Threat Database Trojans Trojan.Kryptik.DVN

Trojan.Kryptik.DVN

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.Kryptik.DVN
Signature status: No Signature

Known Samples

MD5: 47d92b7eb12c39863aeefea5cc4c666b
SHA1: 44651e6fcde7dc9c4b8e2be2a2c660980c7265d2
File Size: 1.34 MB, 1337344 bytes
MD5: 9d63a0ae52c87b5ef474afa57fda5f04
SHA1: 5f86ec8f7da1c2a1d362ef3580ae6e0e81fdf475
File Size: 1.24 MB, 1235968 bytes
MD5: 0666e8c288d97a4ec7db2e3d86cbb9d4
SHA1: 5df5ea974e0d2e0108525ba42e46c2e206474ef9
File Size: 2.07 MB, 2072576 bytes
MD5: 0fc79bce0c4c2592e71b6befde5fa53a
SHA1: 034bd22562f88f89c2d967ed2410f3231834df74
File Size: 2.23 MB, 2230784 bytes
MD5: aeb3ea1557a5927807497a49d972eb10
SHA1: fe517ab64f2193e5ebab4c8f0a969f7449033af8
File Size: 1.32 MB, 1318912 bytes
Show More
MD5: a06b9a9344c62abd2f4e4fe96882b9b6
SHA1: 4a66e6f25772bab73bbb4586787aef5ddb7cd35f
File Size: 970.75 KB, 970752 bytes
MD5: 67b98b2469f7869da378b32615c5eeda
SHA1: ec20d7cf032fc3f803bc3e0a9ee50cbdb65970d7
File Size: 5.31 MB, 5308928 bytes
MD5: fc7d4ec370fc81d3c0b69553d6345d45
SHA1: cac70bb596e7022ebe218b4317257c7519af4081
File Size: 1.42 MB, 1421824 bytes
MD5: 81dfe3ad9d08b14f8e644d87d16e883c
SHA1: 09dfdef95608d922c7e0b0079d6a759597371670
SHA256: E13A7C7C96B0628AB1A52B2F3565EBA687AF0F4BCF01AED695D7816D65D878D8
File Size: 1.71 MB, 1707008 bytes
MD5: 997cda1e691eba9bda89769441e6c2c6
SHA1: e7168dbfb3cfc6562f03d89ce3ed90589d737583
SHA256: 757B620ADF8F1F9FC64FBDC9DD6F5E2FF6E3062E7A96D5ED8D0A010FA23EDBF5
File Size: 1.24 MB, 1235968 bytes
MD5: c1a625554b4773e59db01c424197bbf7
SHA1: 4fa959e00b71efcbea94d27d7baf072ceec8ae23
SHA256: F255CCD2B11B389E5F8620B7BE827C3034E4F9E6EB1AA4D4CF5AB2E28C00D2AE
File Size: 1.74 MB, 1739776 bytes
MD5: dc5fda8141c0104a6b35fd397741c9e0
SHA1: f6b79f7245f51c8068b55ae50495006081e091eb
SHA256: 7DAB746BEC3322DD985B555445A3273237438CBE6CB60F946ED20B22F0732129
File Size: 970.75 KB, 970752 bytes
MD5: 83fa023ef0a948764deb019b93e560a3
SHA1: 4095890cf666734ba435bf8a9d76ddb0478536ce
SHA256: 64D439A37ABD7C30F7D8238140FED58F0EB4DA57B11D2AAB923F1376F8252E76
File Size: 962.05 KB, 962048 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have resources
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name Microsoft Corporation
File Description
  • Run Once Wrapper
  • winrs
File Version
  • 10.0.19041.4355 (WinBuild.160101.0800)
  • 10.0.19041.1 (WinBuild.160101.0800)
Internal Name
  • RunOnce
  • winrs.exe
Legal Copyright © Microsoft Corporation. All rights reserved.
Original Filename
  • RUNONCE.EXE
  • winrs.exe
Product Name Microsoft® Windows® Operating System
Product Version
  • 10.0.19041.4355
  • 10.0.19041.1

File Traits

  • HighEntropy
  • No Version Info
  • x64

Block Information

Total Blocks: 5,298
Potentially Malicious Blocks: 3,035
Whitelisted Blocks: 2,263
Unknown Blocks: 0

Visual Map

x x x x x 0 x x x x x x x x x 0 x x x x 0 x x 0 x x x x x x x x x x x x x x x x x x 0 x x x 0 x x x 0 x x 0 x 0 x x 0 0 x x x 0 x x x 0 x x x x 0 x x x 0 x x x 0 0 x x x x x x x x x x x x x x x x 0 x 0 x x x 0 0 0 x x x 0 x x 0 0 x x 0 x 0 x x x x x 0 x 0 0 x 0 x 0 0 x 0 0 0 x 0 x 0 x x x x 0 x x x 0 x x 0 x x x x x x 0 0 x x x x x x x x 0 x x x x x 0 x x x x x x x x x x 0 0 x x x x 0 x 0 x x 0 x x x x x x 0 x x 0 x 0 0 x x 0 0 x x 0 0 x x 0 0 0 x x x x x x x x x x 0 x x x x x 0 x x 0 x x x x 0 x x x 0 x 0 0 x 0 x x x x x x x x x x x x x x x x 0 x x x x x x x x 0 x x x x 0 x 0 x x x x x x 0 0 x 0 x x x x 0 x 0 x x 0 x x 0 x x x x x x 0 x 0 x x x 0 0 x 0 x x 0 x 0 x x 0 x 0 x x 0 x x x x x x x x x x x 0 x 0 x x x 0 0 x x x 0 x x x x x x x 0 x x x x x 0 x x x 0 0 x 0 0 x x 0 0 x 0 0 x x x x 0 x x 0 0 x 0 0 x x x 0 x 0 x x x x 0 x x x x 0 0 x 0 x x x 0 x x x x 0 x x x x 0 x 0 x x x x 0 0 x x 0 0 x 0 x x x x 0 x 0 x x x x x x x x x x x x 0 x x x 0 x x x 0 x 0 0 0 x 0 x x x x x x x x x x 0 x x x x x x x x x 0 0 x x 0 0 0 0 x 0 x x x x x x x x x x 0 x x x x x x x x x x 0 x x x x x x x x 0 x x x x x x 0 x x x x x x x x x 0 x x x x x x x x 0 x x x x x x x x 0 x x x x x x x x 0 x x 0 x 0 x x x 0 x x 0 0 x 0 x x x 0 x x x 0 x x x x x x x x x x x 0 x 0 0 x x x x 0 0 0 x x 0 0 x x x x 0 0 x x 0 x x x x 0 0 x x x 0 x x x x 0 0 0 x x 0 x x x x x 0 x 0 0 x x x x x x x x x x x 0 x x 0 0 x 0 x x x x x x x x 0 x x x 0 x x x x 0 x x 0 x x x x x 0 0 x x x x x 0 x x x x 0 x x 0 x 0 x 0 x x x x x x x x x 0 x 0 0 x 0 x 0 0 0 x x x 0 x x x x x 0 x x x 0 x 0 x 0 x 0 x 0 x x 0 x 0 0 0 x x x 0 x x x x x x 0 x x x 0 0 0 x x x x x x x 0 x x 0 x x 0 0 x x x x x x x x x x x 0 x x x 0 x x x x x 0 x x x x x 0 0 0 x x 0 x x x x x x x x 0 0 x x x 0 x 0 0 x x x x x x x x 0 0 x 0 x 0 x 0 x 0 x x x x 0 x x x x x x x 0 x x x x 0 0 x x 0 0 0 x x 0 x 0 x x x x x x x x 0 x 0 x x 0 0 x x x x x x 0 x x 0 0 0 x x x 0 x x 0 0 x x x x x x 0 x x 0 0 0 x x x 0 x x x x x x x x x x x 0 x x x x 0 0 x x x x x x 0 0 x x x 0 0 x x x x x x x x x x 0 x 0 0 0 x x 0 x 0 x x 0 x x x x x x x 0 x x 0 x x x 0 0 x x x x x x x 0 0 x x x x x 0 x x x 0 x x x x 0 x 0 x 0 x x x x 0 x x x 0 x x 0 x 0 x x x x x x x 0 0 0 x x x 0 0 x x x 0 0 x x x 0 x x x x x x x 0 x x x 0 x x 0 0 x x x 0 0 x x x x x x x 0 0 x x x x x 0 x x x 0 x x x x 0 x 0 0 0 x x x x x x x 0 0 x x 0 0 x x x x x x x x x 0 0 0 x x x 0 0 x x x 0 0 x x x 0 x x x x x x x 0 x x x 0 x x 0 0 x x x 0 0 x x x x x x x 0 0 x x x x x 0 x x x 0 x x x x 0 x 0 x 0 x x x x 0 x x x 0 x x 0 x 0 x x x x x x x 0 0 0 x x x 0 0 x x x 0 0 x x x 0 x x x x x x x 0 x x x 0 x x 0 x x 0 0 x x x x x x 0 x x x x x 0 0 x x 0 x 0 x 0 x x x 0 0 x x x 0 x x x x 0 0 0 x 0 0 x x 0 0 0 x 0 0 x x 0 0 0 x 0 0 0 x x x x x 0 x 0 x 0 x x x x 0 0 x 0 x x x 0 0 x 0 x x 0 0 x 0 x x 0 0 x x 0 x x x x x 0 0 x x 0 x 0 x x x x x x 0 x 0 x 0 x 0 x 0 0 0 x 0 x x x 0 x 0 0 0 x 0 x x 0 0 x 0 x x x x x 0 x x x x 0 x x x x x x x x x 0 0 x 0 0 x 0 x x x x 0 x x 0 x 0 x x x 0 0 x x x x x 0 x x 0 0 x x 0 0 x x x 0 0 x x x x x x 0 0 x x 0 x x x x x x 0 0 x x x x x x x 0 x x x x x 0 x x x 0 x x x x x 0 x x x x x 0 0 x x 0 x x 0 0 x 0 x 0 x x 0 x 0 x x x 0 x x 0 x x x x 0 0 x 0 0 0 x 0 0 x x x x 0 0 x x x 0 0 x 0 x x 0 0 x 0 x x x x 0 x x 0 x 0 x x x x x x 0 0 0 x 0 x 0 x x x x 0 x 0 x x x x 0 x x x x x x x 0 x x x 0 x x x x 0 0 x 0 0 0 x 0 x 0 x 0 0 x 0 x x x x x x 0 0 0 0 x 0 x x 0 x x x x 0 x 0 x x x x 0 0 x x 0 x x x 0 0 x 0 x x 0 0 x 0 0 x x 0 x 0 0 x 0 0 x x x x x 0 x 0 x x 0 x x x x x x x 0 x 0 x 0 x x 0 x x x x x x x x x x x x 0 x x x x 0 0 x x 0 x x 0 x x x x 0 x 0 x x 0 x 0 x 0 0 x x x x x 0 x x x x 0 0 x x x 0 x x x x 0 0 x 0 0 0 0 0 x 0 x x x x 0 0 0 x 0 x x x x 0 x x x 0 0 0 0 x x x x 0 x 0 x 0 x 0 0 0 0 x 0 x x 0 0 0 0 x 0 x x 0 0 0 0 x 0 x 0 0 x x x x x x x x x x x 0 x 0 0 x x x 0 x x x x x x x x x 0 x x 0 0 0 x x x x x x x x x x 0 x 0 0 x x x x x 0 x x 0 0 0 x 0 0 x x x x x 0 0 x x x x x x 0 x x x x x 0 0 x x 0 x 0 0 0 0 x 0 x x x x 0 x 0 x x x x x 0 x x 0 x 0 x x x 0 0 x 0 x x x x 0 x x x x x x x x 0 x x x 0 x x x x x x x x x 0 x x 0 x x 0 0 x x x x 0 x 0 x x x x 0 x x x x 0 x 0 x x x 0 0 x x x x 0 0 x x 0 x x x 0 0 0 x x x x x x x x x x x x 0 x x x x x 0 0 x 0 x 0 x 0 x x x 0 0 x 0 x x 0 0 0 x x x x x x 0 0 x x x x 0 x 0 0 x x x 0 x x 0 0 x x 0 x x x x x 0 0 0 x 0 x x 0 0 0 0 0 x 0 x
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • CobaltStrike.HM
  • CobaltStrike.SVA
  • CobaltStrike.UJ
  • Kryptik.DVM
  • Kryptik.DVN
Show More
  • Kryptik.DVO

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryInformationProcess
Show More
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState

Trending

Most Viewed

Loading...