Threat Database Trojans Trojan.Kryptik.TA

Trojan.Kryptik.TA

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 19,528
Threat Level: 90 % (High)
Infected Computers: 5
First Seen: July 24, 2009
Last Seen: September 14, 2025
OS(es) Affected: Windows

Aliases

10 security vendors flagged this file as malicious.

Antivirus Vendor Detection
NOD32 probably unknown NewHeur_PE
BitDefender Trojan.Crypt.Delf.X
Symantec Trojan Horse
Panda Generic Trojan
Ikarus Backdoor.Win32.Advertor
F-Secure W32/Malware
CAT-QuickHeal Trojan.Delf.f
BitDefender Trojan.Crypt.Delf.F
AVG Generic10.TKG
AntiVir TR/Crypt.Delf.F.42

File System Details

Trojan.Kryptik.TA may create the following file(s):
# File Name MD5 Detections
1. msmmsgr.exe 17310505a4591823eaf477a8e6c08114 0
2. Nvsvc32.exe 7fe03524ded0ecf85bb42edc28803082 0

Analysis Report

General information

Family Name: Trojan.Kryptik.TA
Signature status: No Signature

Known Samples

MD5: 4a5606c4f756d43a948d75ff3d5274db
SHA1: 5c00c0881143d6c9710730aba196d96257ff715d
SHA256: 2F0D9A104281B79111B9A9E348C09DAD0D77E5614B181D1056928CF064B6E0C5
File Size: 679.94 KB, 679936 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Comments Blow
Company Name Fast Solver
File Description Light Planet
File Version 9.3.9801.8719
Internal Name represent.dll
Legal Copyright ©2014 Fast Solver, All rights reserved
Product Name Light Planet
Product Version 9.3.9801.8719

File Traits

  • dll
  • x86

Block Information

Total Blocks: 172
Potentially Malicious Blocks: 17
Whitelisted Blocks: 155
Unknown Blocks: 0

Visual Map

x x 2 0 0 1 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 3 0 0 1 0 0 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 1 1 1 0 1 0 0 0 0 2 0 0 1 1 x x x x x x x x x x 0 0 x 0 x x x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtProtectVirtualMemory
Show More
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\5c00c0881143d6c9710730aba196d96257ff715d_0000679936.,LiQMAxHB

Trending

Most Viewed

Loading...