Threat Database Trojans Trojan.Kryptik.UBNC

Trojan.Kryptik.UBNC

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 13,060
Threat Level: 80 % (High)
Infected Computers: 721
First Seen: May 20, 2023
Last Seen: February 2, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Kryptik.UBNC
Signature status: No Signature

Known Samples

MD5: 763b1e750166789632d83dda80e3bf43
SHA1: 2454faecab6dfeeb5ff2a9a199fd61a023c81298
SHA256: D5C04C5ADB4546274D071059121725AC3BBCA1A745F30073DB7A6D80BBD70FFA
File Size: 744.57 KB, 744566 bytes
MD5: 78aea0ff68839985c119fb33f4a9f610
SHA1: b889b22bef1c2be6b9aebf5571ac8d520927b257
SHA256: EE44FB625FF3E9BAE45B5B131B600E2D2B902B4C249AE21370F8E0CA6BA4AA90
File Size: 235.52 KB, 235520 bytes
MD5: c50cc7f2aff77c463b4ef5f59f6f5beb
SHA1: af5339f740976ca8cec85464b6db74f79fe025db
SHA256: 235ABCB40178218EFF04A64CB9384AE7AC3B2F511F2F8449A2551C5C297DD4C7
File Size: 286.72 KB, 286720 bytes
MD5: d69619f516ed6c04dcfccedd3aa5fd53
SHA1: cfd164dcb91431fb35e1bfe859d200c9459b56c3
SHA256: 3D85411BFDC70273D1FF6D722D488CC36C7347F3D33DF8E0FDD3C870376912C0
File Size: 2.11 MB, 2109879 bytes
MD5: fd35fe4b8abfb8237878280391fb9265
SHA1: f8568bbd21d219f277ce312010bbbef42d037f0d
SHA256: FB7D567CAD6C32AE40DA74D64133365C553D09FB4850A601B911A5A6C374105B
File Size: 3.06 MB, 3058255 bytes
Show More
MD5: a031add3f7b2e60de5be34774d3f9c1c
SHA1: 5542a4a5a46a50c7d71b9e6fad5dc584b0d34bf8
SHA256: 2E99036204F439F1F9EF8B78CECD0DE21F8953E04F9E471BDEB78400D54D2457
File Size: 283.65 KB, 283648 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments This installation was built with Inno Setup.
Company Name
  • cashinotech
  • Receipt_POS_WIN
File Description
  • DriverInstall Module
  • Install Module
  • KPOSSeries
  • POS104Install Module
  • POSPrinter
File Version
  • 1.30
  • 1.26
  • 1, 0, 0, 1
  • 1, 0, 0, 0
Internal Name
  • DriverInstall
  • Install
  • POS104Install
Legal Copyright
  • Copyright 2019
  • Copyright 2022
  • Copyright 2023
  • Copyright© 2019 cashinotech.com
  • Copyright© 2024
Original Filename
  • DriverInstall.exe
  • Install.exe
  • POS104Install.exe
Product Name
  • DriverInstall Module
  • Install Module
  • KPOSSeries
  • POS104Install Module
  • POSPrinter
Product Version
  • 1.30
  • 1.26
  • 1, 0, 0, 1
  • 1, 0, 0, 0

File Traits

  • Installer Version
  • x86

Block Information

Total Blocks: 1,375
Potentially Malicious Blocks: 1
Whitelisted Blocks: 1,222
Unknown Blocks: 152

Visual Map

? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? 0 ? 0 ? ? ? ? ? ? 0 0 0 ? ? 0 0 0 ? ? ? 0 0 ? ? ? ? 0 0 ? ? ? ? 0 0 ? ? 0 0 ? ? ? 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? 0 ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? 0 0 ? ? ? 0 0 0 0 0 ? 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? 0 0 0 ? ? 0 ? 0 ? 0 0 ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? x 0 ? ? 0 ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 1 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 1 1 1 1 2 2 2 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 2 0 0 0 0 0 1 0 0 0 0 0 0 1 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 1 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 1 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 2 3 1 1 3 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 1 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 1 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 1 0 0 1 0 0 2 2 0 0 1 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 0 1 0 0 0 1 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\program files\winmount Synchronize,Write Attributes
c:\program files\winmount\__tmp_rar_sfx_access_check_3161640 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files\winmount\config.ini Generic Write,Read Attributes
c:\program files\winmount\config.ini Synchronize,Write Attributes
c:\program files\winmount\feedback.exe Generic Write,Read Attributes
c:\program files\winmount\feedback.exe Synchronize,Write Attributes
c:\program files\winmount\frameext Generic Write,Read Attributes
c:\program files\winmount\frameext Synchronize,Write Attributes
c:\program files\winmount\frameext\browser.dll Generic Write,Read Attributes
c:\program files\winmount\frameext\browser.dll Synchronize,Write Attributes
Show More
c:\program files\winmount\frameext\mountplug.dll Generic Write,Read Attributes
c:\program files\winmount\frameext\mountplug.dll Synchronize,Write Attributes
c:\program files\winmount\moucoreui.dll Generic Write,Read Attributes
c:\program files\winmount\moucoreui.dll Synchronize,Write Attributes
c:\program files\winmount\moumaker.dll Generic Write,Read Attributes
c:\program files\winmount\moumaker.dll Synchronize,Write Attributes
c:\program files\winmount\winmount.chm Generic Write,Read Attributes
c:\program files\winmount\winmount.chm Synchronize,Write Attributes
c:\program files\winmount\winmount.exe Generic Write,Read Attributes
c:\program files\winmount\winmount.exe Synchronize,Write Attributes
c:\program files\winmount\wmcommon.dll Generic Write,Read Attributes
c:\program files\winmount\wmcommon.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\is-40o7s.tmp\_isetup\_setup64.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\is-i9sml.tmp\cfd164dcb91431fb35e1bfe859d200c9459b56c3_0002109879.tmp Generic Write,Read Attributes

Windows API Usage

Category API
Keyboard Access
  • GetKeyState
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
User Data Access
  • GetUserObjectInformation

Shell Command Execution

"C:\Users\Xvicshab\AppData\Local\Temp\is-I9SML.tmp\cfd164dcb91431fb35e1bfe859d200c9459b56c3_0002109879.tmp" /SL5="$13014C,1268787,831488,c:\users\user\downloads\cfd164dcb91431fb35e1bfe859d200c9459b56c3_0002109879"

Trending

Most Viewed

Loading...