Threat Database Trojans Trojan.Kryptik.LSB

Trojan.Kryptik.LSB

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 470
Threat Level: 80 % (High)
Infected Computers: 653
First Seen: January 1, 2026
Last Seen: July 20, 2026
OS(es) Affected: Windows

The detection of Trojan.Kryptik.LSB on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the security and integrity of your computer, and it's essential to understand its nature and take steps to remove it.

What Is Trojan.Kryptik.LSB?

Trojan.Kryptik.LSB is a type of Trojan horse malware, which is a broad category of malicious software that disguises itself as legitimate programs. The name "Trojan" refers to the malware's ability to deceive users into installing it on their systems, often by masquerading as a harmless or useful application. The specific name "Kryptik.LSB" suggests that this malware may be related to encryption or other malicious activities, but without further information, it's difficult to determine its exact nature or purpose.

How Trojan.Kryptik.LSB Operates

Trojan horses like Trojan.Kryptik.LSB typically operate by exploiting vulnerabilities in software or deceiving users into installing them. Once installed, they can perform a variety of malicious activities, such as stealing sensitive information, installing additional malware, or providing unauthorized access to the infected system. Trojan.Kryptik.LSB may also attempt to communicate with its creators or other malicious servers to receive updates or transmit stolen data.

Symptoms of Infection

Systems infected with Trojan.Kryptik.LSB may exhibit a range of symptoms, including slow performance, unexpected crashes, or unusual network activity. Users may also notice suspicious programs or processes running in the background, or receive unexpected pop-ups or alerts. However, some Trojans can operate silently, making it difficult to detect their presence without the aid of security software.

How to Remove Trojan.Kryptik.LSB

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for easier removal.
  2. Run a full scan with a reputable anti-malware tool, such as SpyHunter, to detect and remove all instances of the malware.
  3. Uninstall any suspicious programs or applications that may be related to the malware.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and run another full scan to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.Kryptik.LSB from your system requires careful attention to detail and a thorough understanding of the malware's behavior. By following the steps outlined above and using reputable security software, you can help protect your system and prevent further damage. It's essential to remain vigilant and take proactive steps to prevent future infections, such as keeping your operating system and software up to date, using strong passwords, and avoiding suspicious downloads or links.

Analysis Report

General information

Family Name: Trojan.Kryptik.LSB
Signature status: No Signature

Known Samples

MD5: e91ebe4fbbc0529c3b2498b37fbfda9f
SHA1: 8cb3c2c858b196d5169f4f04ebd231b598b4a1be
SHA256: 79D001D64E79E5DEB4116A5DBAD7D2B1263E6851826E5B5344FAE74D3C372D3B
File Size: 1.06 MB, 1058816 bytes
MD5: 41ed4f3fa80baa8e7d9a25ca1b12c991
SHA1: c82a3c80956adf63ed3babb9db1de25c898febbf
SHA256: 65B9B1043CCA9DEDCEBE6FA29FD36A15B0942F786B1B3B5F233D8B7F97FA42E9
File Size: 355.33 KB, 355328 bytes
MD5: 573a13444aa442a6e993162f77d49e4c
SHA1: 591d2da653a13182e00f13282c30d2994d4de377
SHA256: 75857081A93BA31FDFDB292E7886E397F37ED59272FF9E0AF381EBFE5B83A90D
File Size: 3.46 MB, 3457024 bytes
MD5: 41d5627a365fffee058a2f2373ff2133
SHA1: ab17ccae05b67d389a11c754f8fcbc730c7cc30c
SHA256: EADB1885E3EBA87848D9FDF1888753DD2E2B16D160805E5D31CCE3C94C335890
File Size: 3.84 MB, 3837440 bytes
MD5: 02f817b22a1edb971480f16b1865b224
SHA1: f76fbce151777e457fd112fa378f793d250e4c15
SHA256: 038A99D3086D0964144291275DA99621314C2DE5C6628AF6708AFE3AF8992572
File Size: 4.69 MB, 4694528 bytes
Show More
MD5: 836271cb9c4a08ff16147bcae100c63e
SHA1: 6bd5617a7bc488fc788fe7e99b361c38c4daf57f
SHA256: 6B4839E186A4EA733A7837465E7FD0B74412FC58E9390AB666DE7BB830310117
File Size: 354.82 KB, 354816 bytes
MD5: 09e4a2003789d43e13a09c3ae443cd8f
SHA1: 9a2902b289e9442b8389c933d3f965ea205a4f01
SHA256: 3B5E378EC1F0344985B1C2C6D732951AB253CC621E03BA3D07BEBB68D9EF9B90
File Size: 637.16 KB, 637165 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have resources
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments Automatic hardware driver update tool
Company Name
  • Mythic Mounts
  • Notion Labs, Inc.
File Description
  • Advanced mobility script for enhanced movement techniques.
  • mixnewmain
  • Notion
  • ugo-cheaves
File Version
  • 1.1.0
  • 1.00
  • 0.1.0
Internal Name
  • GriffinMount
  • Notion
  • TJprojMain
Legal Copyright
  • Copyright © 2024-2025 Mythic Mounts
  • Copyright © 2026 Notion Labs, Inc.
Legal Trademark Mythic Mounts™
Original Filename
  • GriffinMount.exe
  • Notion.exe
  • TJprojMain.exe
Product Name
  • Griffin Mount
  • mixnewmain
  • Notion
  • Project1
  • ugo-cheaves
Product Version
  • 1.1.0
  • 1.00
  • 0.1.0

File Traits

  • fptable
  • HighEntropy
  • No Version Info
  • ntdll
  • x86

Block Information

Similar Families

  • Fsysna.M
  • Gamehack.GJE
  • Krypt.KBAJ
  • Kryptik.LSB
  • Kryptik.OSBE
Show More
  • Trojan.Kryptik.Gen.BFT

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\programdata\svc_3a1256fa.log Read Attributes,Synchronize,Read Control,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\payload_debug.log Read Attributes,Synchronize,Read Control,Write Attributes,Write extended,Append data

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ﹠끇ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 풾횈ﭴǜ RegNtPreCreateKey

Windows API Usage

Category API
Network Winhttp
  • WinHttpConnect
  • WinHttpOpen
  • WinHttpOpenRequest
  • WinHttpSendRequest
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • NtWriteVirtualMemory
  • VirtualAllocEx
Process Shell Execute
  • CreateProcess
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
Show More
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Process Terminate
  • TerminateProcess
Other Suspicious
  • SetWindowsHookEx

Shell Command Execution

C:\Windows\System32\dism.exe (NULL)

Trending

Most Viewed

Loading...