Threat Database Trojans Trojan.Kryptik.Gen.ECL

Trojan.Kryptik.Gen.ECL

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.Kryptik.Gen.ECL
Signature status: Self Signed

Known Samples

MD5: 71433eadba3f3f3d258e75d98841fa39
SHA1: 4deb46f25d9e030e273fc8ffb8ec8d092484126b
SHA256: 5A509D88669F780465BC59AD9BD092FC3AB4538B6B2653AD02173F1197C23FD1
File Size: 656.19 KB, 656192 bytes
MD5: 2784d93333fa8284267a70b25ed00706
SHA1: 3dcb019973629bcdb423ac6e0df1ef29c4fbd89f
SHA256: 05995356583300D087CB73DA34FC9722099C6229325CBE240BF6BA32AAC258A5
File Size: 658.76 KB, 658760 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File has exports table
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments
  • Enhanced with Machine Learning capabilities
  • Optimized for Cloud computing performance
Company Name
  • Boehm - Stokes
  • Bogan, Witting and McKenzie S.A.S.
  • Robel - Hilpert
  • Skiles - D'Amore B.V.
File Description
  • multi-byte array Professional System
  • USB pixel - Dutch Version
  • USB pixel - French Version
  • USB pixel Master Optimizer
File Version
  • 4.15.5016.985
  • 4.13
Internal Name
  • multibytearray_client.exe
  • usbpixel.exe
Legal Copyright
  • Copyright © 2019 Boehm - Stokes. All rights reserved.
  • © 2024 Robel - Hilpert. All rights reserved.
Legal Trademarks
  • All trademarks are property of their respective owners. multi-byte array is a trademark of Robel - Hilpert.
  • USB pixel® is a registered trademark of Boehm - Stokes
Original Filename
  • boehm-usbpixel.exe
  • robel-multibytearray.exe
Product Name
  • multi-byte array
  • USB pixel
Product Version
  • 4.15.5016.985
  • 4.13

Digital Signatures

Signer Root Status
Boehm - Stokes Boehm - Stokes Intermediate CA 3 Self Signed
Robel - Hilpert Robel - Hilpert Intermediate CA 1 Self Signed

File Traits

  • HighEntropy
  • x64

Block Information

Total Blocks: 40
Potentially Malicious Blocks: 33
Whitelisted Blocks: 7
Unknown Blocks: 0

Visual Map

x x x x x x x x x x x x 0 x x x x 0 0 0 0 x x x x x x x x x x 0 x x 0 x x x x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Trending

Most Viewed

Loading...