Threat Database Trojans Trojan.Kryptik.GFJ

Trojan.Kryptik.GFJ

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 15,619
Threat Level: 80 % (High)
Infected Computers: 1,105
First Seen: April 27, 2024
Last Seen: May 14, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Kryptik.GFJ
Signature status: No Signature

Known Samples

MD5: 3ff677561502d7c3e9744e84fe4c372f
SHA1: 06b8851bcc293751b14e93d2431cc6afb518b115
SHA256: 0023A44C69F0DBCF165AFC029A005AC2B4483CA0A31EA169007E7C447057F286
File Size: 476.16 KB, 476160 bytes
MD5: cb08568fb57391e24274824259dce055
SHA1: 34aa58664e93f96af51788c379d0ac4ed5a14b26
SHA256: EF8750DB4F405A93367A2E1C2D00DB3A15180FC0C300B786FF0D42A70809F09D
File Size: 593.41 KB, 593408 bytes
MD5: cf5f8b5db0e45993a0bed79dfc46a034
SHA1: 34bb1e5f41aef85c9ca798c9f0a177cdc561ec66
SHA256: 3594ECE6D8AF96939FAB774CB69A8ADB545058307B5445C16F0E2EE533A6FFEF
File Size: 411.14 KB, 411136 bytes
MD5: 3273836efd03f56a0785406b8dd1d07f
SHA1: 04082e46f47c52774e5bc46e54650c858fa9e9bc
SHA256: 2B1A419F294D8ADDE5D37C3FCD02CE46036196691C15C6AA8693113076C72EBA
File Size: 634.37 KB, 634368 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have resources
  • File doesn't have security information
  • File has exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • 2+ executable sections
  • dll
  • HighEntropy
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 465
Potentially Malicious Blocks: 0
Whitelisted Blocks: 459
Unknown Blocks: 6

Visual Map

? ? ? ? ? ? 2 0 0 1 0 0 1 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 1 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 0 0 3 1 1 0 1 2 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.AN
  • Agent.ANH
  • Agent.IUH
  • Kryptik.ATAS
  • Kryptik.PAH
Show More
  • Spy.Agent.FG
  • Trojan.Agent.Gen.AJG
  • Trojan.Agent.Gen.SX
  • Trojan.Downloader.Gen.BP
  • Trojan.Krypt.Gen.PS
  • Trojan.Kryptik.Gen.EGV
  • Trojan.ShellcodeRunner.Gen.FF
  • Trojan.ShellcodeRunner.Gen.IC

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\06b8851bcc293751b14e93d2431cc6afb518b115_0000476160.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\34aa58664e93f96af51788c379d0ac4ed5a14b26_0000593408.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\34bb1e5f41aef85c9ca798c9f0a177cdc561ec66_0000411136.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\04082e46f47c52774e5bc46e54650c858fa9e9bc_0000634368.,LiQMAxHB

Trending

Most Viewed

Loading...