Threat Database Trojans Trojan.Kryptik.JOJ

Trojan.Kryptik.JOJ

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 16,418
Threat Level: 80 % (High)
Infected Computers: 70
First Seen: October 17, 2023
Last Seen: July 19, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Kryptik.JOJ
Signature status: No Signature

Known Samples

MD5: 369e544f92ded55434325ba939fa6e48
SHA1: 0a3d079b853b2e0677040be99f8c82f536cf6779
SHA256: B62EE26919B07A1173BDEDC3A17A7ED0D49F7E09E496EBD2E6AA2037468862E9
File Size: 863.74 KB, 863744 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Microsoft Corporation
File Description Win32 Cabinet Self-Extractor
File Version 11.00.17763.1 (WinBuild.160101.0800)
Internal Name Wextract
Legal Copyright © Microsoft Corporation. All rights reserved.
Original Filename WEXTRACT.EXE .MUI
Product Name Internet Explorer
Product Version 11.00.17763.1

File Traits

  • HighEntropy
  • No Version Info
  • x86

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\4vb789rb.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\4vb789rb.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\ov6ts5pw.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\ov6ts5pw.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\tmp4351$.tmp Generic Write,Read Attributes,Delete
c:\users\user\appdata\local\temp\ixp001.tmp\3dl6oa44.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp001.tmp\3dl6oa44.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp001.tmp\em4xd5bx.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp001.tmp\em4xd5bx.exe Synchronize,Write Attributes
Show More
c:\users\user\appdata\local\temp\ixp001.tmp\tmp4351$.tmp Generic Write,Read Attributes,Delete
c:\users\user\appdata\local\temp\ixp002.tmp\1ir28sm6.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp002.tmp\1ir28sm6.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp002.tmp\2nr569vq.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp002.tmp\2nr569vq.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp002.tmp\tmp4351$.tmp Generic Write,Read Attributes,Delete

Registry Modifications

Key::Value Data API Name
HKLM\software\wow6432node\microsoft\windows\currentversion\runonce::wextract_cleanup0 rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Rjybpnya\AppData\Local\Temp\IXP000.TMP\" RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\runonce::wextract_cleanup1 rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Rjybpnya\AppData\Local\Temp\IXP001.TMP\" RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\runonce::wextract_cleanup2 rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Rjybpnya\AppData\Local\Temp\IXP002.TMP\" RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess

Shell Command Execution

C:\Users\Rjybpnya\AppData\Local\Temp\IXP000.TMP\ov6ts5PW.exe
C:\Users\Rjybpnya\AppData\Local\Temp\IXP001.TMP\Em4XD5BX.exe
C:\Users\Rjybpnya\AppData\Local\Temp\IXP002.TMP\1IR28SM6.exe