 0 ? 0 ? 0 0 0 ? 0 0 0 ? ? ? ? ? ? ? ? 0 ? 0 ? 0 ? ? ? ? ? ? 0 ? ? ? ? 0 ? 0 0 0 0 0 0 0 0 ? 0 ? ? ? ? ? 0 0 0 0 ? 0 ? ? 0 0 ? ? ? 0 ? ? ? ? 0 0 x ? 0 ? 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? ? ? 0 ? ? ? 0 0 0 ? ? ? 0 ? ? 0 0 ? ? 0 ? ? ? 0 0 ? 0 0 0 0 ? ? 0 x 0 0 0 ? 0 0 ? 0 ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? 0 0 0 ? 0 0 0 0 0 ? 0 ? 0 ? 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 ? 0 ? 0 ? ? ? ? ? x ? 0 ? ? 0 0 0 ? ? 0 0 ? 0 ? ? 0 0 0 ? ? 0 ? ? ? x ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 ? 0 ? 0 ? 0 ? ? 0 ? 0 ? 0 0 0 ? ? 0 0 ? 0 0 0 ? ? ? ? ? ? ? 0 0 ? 0 ? ? ? 0 ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? 0 0 0 ? 0 0 ? ? 0 0 0 ? 0 0 ? ? 0 0 0 0 ? 0 ? 0 0 0 ? ? 0 ? 0 0 0 ? 0 ? ? 0 0 ? 0 0 ? ? 0 0 0 0 0 ? ? 0 0 ? 0 0 0 0 0 0 0 0 ? ? ? 0 0 x 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? ? 0 0 ? 0 ? 0 ? 0 ? 0 ? ? 0 0 0 ? ? 0 ? ? ? ? ? 0 0 ? 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 ? 0 0 ? 0 0 ? 0 ? 0 0 0 0 0 ? 0 ? 0 0 0 ? 0 0 0 x 0 0 0 0 0 0 ? 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? ? 0 0 0 ? ? ? 0 0 ? 0 ? 0 0 0 ? 0 ? 0 ? ? ? 0 ? 0 0 0 ? ? ? 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? ? 0 0 ? 0 0 0 ? ? ? 0 0 ? 0 0 ? ? ? 0 0 0 0 0 ? 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 0 ? 0 0 ? 0 ? 0 0 ? 0 ? 0 ? 0 ? 0 0 ? ? 0 ? 0 ? 0 0 ? 0 ? 0 ? 0 0 ? ? ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Kryptik.CBBN

Files Modified

File Attributes
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\3acf660917f73e764d4410bf1eaa48f5 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\750f9863dc96151354f5941fd665fa84 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\3acf660917f73e764d4410bf1eaa48f5 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\750f9863dc96151354f5941fd665fa84 Generic Read,Write Data,Write Attributes,Write extended,Append data

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\systemcertificates\ca\certificates\3382517058a0c20228d598ee7501b61256a76442::blob 3�QpX��(՘�u�V�dB�;���k��+��R�zP�;bE�V?;r�~�A��0E}�dFG���};ޱ�v�x}��,��W���3r+W����3�M7:�'Խ�0;1�ZA�c퇨f�_O\ý5I�"Z��74���� �0��0��� C�P� RegNtPreCreateKey
HKCU\software\microsoft\systemcertificates\ca\certificates\31600991ed5fec63d355a5484a6dcc787ead89bc::blob 1` ��_�c�U�HJm�x~����~/���J�p[�ߚ���a��P����1p�X_h[0��%�O�;5D�Ԩ�h�Z�Ͻ�'L��{���wI>�x0+�n�٬�k��V_�o��%�m��\ý5I�"Z��74���� �0��0����~T~ RegNtPreCreateKey

Windows API Usage

Category API
Encryption Used
  • BCryptOpenAlgorithmProvider
User Data Access
  • GetComputerNameEx
  • GetUserObjectInformation
  • OpenClipboard
Anti Debug
  • IsDebuggerPresent
Process Manipulation Evasion
  • ReadProcessMemory

Trending

Most Viewed

Loading...