Threat Database Trojans Trojan.Kryptik.JUF

Trojan.Kryptik.JUF

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 15,296
Threat Level: 80 % (High)
Infected Computers: 5
First Seen: August 15, 2026
Last Seen: September 12, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Kryptik.JUF
Signature status: No Signature

Known Samples

MD5: 71129870e7364138ea46f980d40526fa
SHA1: 5a074f7ffb7f7bef8247af999f1396b7a7ac8017
SHA256: A5C7F07F7ED017F227957AE02A31AA2848850BBBC46104912B1458955B8121BF
File Size: 1.66 MB, 1660928 bytes
MD5: 3f3a89cd26da2502cbc11dd7c8846585
SHA1: 8b70390fa5fe91059d40fc26b68454dcedbd4dea
SHA256: A280D588389C09200DC5E8ED813864AF056F6E31237527221D9F7D00AEBC3615
File Size: 1.74 MB, 1741312 bytes
MD5: 3fc0374a2ff1ddb29bea24162590147c
SHA1: 201a5bf04f18ade886b166b10f4b532dba99cda8
SHA256: 073CE5B923239278AB002026F6E5F264EEAC426CF42B35144E562BBB7E8C4960
File Size: 2.22 MB, 2216448 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • Pare Works
  • Sapa Tools
  • Wimavo Solutions
File Description
  • Pare Runtime
  • Sapa Tool
  • Wimavo Tool
File Version
  • 2.1.0.8773
  • 1.17.2.6955
  • 1.11.42.7656
Internal Name
  • PareRuntime.exe
  • SapaTool.exe
  • WimavoTool.exe
Legal Copyright
  • Copyright (C) 2020 Sapa Tools
  • Copyright (C) 2020 Wimavo Solutions
  • Copyright (C) 2023 Pare Works
Original Filename
  • PareRuntime.exe
  • SapaTool.exe
  • WimavoTool.exe
Product Name
  • Pare Runtime
  • Sapa Tool
  • Wimavo Tool
Product Version
  • 2.1.0.8773
  • 1.17.2.6955
  • 1.11.42.7656

File Traits

  • fptable
  • HighEntropy
  • x64

Block Information

Total Blocks: 403
Potentially Malicious Blocks: 1
Whitelisted Blocks: 390
Unknown Blocks: 12

Visual Map

? ? 0 0 ? 0 ? 0 ? ? ? ? ? ? ? ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Kryptik.JUF
  • Kryptik.JUH
  • Kryptik.JUI
  • Kryptik.JUJ
  • Trojan.Kryptik.Gen.GXL
Show More
  • Trojan.Kryptik.Gen.GZD
  • Trojan.Kryptik.Gen.JCZ

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
Show More
  • UNKNOWN