Trojan.Kryptik.IOC
Threat Scorecard
EnigmaSoft Threat Scorecard
EnigmaSoft Threat Scorecards are assessment reports for different malware threats which have been collected and analyzed by our research team. EnigmaSoft Threat Scorecards evaluate and rank threats using several metrics including real-world and potential risk factors, trends, frequency, prevalence, and persistence. EnigmaSoft Threat Scorecards are updated regularly based on our research data and metrics and are useful for a wide range of computer users, from end users seeking solutions to remove malware from their systems to security experts analyzing threats.
EnigmaSoft Threat Scorecards display a variety of useful information, including:
Popularity Rank: The ranking of a particular threat in EnigmaSoft’s Threat Database.
Severity Level: The determined severity level of an object, represented numerically, based on our risk modeling process and research, as explained in our Threat Assessment Criteria.
Infected Computers: The number of confirmed and suspected cases of a particular threat detected on infected computers as reported by SpyHunter.
See also Threat Assessment Criteria.
| Popularity Rank: | 26,443 |
| Threat Level: | 80 % (High) |
| Infected Computers: | 27 |
| First Seen: | November 14, 2025 |
| Last Seen: | July 15, 2026 |
| OS(es) Affected: | Windows |
The detection of Trojan.Kryptik.IOC on your system indicates a potential security threat. This report aims to provide you with general guidance on understanding and removing this threat. It's essential to approach this situation with caution and follow the recommended steps to ensure the security of your system and data.
Table of Contents
What Is Trojan.Kryptik.IOC?
Trojan.Kryptik.IOC is a type of malware that can compromise the security of your system. The term "Trojan" refers to a broad category of malicious software that can disguise itself as legitimate programs, allowing it to bypass security measures and gain unauthorized access to your computer. The specific characteristics and behaviors of Trojan.Kryptik.IOC can vary, but its primary goal is to cause harm or exploit your system for malicious purposes.
How Trojan.Kryptik.IOC Operates
Malware like Trojan.Kryptik.IOC typically operates by exploiting vulnerabilities in software or tricking users into installing it. Once installed, it can perform a variety of malicious actions, such as stealing sensitive information, installing additional malware, or providing unauthorized access to your system. The exact mechanisms and tactics used by Trojan.Kryptik.IOC are not specified here, as they can depend on various factors, including the malware's design and the system it infects.
Symptoms of Infection
Systems infected with Trojan.Kryptik.IOC may exhibit a range of symptoms, including but not limited to, unusual system behavior, slow performance, frequent crashes, or the appearance of unwanted programs or toolbars. However, some malware is designed to operate stealthily, making it difficult to detect without the use of specific security tools. If you suspect that your system is infected, it's crucial to take immediate action to minimize potential damage.
How to Remove Trojan.Kryptik.IOC
- Boot your system into Safe Mode with Networking to prevent the malware from loading and to allow for internet access. This will make it easier to download and install removal tools.
- Download and run a full scan with a reputable anti-malware tool, such as SpyHunter, to detect and remove Trojan.Kryptik.IOC and any other malware that may be present on your system.
- Uninstall any suspicious programs that you do not recognize or that were installed around the time the malware was detected. Be cautious and only remove programs that you are certain are not essential to your system's operation.
- Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or settings that the malware may have installed.
- Reboot your system and perform another full scan with your anti-malware tool to ensure that all traces of the malware have been removed. This step is crucial to verify that your system is clean and secure.
Conclusion
The removal of Trojan.Kryptik.IOC requires careful attention to detail and adherence to best practices for malware removal. By following the steps outlined in this report and maintaining a proactive approach to system security, you can significantly reduce the risk of future infections. Remember, prevention is key, and using reputable security software, keeping your operating system and applications up to date, and being cautious when downloading and installing software can help protect your system from threats like Trojan.Kryptik.IOC.
Analysis Report
General information
| Family Name: | Trojan.Kryptik.IOC |
|---|---|
| Signature status: | No Signature |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
d646e56169d0760b259cee658cc6c426
SHA1:
9a7ac0f4f15c754d3a3512f147a192c77531688d
SHA256:
E48EC0BD3F1C4CE9E13B2A010BDBDD0EAC0B33511458478127762FC02D6A1920
File Size:
4.67 MB, 4668992 bytes
|
|
MD5:
d4ae3614af5f1b042ed23e89535ddf41
SHA1:
b62339a2f54c91f2b5bf6421ef0f09210c10e4a7
SHA256:
1953BB3E9AA0D2BA609ACE8D08104BACF65F366734E97CD18F37D3AFF94FEEC1
File Size:
9.83 MB, 9825857 bytes
|
|
MD5:
a4082e6929cbd767b475f56315b6876c
SHA1:
e9e855548b7c5f2c51483ba621d69e2621103160
SHA256:
FCE8BAABEE544CE0B1C14404B1EB0B84D1EC63D50636D3B598B265CE967E275C
File Size:
5.49 MB, 5486144 bytes
|
|
MD5:
c450dfa416e535a0ecf00aafe4b0e8d3
SHA1:
ea0a55e8d1c594a7897a427a1acce2756961a06a
SHA256:
84672D86CA44479FD388F451CD97002EB1E7EA94AAFD62786D52ECA5A2FF1FCE
File Size:
3.65 MB, 3653128 bytes
|
|
MD5:
4f4b54718385c350cd8aa5c222475c9c
SHA1:
23832326714adeb5699e0210871c85eca960128b
SHA256:
5C7B9621AAEC04698B0069E2F8226FC181FC432D40E93BD6C3A5F09520AA626D
File Size:
3.54 MB, 3542144 bytes
|
Show More
|
MD5:
550e2af9997e24eaf1c94cf25b36b245
SHA1:
10342c2e752c44685f2b5f54aaea8c024093c04c
SHA256:
A85181C3D9F6069873759D9C29E0D6F1581CF7CCD6752034F04D0992073E831B
File Size:
4.10 MB, 4100240 bytes
|
|
MD5:
bde5ab469fb4d105c0d14bcd9e5d9ebe
SHA1:
77c02b64fc84fac611519fdd128e115886f1d9f1
SHA256:
B81C97C384B7C6E01594CEE96D53A262530D4A69AA1D1EC6EF177FDAA723E929
File Size:
3.73 MB, 3725440 bytes
|
|
MD5:
a8821241e8713b979401cf29c02d4449
SHA1:
019beb3d2c896438967d8ab5a939392002bbfd58
SHA256:
880C09AC158CCC9DC96E5E3AB674B20F3FC56F3EA6A21E7F6384183655857DDE
File Size:
4.13 MB, 4129584 bytes
|
|
MD5:
f49f47e9ee42a3dbcadd25822811ed54
SHA1:
bc67af39cef2c613ebb92abfc75328bcce59ad20
SHA256:
19EAFE6C2F779DD6F53EB028D4C70EC7AB2646E99906FEA5A2A90BCB11F9503E
File Size:
4.43 MB, 4433472 bytes
|
|
MD5:
8bb565d2f3dd7d9ad41401d547ec109e
SHA1:
b869ecd713380275c21f55f2311d8478bb44045f
SHA256:
C8C7DF951CF11FD13CF2134465836BD1E4013B200667638516AC04ACA1BF9225
File Size:
4.11 MB, 4112072 bytes
|
|
MD5:
2d6c5dc1648c07d8d435fe02a61e15be
SHA1:
6fa7b3bd6cf602e27a455bc8215eca15ea3c0bd2
SHA256:
4AF4860E696C35949993DBEE6F72BBE61755B546836832C1DE4D6FDA9CAFF04F
File Size:
3.70 MB, 3704776 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have debug information
- File doesn't have exports table
- File doesn't have security information
- File has exports table
- File has TLS information
- File is 64-bit executable
- File is either console or GUI application
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is Native application (NOT .NET application)
Show More
- File is not packed
- IMAGE_FILE_DLL is not set inside PE header (Executable)
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
File Icons
File Icons
This section displays icon resources found within family samples. Malware often replicates icons commonly associated with legitimate software to mislead users into believing the malware is safe.Windows PE Version Information
Windows PE Version Information
This section displays values and attributes that have been set in the Windows file version information data structure for samples within this family. To mislead users, malware actors often add fake version information mimicking legitimate software.| Name | Value |
|---|---|
| Comments | https://mobaxterm.mobatek.net |
| Company Name |
|
| File Description |
|
| File Version |
|
| Internal Name |
|
| Legal Copyright |
|
| Legal Trademarks | Mobatek - https://mobaxterm.mobatek.net |
| Original Filename |
|
| Product Name |
|
| Product Version |
|
Digital Signatures
Digital Signatures
This section lists digital signatures that are attached to samples within this family. When analyzing and verifying digital signatures, it is important to confirm that the signature’s root authority is a well-known and trustworthy entity and that the status of the signature is good. Malware is often signed with non-trustworthy “Self Signed” digital signatures (which can be easily created by a malware author with no verification). Malware may also be signed by legitimate signatures that have an invalid status, and by signatures from questionable root authorities with fake or misleading “Signer” names.| Signer | Root | Status |
|---|---|---|
| HTC Corp. | DigiCert SHA2 Assured ID Code Signing CA | Hash Mismatch |
| HTC Corp. | DigiCert SHA2 Assured ID Code Signing CA | Hash Mismatch |
| Shenzhen CBD Technology Co., Ltd. | DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 | Hash Mismatch |
| Mobatek | Sectigo Public Code Signing Root R46 | Hash Mismatch |
| dark.shopping | dark.shopping | Self Signed |
Show More
| www.tripadvisor.com | www.tripadvisor.com | Self Signed |
File Traits
- big overlay
- dll
- golang
- HighEntropy
- Installer Version
- No Version Info
- x64
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 4,882 |
|---|---|
| Potentially Malicious Blocks: | 409 |
| Whitelisted Blocks: | 3,809 |
| Unknown Blocks: | 664 |
Visual Map
? - Unknown Block
x - Potentially Malicious Block
Similar Families
Similar Families
This section lists other families that share similarities with this family, based on EnigmaSoft’s analysis. Many malware families are created from the same malware toolkits and use the same packing and encryption techniques but uniquely extend functionality. Similar families may also share source code, attributes, icons, subcomponents, compromised and/or invalid digital signatures, and network characteristics. Researchers leverage these similarities to rapidly and effectively triage file samples and extend malware detection rules.- Agent.IDA
- Agent.KOFA
- Agent.LKGG
- Agent.LPX
- Agent.TKJ
Show More
- Agent.TRFE
- Dropper.JD
- Filecoder.PFA
- Filecoder.YA
- Kryptik.FSK
- Kryptik.FST
- Kryptik.GSH
- Kryptik.IOA
- Kryptik.IOB
- Kryptik.IOC
- Kryptik.MDA
- Kryptik.MHD
- Kryptik.MHE
- Quasar.LD
- Quasar.SA
- Reconyc.FH
- Reconyc.FI
- ReverseShell.XF
- ShellcodeRunner.HCA
- ShellcodeRunner.TO
- Trojan.Metasploit.Gen.AF
- Trojan.ReverseShell.Gen.W
- Trojan.ShellcodeRunner.Gen.AQ
- Vidar.PA
- Vidar.PB
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API usage analysis is a valuable tool that can help identify malicious activity, such as keylogging, security privilege escalation, data encryption, data exfiltration, interference with antivirus software, and network request manipulation.| Category | API |
|---|---|
| Syscall Use |
Show More
|
| Process Manipulation Evasion |
|
| Process Shell Execute |
|
Shell Command Execution
Shell Command Execution
This section lists Windows shell commands that are run by the samples in this family. Windows Shell commands are often leveraged by malware for nefarious purposes and can be used to elevate security privileges, download and launch other malware, exploit vulnerabilities, collect and exfiltrate data, and hide malicious activity.
C:\\Windows\\SysWOW64\\explorer.exe
|