Threat Database Trojans Trojan.Kryptik.NFYB

Trojan.Kryptik.NFYB

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.Kryptik.NFYB
Signature status: Hash Mismatch

Known Samples

MD5: 57007950791e9e4a09fb09cc0cf6ac15
SHA1: b1f47e7bea3efea9cdb1217ba1ebd2b9e796cb36
SHA256: 1590F5BC877168396A099A8726B2922C2F5FC4116C047719FCA6A315CA33BA2A
File Size: 609.66 KB, 609656 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name PERPLEXITY AI, INC.
File Description Comet Updater (x64)
File Version 147.0.7727.1860
Product Name Comet Updater (x64)
Product Version 147.0.7727.1860

Digital Signatures

Signer Root Status
PERPLEXITY AI, INC. GlobalSign Code Signing Root R45 Hash Mismatch

File Traits

  • fptable
  • HighEntropy
  • WriteProcessMemory
  • x64

Block Information

Total Blocks: 521
Potentially Malicious Blocks: 191
Whitelisted Blocks: 309
Unknown Blocks: 21

Visual Map

x x x x x x x x ? 0 x 0 x x 1 x x x x 0 x x x x x x x x x x x x x x ? ? x 1 x x x x x x x x x x x x x x x x x x x 0 x x x x 0 x x x x x x x x x x x x x x 0 0 0 x x x x x 0 x 0 0 x x x 0 x x 0 ? x x x 0 x x x x x x 0 x 0 0 0 0 x x 0 0 0 x x x x x x x x x 0 x x x x x 0 0 0 x 0 x x x 0 0 x x x x x x 0 0 x x x 0 0 x x x x 0 x 0 x x 0 x 0 x x x x x x x x x 0 0 x 0 x x x x x x x x 0 0 0 x x x 0 0 0 x x x x x x 0 x x x x 0 0 x x x x x x x 1 x x x x x x x x 0 x x x x 1 x x x x x 0 x x x x 0 x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 ? ? 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 2 0 2 0 0 0 ? 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Kryptik.NFYB

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAddAtomEx
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
Show More
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN
User Data Access
  • GetComputerName
  • GetUserName