Threat Database Trojans Trojan.Kryptik.Gen.GCF

Trojan.Kryptik.Gen.GCF

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.Kryptik.Gen.GCF
Signature status: No Signature

Known Samples

MD5: 5133b343ace69f0311beb8e1bdc81962
SHA1: 2c9dfb342897a1bfd74367dc378fe9e3415ab6f8
SHA256: 325CED92205974AAB6F44A7052A2657A1FF54D24AB388CE866A9378418DCE437
File Size: 747.01 KB, 747008 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name SoftWorks LLC
File Description Component Host
File Version 5.8.50.1287
Internal Name helper
Original Filename helper.exe
Product Name Component Host
Product Version 5.8.50.1287

File Traits

  • HighEntropy
  • x64

Block Information

Total Blocks: 32
Potentially Malicious Blocks: 31
Whitelisted Blocks: 1
Unknown Blocks: 0

Visual Map

x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN