Threat Database Trojans Trojan.Kryptik.CBBN

Trojan.Kryptik.CBBN

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.Kryptik.CBBN
Signature status: No Signature

Known Samples

MD5: 66828b61fb93bb191dc84d04d2ba83a4
SHA1: d085fe898ae542d95b392d59611319aa5f09a1bb
SHA256: 911B5A883C32ADA0B9352261252293AD5ECB1B9E339B64A45C355EA944CFF5EC
File Size: 1.42 MB, 1416684 bytes
MD5: b5a19eeb83183582d55c9ad27f940b6d
SHA1: 38fe8c66a692353eb9c8ddabddf381ebc952d0d8
SHA256: 37CE97430861BA9F13EC25516AE4FDDE0E7962A465DC72E42A8CEA3B224B8547
File Size: 980.48 KB, 980480 bytes
MD5: b365242055693992669d89e34d445b40
SHA1: 7724d2e8a4f108483df573f31f4d17ad664a8691
SHA256: 51184DD76E0240D08A77481B3BA4A09A9FE0DDAB07218AA65850E203353C4A45
File Size: 4.26 MB, 4263936 bytes
MD5: 177982616a080c1997207db378498044
SHA1: ceefe73f62044e807234983ddff5cfc7a979d60f
SHA256: A45C5A38D6E6B6C458B93FAAE91B637717C1A6831A9CC54842E96D43B322E30A
File Size: 1.40 MB, 1399378 bytes
MD5: e730829e44bf1e02e685d0d27f8fb9f9
SHA1: 62eaf2c7d771dcf6b92767edb8d22c774ecb1c6b
SHA256: 50C626E3F37B9E9253A27411D1FEFB798A1F2005D7774C540923B9BC2E2F632C
File Size: 6.44 MB, 6439424 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have resources
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
Show More
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
File Description
  • instally-scaffold
  • ZeroBot - Updater
File Version
  • 0.1.0
  • 0.0.0
Product Name
  • instally-scaffold
  • ZeroBot
Product Version
  • 0.1.0
  • 0.0.0

Digital Signatures

Signer Root Status
Adobe Inc. DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Hash Mismatch

File Traits

  • big overlay
  • HighEntropy
  • imgui
  • Installer Version
  • No Version Info
  • ntdll
  • VirtualQueryEx
  • x86

Block Information

Total Blocks: 14,579
Potentially Malicious Blocks: 341
Whitelisted Blocks: 7,609
Unknown Blocks: 6,629

Visual Map

? ? 0 ? ? ? ? 0 ? 0 ? ? ? ? ? ? 0 ? 0 ? ? ? ? 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? ? ? ? ? ? ? 0 0 0 0 0 ? 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 ? 0 ? ? 0 0 ? ? ? ? 0 ? 0 ? 0 ? 0 0 0 ? ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 ? ? ? ? ? ? ? ? ? 0 x x ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? ? 0 ? 0 0 ? 0 ? 0 0 ? 0 ? 0 ? ? ? 0 ? 0 0 0 0 ? ? ? 0 0 ? 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 0 ? ? ? 0 ? 0 ? ? 0 0 ? ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x ? 0 0 ? 0 0 ? 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 ? 0 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? 0 ? ? ? ? 0 ? ? 0 ? 0 ? ? ? ? ? ? 0 ? 0 0 0 ? ? 0 ? ? 0 x 0 0 0 0 0 0 0 0 0 ? 0 0 ? ? 0 ? 0 0 0 x 0 0 ? 0 0 0 ? 0 ? ? 0 ? 0 ? 0 0 0 ? ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? ? ? 0 0 ? 0 ? 0 0 ? 0 0 0 0 ? 0 ? ? 0 ? 0 0 ? ? 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 ? 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? 0 ? ? 0 0 0 0 0 0 ? 0 ? ? 0 0 0 ? 0 0 0 0 0 0 0 0 ? 0 ? 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? x ? ? ? 0 x 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x 0 0 x 0 x 0 0 x 0 x 0 0 0 0 0 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 ? 0 0 0 0 0 0 ? 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? ? ? ? ? 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 0 1 0 0 0 0 0 ? 0 0 0 ? 0 0 0 0 0 0 ? 0 ? ? ? ? 0 0 ? ? ? ? 0 ? ? 0 ? ? ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? ? 0 0 0 ? 0 ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? 0 0 ? ? ? ? ? 0 ? 0 ? 0 0 0 0 ? 0 0 ? 0 0 0 0 ? ? 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? ? 0 0 ? 0 ? 0 0 ? ? 0 ? ? ? 0 ? 0 0 0 ? 0 ? 0 ? 0 0 ? 0 0 ? 0 0 ? 0 ? ? ? ? ? ? 0 0 ? 0 ? ? ? 0 ? ? 0 ? ? 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? 0 0 ? 0 0 x ? ? ? ? ? 0 ? ? ? 0 0 ? 0 ? ? ? ? 0 ? 0 0 ? ? ? ? ? ? 0 ? ? 0 0 0 0 x 0 0 0 x 0 0 x 0 0 0 0 0 0 0 ? 0 0 x ? ? ? 0 0 x ? ? ? 0 0 ? 0 0 0 0 0 0 0 0 x 0 0 ? ? ? ? ? ? 0 ? ? 0 ? ? 0 0 ? ? 0 ? 0 0 ? 0 0 ? ? ? 0 0 0 0 0 ? 0 0 0 ? 0 0 0 ? 0 0 ? 0 0 0 ? 0 0 ? 0 0 0 ? 0 ? 0 ? 0 0 ? 0 0 ? 0 ? 0 0 ? 0 ? 0 ? 0 ? ? 0 ? 0 ? 0 ? ? 0 ? ? 0 0 ? 0 ? ? ? ? 0 ? ? 0 x ? ? ? ? 0 ? ? ? ? 0 0 ? 0 ? 0 ? 0 ? 0 0 0 ? 0 0 0 ? ? ? ? ? ? ? ? 0 ? 0 ? 0 ? ? ? ? ? ? 0 ? ? ? ? 0 ? 0 0 0 0 0 0 0 0 ? 0 ? ? ? ? ? 0 0 0 0 ? 0 ? ? 0 0 ? ? ? 0 ? ? ? ? 0 0 x ? 0 ? 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? ? ? 0 ? ? ? 0 0 0 ? ? ? 0 ? ? 0 0 ? ? 0 ? ? ? 0 0 ? 0 0 0 0 ? ? 0 x 0 0 0 ? 0 0 ? 0 ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? 0 0 0 ? 0 0 0 0 0 ? 0 ? 0 ? 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 ? 0 ? 0 ? ? ? ? ? x ? 0 ? ? 0 0 0 ? ? 0 0 ? 0 ? ? 0 0 0 ? ? 0 ? ? ? x ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 ? 0 ? 0 ? 0 ? ? 0 ? 0 ? 0 0 0 ? ? 0 0 ? 0 0 0 ? ? ? ? ? ? ? 0 0 ? 0 ? ? ? 0 ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? 0 0 0 ? 0 0 ? ? 0 0 0 ? 0 0 ? ? 0 0 0 0 ? 0 ? 0 0 0 ? ? 0 ? 0 0 0 ? 0 ? ? 0 0 ? 0 0 ? ? 0 0 0 0 0 ? ? 0 0 ? 0 0 0 0 0 0 0 0 ? ? ? 0 0 x 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? ? 0 0 ? 0 ? 0 ? 0 ? 0 ? ? 0 0 0 ? ? 0 ? ? ? ? ? 0 0 ? 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 ? 0 0 ? 0 0 ? 0 ? 0 0 0 0 0 ? 0 ? 0 0 0 ? 0 0 0 x 0 0 0 0 0 0 ? 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? ? 0 0 0 ? ? ? 0 0 ? 0 ? 0 0 0 ? 0 ? 0 ? ? ? 0 ? 0 0 0 ? ? ? 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? ? 0 0 ? 0 0 0 ? ? ? 0 0 ? 0 0 ? ? ? 0 0 0 0 0 ? 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 0 ? 0 0 ? 0 ? 0 0 ? 0 ? 0 ? 0 ? 0 0 ? ? 0 ? 0 ? 0 0 ? 0 ? 0 ? 0 0 ? ? ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Kryptik.CBBN

Files Modified

File Attributes
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\3acf660917f73e764d4410bf1eaa48f5 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\750f9863dc96151354f5941fd665fa84 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\3acf660917f73e764d4410bf1eaa48f5 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\750f9863dc96151354f5941fd665fa84 Generic Read,Write Data,Write Attributes,Write extended,Append data

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\systemcertificates\ca\certificates\3382517058a0c20228d598ee7501b61256a76442::blob RegNtPreCreateKey
HKCU\software\microsoft\systemcertificates\ca\certificates\31600991ed5fec63d355a5484a6dcc787ead89bc::blob RegNtPreCreateKey

Windows API Usage

Category API
Encryption Used
  • BCryptOpenAlgorithmProvider
User Data Access
  • GetComputerNameEx
  • GetUserObjectInformation
  • OpenClipboard
Anti Debug
  • IsDebuggerPresent
Process Manipulation Evasion
  • ReadProcessMemory

Trending

Most Viewed

Loading...