Threat Database Trojans Trojan.Kryptik.Gen.DBQ

Trojan.Kryptik.Gen.DBQ

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.Kryptik.Gen.DBQ
Signature status: No Signature

Known Samples

MD5: b054cb025c67eb1e27b984f52a191917
SHA1: 0e95e6d574b84da4473dc2cbe39cf46f9b03e0fa
SHA256: 02FF23A4D5CA9E19B1D6D34BF05E26E1E52834D49C9B342049331D6C161484F4
File Size: 605.92 KB, 605918 bytes
MD5: 451beaf87986ef52605d3a99bd7a6b23
SHA1: 7c991dc2ab2ee41bb0084ec79a8d31fad2fd7d1d
SHA256: 331E592CF7FABAE31508D6EFD7CF9D2F3458F10085BEFA8D59E8A3993EA80E43
File Size: 2.73 MB, 2734937 bytes
MD5: 250ad250af353f31b6c662bd671f2783
SHA1: 548a8defbaf1e3474fa3db69c7268294f6d8895f
SHA256: 54FF42709F0D9FC94F65FE8D7F1288587966DABAE136F9D5C6EC3ED3E9834D34
File Size: 1.81 MB, 1814928 bytes
MD5: 87a87134832dc6bd910a2fdf92ed3a73
SHA1: 0d40f7f81b57243850066185b788242974455536
SHA256: 13D2B6D339946665271581A8D8FED954535F6B3405FB82BBB5614491F7A25DB4
File Size: 1.61 MB, 1614760 bytes
MD5: d833ddd42217849d90418f18e406168b
SHA1: 86b175502337a5a8f5bca48091f5ad6e03b2939a
SHA256: B877F3EF3A5F6941AB8A732CAEAF21FA80A8818814382AA3EC49FD9A6128B45B
File Size: 1.82 MB, 1816484 bytes
Show More
MD5: 285292d86f774302853af0e93a2353c2
SHA1: 2af7161fd492aae8ebc41945a1fa9004960cf0ec
SHA256: 52EDDCFE0DD3093B6D66CEBBD420480846E0AC79C422D88137A1A96AA34FE894
File Size: 1.59 MB, 1593032 bytes
MD5: cac62732830cf65e8578a50a3fc1114b
SHA1: 1c8eb481822afc8dcb7c84b39ed07d08d5eac737
SHA256: FB209B43468810B910846E2520E98DFF84074F60C038362C61A1FD5E92B81834
File Size: 3.41 MB, 3412072 bytes
MD5: 431fd1c2e9e89b58e66ad3ec449f25b8
SHA1: 0afb05de7a6f402605f3dbf8ca5c9a6a378c0e95
SHA256: BBFE9320BC5247DF59E1FB651428D2CA9E5A90105D4473DE73E75CD0A56BE5AC
File Size: 3.40 MB, 3403540 bytes
MD5: 8d91a5287d842fc54a20b43abe4f42cd
SHA1: f9c01a81c780f1d3a9c33925235ef2f5735c2b11
SHA256: C140527D5665214300EBD20CF46CA1F9DA97303971204B01A9A22784F6D662AE
File Size: 1.12 MB, 1115720 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name
  • Crystal Customer Fast BV
  • ElementDoor Technologies
  • Gamma Nova Co
  • Geo-Fast Network
  • Grid Benchmark Wireless
  • MatrixFirst Co
  • Sequence Technologies
  • Solar Find PC
  • The Neutron Chain Sphere
File Description
  • Approach Allow Divide
  • Canonical Life Framework
  • CRC Sales Continue Helper
  • Deep Latency Handler
  • Import Design Module
  • Innovative Bespoke Orchestration Pack Helper
  • Module Notify Engine
  • Network ARQ Combined Pause Adapter
  • Straightforward Setup Layer
File Version
  • 16.10.17.674
  • 10.14.27.597
  • 7.6.12.92
  • 5.8.4.76
  • 5.3.84.996
  • 3.12.41.507
  • 3.4.18.3
  • 3.1.7.27
  • 2.5.2.39
Internal Name
  • auth51
  • chrome_elf
  • FileResolver
  • format_logistics_plug
  • helper_8c44
  • micro_automation
  • runtime_bf786
  • sqlite
Legal Copyright
  • (C) 2020 - 2020 MatrixFirst Co
  • (C) 2026 Gamma Nova Co
  • 2022 Sequence Technologies. All Rights Reserved.
  • Copyright (c) 2019 by Geo-Fast Network
  • Copyright (c) 2022 by Grid Benchmark Wireless
  • Copyright 2020, 2020 Solar Find PC
  • Copyright 2022 Crystal Customer Fast BV
  • Copyright 2025. The Neutron Chain Sphere
  • ElementDoor Technologies Copyright 2023-2024
Original Filename
  • auth51
  • chrome_elf
  • FileResolver
  • format_logistics_plug
  • helper_8c44
  • micro_automation
  • runtime_bf786.dll
  • sqlite
Product Name
  • Band Resistance Fog Miner
  • Deal Mixer Resolver
  • Facade Tuple Attacher
  • Index Reliable Member Viewer
  • Insights Piece
  • ObserverBone Exceptional Portal
  • Premier Distort Highlighter
  • Sage Facade Natural Snapshot
  • Volume Merged Tester
Product Version
  • 15.4.46.31
  • 11.4.4.325
  • 8.14.24.771
  • 8.7.39.60
  • 6.5.11.138
  • 5.4.1.259
  • 5.0.19.96
  • 3.7.15.260
  • 3.1.7.27

File Traits

  • big overlay
  • dll
  • fptable
  • HighEntropy
  • Installer Manifest
  • Installer Version
  • ntdll
  • x64

Block Information

Total Blocks: 620
Potentially Malicious Blocks: 75
Whitelisted Blocks: 422
Unknown Blocks: 123

Visual Map

? ? ? ? x ? x ? ? x 0 x ? 0 ? ? 0 x x x x x ? x ? ? 0 x ? x ? ? ? 0 ? ? ? ? x ? 0 ? ? x 0 x ? x x ? x x x ? 0 ? ? 0 ? x x x x 0 0 x x x ? ? ? 0 0 x x ? x ? ? x 0 ? ? x ? x x ? x ? x x x 0 x ? ? x x ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? x ? ? ? ? ? x ? ? x ? x x x ? x ? x ? x x ? x ? ? x x ? x ? ? x x 0 x x ? x x x x x ? ? ? ? 0 ? x ? ? x ? ? 0 x ? x ? 0 0 ? x ? ? ? x ? ? 0 ? ? x ? ? ? ? x ? 0 ? x x 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.FTS
  • Agent.KUH
  • CobaltStrike.SVN
  • Kryptik.DEQ
  • Kryptik.GUB
Show More
  • LockScreen.AG
  • Lumma.JC
  • Marte.CP
  • Rozena.XV
  • ShellcodeRunner.RRB
  • Trojan.Agent.Gen.BCO
  • Trojan.Agent.Gen.BGO
  • Trojan.Agent.Gen.BNR
  • Trojan.Agent.Gen.BPF
  • Trojan.Downloader.Gen.KG
  • Trojan.Injector.Gen.GOC
  • Trojan.Kryptik.Gen.DBQ
  • Trojan.Kryptik.Gen.DKA
  • Trojan.Kryptik.Gen.DOM
  • Trojan.Kryptik.Gen.DUH
  • Trojan.Kryptik.Gen.DZH
  • Trojan.Kryptik.Gen.EAW
  • Trojan.Kryptik.Gen.EEG
  • Trojan.ShellcodeRunner.Gen.KE
  • Trojan.ShellcodeRunner.Gen.KI
  • Trojan.ShellcodeRunner.Gen.KS

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
Show More
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtYieldExecution
  • UNKNOWN
Encryption Used
  • BCryptOpenAlgorithmProvider

Trending

Most Viewed

Loading...