Threat Database Trojans Trojan.Kryptik.NDO

Trojan.Kryptik.NDO

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 17,345
Threat Level: 80 % (High)
Infected Computers: 4
First Seen: September 1, 2026
Last Seen: September 16, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Kryptik.NDO
Signature status: No Signature

Known Samples

MD5: 86b3b9c2729f655973f5daae2bd950d7
SHA1: 872ee077de6ec8ab4c97d14fe72b2ca87e9c2509
SHA256: F500C4F4742D242322C5EA0841B2697D3D52F840164BC4677869F7FC4AC55B4E
File Size: 510.46 KB, 510464 bytes
MD5: c2cb3568780e8b3edbff6cedb65c8c5f
SHA1: e18660aee6763835673754460bb2c01210d72d1c
SHA256: D552833788186D0E9F83E5C99108AF7DA0A58639A9603781DA159D326BB25FE6
File Size: 512.51 KB, 512512 bytes
MD5: 2634e009d53c9d46e844e9cf5f76cc24
SHA1: ae8f2b836a88d21011b70ea59f1858fc1953376f
SHA256: 924D71459F98C2812860619DF6EB064E8EBD3A956BDACE0811BE9DE4DA11B5FF
File Size: 627.20 KB, 627200 bytes
MD5: b8cd36caac0a76b130fbcf8bc7505d3d
SHA1: bd6104fc95852889c097935e437a8ddd08c5ca34
SHA256: 7E135DC853EC165D659174B4B53F41D44052EBD33E6C2281677C81F82C6B7452
File Size: 587.78 KB, 587776 bytes
MD5: 41f22112a01cc43f7d1e11c4d2c161ec
SHA1: 6479ed039d32300d79973e33e2be421afad4d20c
SHA256: 4F433510F1411AD259512C45F877AE67CE94764AA4676A0A72763397B3AA26B6
File Size: 613.89 KB, 613888 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name
  • gluiethud s.p. z o.o
  • kraioftuent LLP
  • ompaiony LLC
  • uetchuntly LLC
  • uienkeetts LLC
File Version
  • 2.2.21.5248
  • 2.0.22.1986
  • 1.1.30.1611
  • 1.0.26.5316
  • 1.0.2.4704
Internal Name
  • Cieuttsienk.exe
  • Clauftauety.exe
  • eongiaotts.exe
  • shiuppaorly.exe
  • Zaoryeaff.exe
Original Filename
  • Cieuttsienk.exe
  • Clauftauety.exe
  • eongiaotts.exe
  • shiuppaorly.exe
  • Zaoryeaff.exe
Product Name
  • Cieuttsienk
  • Clauftauety
  • eongiaotts
  • shiuppaorly
  • Zaoryeaff
Product Version
  • 2.2.21.5248
  • 2.0.22.1986
  • 1.1.30.1611
  • 1.0.26.5316
  • 1.0.2.4704

File Traits

  • GetConsoleWindow
  • ntdll
  • x64

Block Information

Total Blocks: 425
Potentially Malicious Blocks: 7
Whitelisted Blocks: 404
Unknown Blocks: 14

Visual Map

x ? ? 0 0 1 x x ? ? 0 ? 0 0 ? ? 0 ? ? ? x x ? ? ? 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 2 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Kryptik.JUK
  • Kryptik.NDO
  • Trojan.Kryptik.Gen.FEJ
  • Trojan.Kryptik.Gen.INT
  • Trojan.Kryptik.Gen.ITP
Show More
  • Trojan.Kryptik.Gen.JFS
  • Trojan.Kryptik.Gen.JVE

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateSection
Show More
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryTimerResolution
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN