Threat Database Trojans Trojan.Kryptik.PFV

Trojan.Kryptik.PFV

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.Kryptik.PFV
Signature status: No Signature

Known Samples

MD5: a90cd7c40e1325e9dc338a0aa4017c69
SHA1: d9630985b1be9dcd413cab7ac9369441b9852682
SHA256: BFFB6D43F1ECA311BDE42003F26CF51F2A77B3053231A67597E070C7933A77D8
File Size: 937.47 KB, 937472 bytes
MD5: aeaa11a7440d984d27d1eaefdeaaa328
SHA1: 2a8cbcc52fd5ad93b35872ea6b9517bf159e6019
SHA256: 59F50671EB946D43638043B941A5F9A659C8EE7B6B6B380B7E02F8EF8BF477D8
File Size: 1.10 MB, 1103872 bytes
MD5: 041f99f6dd43a5fe666762320c312988
SHA1: 0a0338d23e9e93446a29a6221098af36e8097944
SHA256: 598B8D4371C8B905C3C5E004EA9EA7CACFA9F62ABD6E62050DC1C9ADAB140D54
File Size: 878.59 KB, 878592 bytes
MD5: 9efa1f607296181cce7052aab5321111
SHA1: f7f621e6ef7e1175af09e34dc679d940b3a4c871
SHA256: B27F20D64996B72D42B5F6142BB02B1BDC96620CB0D01BC262F3D7F977A67122
File Size: 1.04 MB, 1041408 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • HighEntropy
  • No Version Info
  • x64

Block Information

Total Blocks: 515
Potentially Malicious Blocks: 85
Whitelisted Blocks: 430
Unknown Blocks: 0

Visual Map

x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x 0 0 0 0 x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.KPEE
  • Agent.PGT
  • ClipBanker.FG
  • CobaltStrike.XAA
  • Exploit.X
Show More
  • Kryptik.DTGC
  • Kryptik.JUB
  • Kryptik.OSA
  • Kryptik.PFU
  • Kryptik.PFV
  • Kryptik.UP
  • Phant0m.A
  • ShellcodeRunner.KA
  • Spy.Agent.KGB
  • Trojan.Agent.Gen.ACR
  • Trojan.Agent.Gen.ADC
  • Trojan.Agent.Gen.ADD
  • Trojan.Agent.Gen.AIR
  • Trojan.Agent.Gen.V

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetComputerName
  • GetUserName
  • GetUserObjectInformation

Trending

Most Viewed

Loading...