Threat Database Trojans Trojan.Kryptik.UBNE

Trojan.Kryptik.UBNE

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 24,097
Threat Level: 80 % (High)
Infected Computers: 3,271
First Seen: June 19, 2023
Last Seen: May 23, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Kryptik.UBNE
Signature status: Hash Mismatch

Known Samples

MD5: fa47d6c8456647ca3677aedaf51ee5d1
SHA1: c2f7ad31e114459eb89d0cea36dc13329d3b2a6b
SHA256: EC7FC806FC0BEFCBFEE9C940418A6086CBCD0101C2A0289802BA5E284CE71140
File Size: 3.59 MB, 3590136 bytes
MD5: 679aeb332c9babf63dc30b8397ec226e
SHA1: 98b9c87ebfa13d86afd0c1687ada3ff76cb6a732
SHA256: D636A3ACE8B0EA2948EB50E609EFCA96EBEC80ABB67B3B2BE6CFFF5FCFF20B6F
File Size: 4.86 MB, 4861296 bytes
MD5: d26db2b3d79a0cac8c6236bdf97de50b
SHA1: c6225467e8ed0fd1b8be4a9189f33c0141348e62
SHA256: F9C9CB757F6D3F7C015D0F1F5A3B89E07AE37A336F52F259B8570F99E95E42D0
File Size: 531.78 KB, 531776 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Comments
  • Analogies microbe stiffly traced sketchpad
  • This is a legitimate application.
  • Tournament quadrant blackshirts milliners
Company Name
  • BHP Group
  • Hillock streaking
  • Restless ascorbic quietest
File Description
  • BHP Group Product
  • Falsebay toleration presupposition cuddled hermaphrodite lenders
  • Remarking abusive
File Version
  • 629
  • 8.258.196.5
  • 5.80.23.5
Internal Name
  • Boughs contribute
  • d2qvRE0YQLQN
  • Prunes surpassed
Legal Copyright
  • Copyright © Finances militarised hoarfrost pledged vanished
  • Copyright © Shelved liquid
  • © BHP Group All rights reserved.
Legal Trademarks
  • Detachable novelist cairo charioteers overshot faults
  • Subtracted tightest
  • © BHP Group Trademarks
Original Filename
  • iiD5rgCl.exe
  • Panda designating
  • Robust corrupting
Product Name
  • oStdQd64Xx
  • Reconnoitre heterogeneous
  • Understate
Product Version
  • 629
  • 8.258.196.5
  • 5.80.23.5

Digital Signatures

Signer Root Status
Adobe Inc. DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Hash Mismatch
Zoom Video Communications, Inc. DigiCert Trusted Root G4 Hash Mismatch
Sublime HQ Pty Ltd USERTrust RSA Certification Authority Hash Mismatch

File Traits

  • HighEntropy
  • x86

Block Information

Total Blocks: 330
Potentially Malicious Blocks: 5
Whitelisted Blocks: 325
Unknown Blocks: 0

Visual Map

x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 1 0 0 0 0 0 0 0 0 0 0 1 1 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 1 1 0 0 0 0 1 1 2 1 1 3 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 1 0 0 1 0 0 0 0 1 0 0 0 1 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 2 3 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 1 1 0 0 1 0 0 0 0 2 2 0 0 1 0 0 0 1 1 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 2 1
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Trending

Most Viewed

Loading...