Threat Database Trojans Trojan.Kryptik.KPE

Trojan.Kryptik.KPE

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.Kryptik.KPE
Signature status: No Signature

Known Samples

MD5: c90f99b3386ca5aa37c3e4444e0621f2
SHA1: 437b91de9453a26a9603c7aad71ddc9ad5ab0870
SHA256: 16C6FC94503FE1DF80E68326B777EA8CCB57CB3A85453A082657875692156504
File Size: 3.87 MB, 3873792 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments Simple workspace tool for writers and makers.
Company Name Inkwell 69 Apps Inc.
File Description Studio Sketch for everyday maps.
File Version 4.11.398.47
Internal Name portfoliominiforlists
Legal Copyright Copyright 2022 Inkwell 69 Apps Inc.
Legal Trademarks Portfolio Mini for Lists is a mark of Inkwell 69 Apps Inc..
Original Filename portfoliominiforlists.exe
Product Name Portfolio Mini for Lists
Product Version 4.11.398.47

File Traits

  • fptable
  • x64

Block Information

Total Blocks: 1,371
Potentially Malicious Blocks: 330
Whitelisted Blocks: 656
Unknown Blocks: 385

Visual Map

x x 0 0 0 0 0 ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 ? 0 ? x ? 0 x x x x 0 x 0 x 0 0 x x 0 x 0 x x x x 0 x x x 0 0 0 x x 0 ? ? ? ? x x 0 0 0 ? ? ? ? ? x x x 0 x 0 x ? ? ? ? ? x x x 0 x 0 x x ? ? ? ? ? ? ? x ? ? ? ? ? x ? ? x 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 x 0 0 ? ? 0 ? ? ? ? ? ? ? ? x x x ? 0 0 x x x x 0 0 x x x 0 0 ? ? ? ? ? ? ? ? ? ? x ? ? ? x ? 0 x 0 0 x x x 0 0 ? 0 x ? ? ? x x 0 x x x 0 x x 0 x 0 x x 0 ? ? x x 0 x x ? ? ? ? ? ? ? ? x ? x x 0 0 x x x x 0 ? x ? x ? ? x 0 ? ? ? ? ? x x x x 0 x x x x 0 x ? ? ? ? ? ? x ? ? x 0 x x 0 x x x 0 x x ? ? ? ? ? x ? ? ? ? ? x x x ? x x 0 x ? x ? x 0 ? ? ? x x x ? x x x x 0 x 0 x x x x x 0 x x 0 x 0 0 0 x ? ? ? ? ? x x 0 x x 0 x ? ? ? ? ? x ? ? x ? x ? ? ? ? ? ? ? ? ? ? ? ? 0 x 0 x 0 ? ? ? ? ? x ? ? ? ? ? x x 0 x 0 x x x x x x x x x x x x 0 0 x x x x x x x 0 x 0 0 x x 0 x ? ? ? 0 ? ? ? x 0 ? ? ? x ? ? ? ? x x x ? 0 ? ? ? ? ? x x 0 0 x x x 0 x 0 x ? ? 0 0 x x ? ? ? x x ? ? x ? ? ? ? x x x x x x x 0 0 0 ? ? ? ? ? x x ? x x x x x x 0 0 ? ? ? x x x ? ? ? ? ? x 0 x 0 x 0 ? ? ? x x x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? x x ? x ? ? ? ? x x 0 ? ? ? ? ? ? ? ? ? ? ? x x x x 0 x x 0 0 x 0 x ? ? ? ? ? 0 0 x x 0 ? x x x x ? x ? ? ? x 0 0 ? ? 0 0 x x 0 x x 0 x x x ? ? ? x x x x 0 0 x x ? ? ? 0 0 ? ? ? x x 0 x 1 x ? ? ? 0 ? x x ? ? ? ? ? 0 0 ? ? ? 0 ? ? ? ? x ? x ? ? ? x ? 0 x x x 0 ? x x ? x x x 0 x x x x x x x 0 ? ? 0 0 0 0 0 0 0 0 0 1 x ? ? ? 0 0 ? x x x 0 0 0 x 0 0 x 0 x x 0 x 0 x 0 0 x 0 0 0 0 0 ? x ? 0 x x x x x 0 x x 0 x ? x ? ? x ? x ? x ? x ? x ? x ? x ? ? x ? x ? x ? x ? x ? x ? x ? x ? x ? x ? x ? x ? x ? x ? x ? x ? x ? x ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x 0 0 0 x 0 0 x 0 x x x x x 0 ? x x x x 0 0 x x 0 ? x x x 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 2 0 0 0 0 ? 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtClose
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
Show More
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN