Threat Database Trojans Trojan.Kryptik.RV

Trojan.Kryptik.RV

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.Kryptik.RV
Signature status: No Signature

Known Samples

MD5: a4396d90f3bfc54f2cfc6519f2cda36d
SHA1: 26bdb315d7d394ea8f5084a28c0d1dcde24c5775
SHA256: 07DD1B95B959BFD0D9399F0ED3C06CDD05BD07EDA2D441891FB5FCD07B7B8BDC
File Size: 368.64 KB, 368640 bytes
MD5: 808c0914127b6052f51bd7e7a5073c28
SHA1: ce84fe0253ef85196f003eef08da53ec3ca2cbb1
SHA256: DCF21AD220A9E7A70C7BD52B061FC86F296069F8984F03861AFBC1ACC14D36C5
File Size: 370.69 KB, 370688 bytes
MD5: b089bc4cd6757ab1542bea723bedd30d
SHA1: 89cd94f77e9c4169bbf234d0071647bb2ecacd7b
SHA256: 5739313481983142DC798F8DEFD3A25727F511DDD84F1286A1C121C9636E04FB
File Size: 768.00 KB, 768000 bytes
MD5: b6a1983e9ac2ff30aafd452491d5ba7d
SHA1: ec5f53c450a36be18a7d9a3b344270b30cf32d17
SHA256: 9BB15F10E60B10707B4F1FDC44298BB8A7A0DF0F88C3BC40AA7D34A576466B9C
File Size: 588.29 KB, 588288 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have resources
  • File doesn't have security information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • HighEntropy
  • No Version Info
  • x64

Block Information

Total Blocks: 540
Potentially Malicious Blocks: 44
Whitelisted Blocks: 496
Unknown Blocks: 0

Visual Map

x 0 x x x 0 x x 0 x x x x 0 x 0 x x x x 0 x x x 0 x x 0 x 0 x x 0 x 0 x x 0 0 0 0 x 0 x x x x x x x 0 x 0 0 0 0 x x x x x x x x 0 0 x 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.OGGB
  • Agent.TBD
  • Agent.TBF
  • BadIIS.I
  • CobaltStrike.XLC
Show More
  • CobaltStrike.XLF
  • Downloader.GDS
  • Farfli.XC
  • Kryptik.DSK
  • ShellcodeRunner.KB
  • ShellcodeRunner.TWE
  • Trojan.Agent.Gen.ADI
  • Trojan.Agent.Gen.DZ
  • Trojan.Agent.Gen.EL
  • Trojan.Agent.Gen.TL
  • Trojan.Kryptik.Gen.AVE
  • Trojan.ShellcodeRunner.Gen.GF

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationWorkerFactory
Show More
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState

Related Posts

Trending

Most Viewed

Loading...