Threat Database Trojans Trojan.Kryptik.DTW

Trojan.Kryptik.DTW

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.Kryptik.DTW
Signature status: No Signature

Known Samples

MD5: 01a091446376a18851b9bfe881f1bac7
SHA1: b0990f8df008fa3c54209ee37bbd74de03ad6ada
SHA256: 74958B410E944F042C61E855916547A85FFD499ABDD01AAADC470ADA4A4D9BCA
File Size: 303.62 KB, 303616 bytes
MD5: f92a58cdd2a53e3f62363544a9f6cfc0
SHA1: 13c09be1d5b9d77ea0cf8320e4620dd4d145f61c
SHA256: 0EA8DA9E3914ED8FDABC6513AD9FC7895FE7E74E0E59B9BCE164863493DDAF83
File Size: 296.96 KB, 296960 bytes
MD5: 81de2aaca8f504a6085b8f5e894be729
SHA1: 58c29e6a2963da290ef66f69eb787bb92f9e74e6
SHA256: C848D6431E722EA0C6A118439B2AAEC84FD9AA3912A7D84FB7FD748C77D33F61
File Size: 326.66 KB, 326656 bytes
MD5: d0a1802836714f8569c8d86e5fba9b5e
SHA1: 658f511802a6e394b05871e5b9c07f10d5c95062
SHA256: 872E6BD67233CACB289E6169E374E91B85974BDE4D98B0065D6D7D865811A85D
File Size: 376.83 KB, 376832 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have security information
  • File has exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Comments Professional-grade tool for email automation optimized for cloud-native use.
Company Name
  • Cosmic Security
  • Global Regional International
  • Preferred Knowledge
  • Vault Stream Consultants
Company Short Name
  • Cosmic
  • Global Net
  • Preferred
  • Vault
File Description
  • Comprehensive data management suite for project managers
  • Enterprise-grade business intelligence solution for healthcare organizations
  • Secure report generation application for sales professionals
  • Secure statistical analysis application for IT specialists
File Version
  • 11.8.643.334
  • 4.12.844.237
  • 1.18.1628.75
  • 1.9.4959.205
Internal Name
  • FunDeteAppApp
  • IntArchViewApp
  • SafeEnterpriseSetInternal
  • SupEngiEditProcessor
Legal Copyright
  • Copyright © 2020-2022 Vault Stream Consultants. Protected by copyright law.
  • Copyright © 2021-2020 Global Regional International. All rights reserved.
  • Cosmic Security © 2017-2021. All rights reserved.
  • © 2022-2021 Preferred Knowledge. All rights reserved. Unauthorized use prohibited.
Legal Trademarks Fundamental Detector and the Fundamental Detector logo are trademarks of Preferred Knowledge.
Original Filename
  • app_IntArchView.exe
  • FunDeteApp_util.exe
  • SafEnteTool_main.exe
  • SupEngiEdit_editor.exe
Product Name
  • Fundamental Detector
  • Internet Archive Pro
  • Safe Enterprise Set
  • Super Engineer Pro
Product Short Name
  • FunDeteApp
  • IntArchView
  • SafEnteTool
  • SupEngiEdit
Product Version
  • 11.8.643.334
  • 4.12.844.237
  • 1.18.1628.75
  • 1.9.4959.205

File Traits

  • HighEntropy
  • x86

Block Information

Total Blocks: 139
Potentially Malicious Blocks: 16
Whitelisted Blocks: 114
Unknown Blocks: 9

Visual Map

x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 x x x ? ? x ? x ? ? ? ? x x x x x 0 0 x x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Kryptik.DTW

Trending

Most Viewed

Loading...