Threat Database Trojans Trojan.Kryptik.EDAJ

Trojan.Kryptik.EDAJ

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 15,315
Threat Level: 80 % (High)
Infected Computers: 12
First Seen: January 2, 2026
Last Seen: June 24, 2026
OS(es) Affected: Windows

The detection of Trojan.Kryptik.EDAJ on your system indicates a potential security threat that requires immediate attention. This report aims to provide you with general guidance on understanding and removing the detected threat. It is essential to approach this situation with caution and follow the recommended steps to ensure the security and integrity of your system.

What Is Trojan.Kryptik.EDAJ?

Trojan.Kryptik.EDAJ is a type of malware that has been detected on your system. The name suggests that it may be related to Trojan-type threats, which are known for their ability to disguise themselves as legitimate programs or files. Trojans can be used to gain unauthorized access to a system, steal sensitive information, or disrupt system operations. However, without more specific information, it is difficult to determine the exact nature and capabilities of Trojan.Kryptik.EDAJ.

How Trojan.Kryptik.EDAJ Operates

Malware like Trojan.Kryptik.EDAJ typically operates by exploiting vulnerabilities in software or human error. They can be spread through various means, including infected email attachments, compromised websites, or infected software downloads. Once inside a system, the malware can establish a connection with its command and control server, allowing it to receive instructions and transmit stolen data. The exact mechanisms used by Trojan.Kryptik.EDAJ are unknown, but it is likely that it uses common techniques such as code obfuscation, encryption, and anti-detection methods to evade detection.

Symptoms of Infection

Systems infected with Trojan.Kryptik.EDAJ may exhibit a range of symptoms, including slow system performance, unexpected crashes, and unusual network activity. You may also notice that your system is behaving erratically, such as displaying unusual error messages or pop-ups. In some cases, the malware may attempt to hide its presence, making it difficult to detect without the use of specialized tools. If you suspect that your system has been infected, it is essential to take immediate action to prevent further damage.

How to Remove Trojan.Kryptik.EDAJ

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for easier removal.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any associated files or components.
  3. Uninstall any suspicious programs or applications that may be related to the malware.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or plugins.
  5. Reboot your system and perform a follow-up scan to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.Kryptik.EDAJ from your system requires a thorough and multi-step approach. By following the recommended steps and using reputable anti-malware tools, you can help ensure the security and integrity of your system. It is essential to remain vigilant and take proactive measures to prevent future infections, such as keeping your software up-to-date, using strong passwords, and avoiding suspicious emails or downloads. If you are unsure about any aspect of the removal process, consider seeking the assistance of a qualified IT professional or the manufacturer's support team.

Analysis Report

General information

Family Name: Trojan.Kryptik.EDAJ
Signature status: No Signature

Known Samples

MD5: c97f93932330553a3357cc494b29723f
SHA1: d5720bc6255c524e5f98b403fcb84dbf89617ad8
SHA256: 2A473C150EBDEC637F0938E59681F9119E7485A3D673DD77037EF6248B981151
File Size: 2.54 MB, 2539520 bytes
MD5: f6a0aaf746095a75c0420c98232249f6
SHA1: 8f13ce1901541e97ec4098f6222df5c40dddc32e
SHA256: 73A94368925F13713D827DD8E56A300C9EB1C0FD0569E38209A0E3373FAA73FD
File Size: 2.54 MB, 2539520 bytes
MD5: 957cb2d0a8944d460028c62d313b32e7
SHA1: 13894ffa1e14e052ffafca2e0a5c59bd7c9acbc8
SHA256: 273E24BD9F15CE339BCACB82E57EA28CD8594A526FBBE3A6444427D25EB14051
File Size: 2.54 MB, 2539520 bytes
MD5: e4cedf58a04e66f089239ad9e7f38c30
SHA1: 7f9ffe4867294ab86ce7980a2f834ab5107d441c
SHA256: 0D01C7AF8E0F06D82A72CDE889C91E78E2B7C9FFCBB544636DF4D5D34CA3265D
File Size: 2.54 MB, 2539520 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have resources
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • CryptUnprotectData
  • fptable
  • No CryptProtectData
  • No Version Info
  • ntdll
  • VirtualQueryEx
  • x64

Block Information

Total Blocks: 2,091
Potentially Malicious Blocks: 933
Whitelisted Blocks: 1,158
Unknown Blocks: 0

Visual Map

x x 0 x 0 x 0 x 0 0 0 0 0 0 0 x 0 x x x x x x x x x 0 x 0 x 0 0 x 0 x x 0 0 x x x x x x x x x 0 0 0 x x x x x x 0 x 0 x x x x x x x 0 0 x x x x x x 0 0 0 0 x 0 0 0 0 x 0 x x 0 x 0 x 0 0 0 0 0 x 0 0 x 0 x x 0 0 0 x 0 0 0 x x 0 x x x x 0 0 x 0 0 x x x x x 0 x x x 0 x 0 0 0 0 0 x 0 x 0 x 0 0 0 0 0 0 0 x 0 0 x 0 x x 0 0 x 0 x 0 x 0 0 x 0 0 x x x x x 0 0 0 x x 0 0 x x x 0 0 0 0 x x 0 0 x x 0 0 0 x 0 x 0 x 0 0 x 0 0 0 x x x x x x 0 0 0 0 0 0 0 x 0 0 0 0 x x x x x x 0 x 0 x x x x 0 0 0 x x x x x x x x x x 0 x 0 0 0 0 x x 0 x x x x x x x x x 0 0 0 0 x x x x x 0 x x x x 0 x x 0 0 0 0 x x x x x x x x x x 0 x x x x 0 x 0 x 0 0 x x x x 0 x x 0 x 0 x x x 0 0 x x 0 x 0 x x x 0 x x 0 0 x 0 x 0 x x x 0 x 0 x x x 0 0 x 0 0 x x 0 x 0 x x 0 x x 0 0 x x 0 x 0 0 0 x x 0 0 x 0 0 0 x x 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 x x 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x x x x x 0 x x 0 x 0 x 0 0 0 0 0 x x x x x x 0 0 x 0 0 x x x x x 0 x 0 x x 0 x 0 x x x 0 x 0 0 x 0 x x 0 x x 0 0 x x 0 0 x x x 0 x 0 0 x x x 0 0 x x 0 x x x x x x x x 0 x 0 0 0 x 0 0 x 0 x x x 0 0 0 0 0 0 x x 0 x 0 x 0 x 0 0 0 0 0 x x x 0 0 x 0 x 0 0 x x x x x 0 0 x x x x 0 x x x 0 0 x x x x 0 x 0 0 x x x 0 0 0 x 0 0 x x x 0 0 0 x 0 x x x x 0 0 x x 0 0 x x x 0 0 x x x x 0 x 0 x 0 x 0 x x x x x x x x x 0 0 0 0 x 0 x 0 x x x x 0 0 x x x x 0 x x 0 0 0 x x x 0 0 x x x x x x x x x 0 x 0 x x x x x 0 0 0 0 x 0 x 0 0 0 x 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 x 0 x x x x 0 x 0 0 0 0 x 0 x 0 0 0 x 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 x 0 x 0 0 0 x 0 0 0 0 x 0 x x x 0 x 0 x 0 0 0 0 x 0 x x x 0 x 0 x 0 0 0 0 x 0 x 0 x x 0 x 0 0 0 0 0 x 0 0 0 0 x 0 x 0 0 0 x x x 1 x x x x 0 x x x x x 0 0 x x x x x 0 x x x x 0 0 0 0 x 0 0 x 0 x x 0 0 0 x 0 0 x 0 0 x x x x 0 x x 0 x 0 x x 0 x x 0 x x x x x 0 x x 0 0 0 x x x x x 0 x x x 0 0 0 0 x x 0 x x x x x x x x x 0 x x x x 0 0 0 0 0 0 x x 0 x x x x x x x 0 x x x x x x 0 0 x 0 0 x x x x 0 0 0 x 0 x x x x x x x x x x 0 0 0 x x 0 0 x 0 x x x x 0 x 0 0 x 0 0 0 x x x x x x 0 x 0 0 0 x x 0 x x x x x x 0 0 x 0 x x 0 x x 0 x x x 0 0 0 0 0 x x x 0 x x x x x 0 x 0 0 x x x 0 0 x 0 x 0 0 0 x 0 0 0 x 0 x x 0 0 0 0 x x x x x x 0 0 x 0 0 x x x 0 x x x x 0 x 0 x 0 0 x x x 0 0 x 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 x x 0 x x x x 0 x 0 x 0 x 0 x 0 x x x 0 x 0 x 0 x 0 x x 0 x x x x x x x 0 0 0 x 0 x x x x 0 x x 0 0 x 0 0 0 0 0 x 0 x 0 x 0 0 x 0 x 0 x x 0 x x 0 x x x x x x x 0 x x x 0 x x x x 0 0 x x x x x x x 0 x x x x x 0 x x 0 0 0 x x 0 x x 0 x 0 0 0 0 x x x x x 0 x x 0 0 0 x 0 x 0 0 x 0 x 0 x x 0 x x 0 x x 0 x x 0 0 x x 0 0 x x x x x x 0 0 x x x x x x x 0 0 x x 0 x x 0 x x x x x 0 0 0 0 0 x 0 0 x x 0 x 0 0 0 0 0 x x 0 x x x x 0 x x x x 0 0 x x x x x x 0 x 0 x x x x x x 0 0 x x x 0 0 0 x 0 0 x 0 x x 0 x 0 0 0 x x 0 x 0 0 0 0 0 0 x 0 0 x 0 x x x x 0 0 0 0 0 x x x x x 0 x x x x x x 0 x 0 x x 0 0 0 x 0 0 x x x x 0 0 0 x 0 x x 0 x 0 x x 0 x x x x x 0 0 0 x 0 x 0 x x 0 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x x 0 x 0 x x 0 0 0 x 0 x x x x 0 0 0 x 0 0 0 x x 0 x 0 x 0 0 0 0 0 x 0 0 0 0 x x x x x x 0 x x 0 0 x 0 x x 0 0 0 0 x 0 x x x 0 x 0 0 x x 0 x x x x 0 x 0 x x 0 0 0 x 0 x 0 0 x x 0 x x x x 0 x x x x 0 x x x 0 x 0 0 0 x x x 0 x x 0 x 0 x x x 0 x x 0 x 0 x 0 x x x x x x x x x x x 0 0 x 0 x 0 x 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 2 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x 0 x x x 0 x x x 0 x x x 0 x 0 0 0 0 x 0 x 0 0 0 x 0 x x 0 x 0 x 0 x x x x 0 x x x x x 0 0 x x x 0 x x x x x x 0 x 0 0 x x x x 0 x x x x 0 0 x x 0 x x 0 0 x x x x x x x 0 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Kryptik.EDAJ

Files Modified

File Attributes
\device\namedpipe Generic Write,Read Attributes
\device\namedpipe\dav rpc service Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\pshost.134136928048646637.4972.defaultappdomain.powershell Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
\device\namedpipe\pshost.134142956711232021.6348.defaultappdomain.powershell Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
\device\namedpipe\pshost.134145072581043696.7824.defaultappdomain.powershell Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
\device\namedpipe\pshost.134231758461534901.4824.defaultappdomain.powershell Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
\device\namedpipe\wkssvc Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\powershell\startupprofiledata-noninteractive Generic Write,Read Attributes
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.0.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.1.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
Show More
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.2.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\__psscriptpolicytest_g0h5py5y.o5r.psm1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_mg0eutwf.2sh.psm1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_mv0jkqzr.lug.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_oqmus3e4.zwv.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_spplohvk.2ih.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_sv1ra0zh.3ar.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_svtqjrxs.lre.psm1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_ysppeara.z3s.psm1 Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 䮛賓ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 鞑鐻ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe I���N�� RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 疌뢮ǜ RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAllocateLocallyUniqueId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelTimer2
Show More
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCompareSigningLevels
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateNamedPipeFile
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtGetCachedSigningLevel
  • ntdll.dll!NtGetWriteWatch
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtQueueApcThreadEx2
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRemoveIoCompletion
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResetWriteWatch
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationObject
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSetTimerEx
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl

26 additional items are not displayed above.

Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
User Data Access
  • GetUserDefaultLocaleName
  • GetUserName
  • GetUserNameEx
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
Other Suspicious
  • AdjustTokenPrivileges
Process Terminate
  • TerminateProcess

Shell Command Execution

C:\WINDOWS\System32\WindowsPowerShell\v1.0\powershell.exe "powershell" -Command "Get-Process | Select-Object Name"

Trending

Most Viewed

Loading...