Threat Database Trojans Trojan.Kryptik.Gen.EZN

Trojan.Kryptik.Gen.EZN

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 12,475
Threat Level: 80 % (High)
Infected Computers: 6
First Seen: June 11, 2026
Last Seen: August 29, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Kryptik.Gen.EZN
Signature status: No Signature

Known Samples

MD5: be4c9941a3f8a43dde029fc65dff257f
SHA1: e49ab42418d735dbfd474eb1ba99d1221282b91e
SHA256: BC4AAD16458106A774A2CD45037429981403E2728D2334D079AB26F17B6FBBB8
File Size: 531.97 KB, 531968 bytes
MD5: 31c4783b252e309bf99b2b8552dc10d5
SHA1: 55363c8570fdca482f5a44ac073d4ca3b4446785
SHA256: 23C073C9CE1CBF677FE23FC10572B43207ED4E7D5963E9FF2C56DE816B56A2C0
File Size: 512.51 KB, 512512 bytes
MD5: 0641de74a391fdff6566f421377bda75
SHA1: 274f362d228e032728470837179476ac5d3b8d15
SHA256: F6A84A436186EFD0D445AB07C3A3753F8A83963617943137F250E183D48EDD88
File Size: 507.90 KB, 507904 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name
  • caudyeiangs s.p. z o.o
  • cyreintaar s.p. z o.o
  • flaawseryably LLP
File Version
  • 2.2.16.3066
  • 2.0.18.2204
  • 2.0.8.546
Internal Name
  • Uedsaoys.exe
  • wheetzeint.exe
  • Yelyeaububly.exe
Original Filename
  • Uedsaoys.exe
  • wheetzeint.exe
  • Yelyeaububly.exe
Product Name
  • Uedsaoys
  • wheetzeint
  • Yelyeaububly
Product Version
  • 2.2.16.3066
  • 2.0.18.2204
  • 2.0.8.546

File Traits

  • GetConsoleWindow
  • ntdll
  • x64

Block Information

Total Blocks: 417
Potentially Malicious Blocks: 7
Whitelisted Blocks: 402
Unknown Blocks: 8

Visual Map

? 0 ? ? x x 0 ? 0 ? x 0 x 1 ? ? x 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 2 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

Show More
  • Trojan.Kryptik.Gen.FEJ
  • Trojan.Kryptik.Gen.GLZ
  • Trojan.Kryptik.Gen.IKJ
  • Trojan.Kryptik.Gen.INT
  • Trojan.Metasploit.Gen.DV

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
Show More
  • UNKNOWN