Threat Database Trojans Trojan.Kryptik.Gen.DSF

Trojan.Kryptik.Gen.DSF

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 18,843
Threat Level: 80 % (High)
Infected Computers: 3
First Seen: March 18, 2026
Last Seen: April 22, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Kryptik.Gen.DSF
Signature status: No Signature

Known Samples

MD5: de10996d7714c52f0c8cc0ece7ecc810
SHA1: a9ec513968f31619967ab972d5a37af57f81b19f
SHA256: 67F41BE88BDFF63E8320865979B0E0F4F6031422B40BBE2944924FEB173D6945
File Size: 4.58 MB, 4575744 bytes
MD5: 510c801e18ac1bae3fd084473c86f820
SHA1: dc3c9b64fe0d3c1a2f0c3d97c0f7bd5c820624ce
SHA256: 1F2206101F7144725BF3946CEC5AE221C52AE8ACB2940FDB4EBCA00FC5CF84C8
File Size: 332.29 KB, 332288 bytes
MD5: d4139aaad2d6c72d60e172a91c681cae
SHA1: 39eff60261fc215c0b6e3aa29acbe055a99c9124
SHA256: 2309395A0B131D7F8090326E66BA87BE5D694375E5DD5FC9722ADEDD689791C8
File Size: 4.58 MB, 4581376 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have resources
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
Show More
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name voidtools
File Description Everything - Search Engine for Windows
File Version 1.4.1.1026
Internal Name Everything
Legal Copyright © 2023 voidtools
Original Filename Everything.exe
Product Name Everything
Product Version 1.4.1.1026

File Traits

  • CryptUnprotectData
  • HighEntropy
  • No CryptProtectData
  • No Version Info
  • WriteProcessMemory
  • x64

Block Information

Total Blocks: 1,409
Potentially Malicious Blocks: 215
Whitelisted Blocks: 1,153
Unknown Blocks: 41

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x x x x x x x x 0 x x x 0 x 0 x x x 0 x x x x x 0 x x x x x x 0 x x 0 x 0 x x x x x x x x x x x 0 x x ? x 0 0 x 0 x x x 0 0 0 0 0 ? ? ? x ? 0 x ? ? ? ? x 0 ? ? 0 ? ? 0 0 ? ? ? 0 ? ? ? ? ? ? 0 0 ? x x x x x 0 0 x x x x x x x 0 0 0 0 0 x x 0 x 0 x 0 x ? 0 ? ? 0 ? ? 0 x x 0 x x x x 0 0 0 0 x x x x x 0 ? ? ? 0 0 0 ? 0 ? ? x 0 0 ? 0 0 ? ? ? ? ? 0 ? x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 x x x 0 x x 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 x x 0 x x 0 x x 0 0 0 0 0 0 0 0 0 x 0 0 x x x x 0 0 x 0 0 0 0 x 0 0 0 0 x 0 0 x x 0 0 x 0 0 0 0 x 0 0 0 0 0 x 0 x 0 0 x 0 x 0 x 0 0 x 0 0 x x x x 0 x x 0 0 0 x 0 0 0 x 0 x 0 0 x 0 x x x x x 0 x x 0 0 0 x 0 x 0 0 0 x 0 0 x 0 x 0 x x 0 x 0 x 0 x x 0 x 0 0 x 0 x x 0 x 0 x 0 x x 0 x 0 x 0 0 0 0 0 0 0 x x 0 x 0 x x x 0 x 0 x 0 x 0 0 0 x 0 x 0 x x x 0 x 0 x 0 x 0 x 0 x x 0 0 0 x x x 0 x 0 0 x x 0 0 x x 0 x x 0 0 0 0 0 0 x x x 0 x 0 0 x x 0 0 x x x x x x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

Show More
  • Trojan.ShellcodeRunner.Gen.NS
  • Trojan.ShellcodeRunner.Gen.NY

Files Modified

File Attributes
\device\namedpipe\chromium.ipc.44196.5508 Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\chromium.ipc.64633.6396 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\log.txt Generic Write,Read Attributes

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtGetNextProcess
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
Show More
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTerminateProcess
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • VirtualAllocEx
Process Shell Execute
  • CreateProcess
Thread Create Remote
  • CreateRemoteThread
Service Control
  • StartServiceCtrlDispatcher

Shell Command Execution

C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe (NULL)

Trending

Most Viewed

Loading...