Threat Database Trojans Trojan.Kryptik.UBR

Trojan.Kryptik.UBR

Trojan.Kryptik.UBR is a detection name used by security software to identify a trojan horse threat that has been packed or obfuscated in a way that makes it difficult for antivirus engines to analyze right away. The "Kryptik" label generally refers to a family of trojans that rely on code obfuscation or encryption to hide their true purpose from security tools, rather than describing one single piece of malware with a fixed function. Because specific technical details about this particular detection are not fully documented, this article describes the typical behavior associated with threats in this category so you can understand the general risks and how to respond.

What This Threat Does

Like most trojans, Trojan.Kryptik.UBR is designed to disguise itself as a legitimate or harmless file while secretly carrying out malicious actions in the background. Trojans in this family commonly act as a delivery mechanism for other malicious components, meaning the initial detection may only be the tip of the iceberg. Typical actions associated with Kryptik-family trojans include downloading and installing additional malware, modifying system settings, attempting to disable or interfere with security software, and collecting information from the infected device. Some variants may also try to establish a connection to a remote server controlled by attackers, allowing further instructions or payloads to be delivered to the compromised machine.

How It Usually Gets Onto Computers

Trojans of this type typically spread through deceptive methods rather than by exploiting a single specific vulnerability. Common infection paths include malicious email attachments disguised as invoices, receipts, or documents; bundled downloads from unofficial or pirated software sources; fake software updates or cracked program installers; and malicious links shared through phishing messages or compromised websites. Because the malware is obfuscated, it can slip past less thorough scans or appear as an unfamiliar, hard-to-identify file until a security tool flags it based on behavior or heuristic analysis.

Risks for the User

An active trojan infection can expose users to a range of risks. These commonly include theft of personal or financial information, unauthorized access to the system by remote attackers, degraded system performance due to background malicious processes, and the installation of additional threats such as ransomware, spyware, or adware. In some cases, infected systems may be added to a larger network of compromised machines used for further criminal activity. The exact impact depends on the specific payload the trojan delivers, which can vary between infections even when they share the same detection name.

Signs of Infection

Because trojans are built to operate quietly, visible symptoms are not always obvious. However, users may notice warning signs such as unexpected slowdowns, unfamiliar processes running in the task manager, changes to browser or system settings that were not made intentionally, unusual network activity, or security software repeatedly flagging the same file or location. Frequent crashes or unexpected pop-ups can also indicate a deeper compromise.

How to Stay Protected

To reduce the risk of infections like Trojan.Kryptik.UBR, avoid downloading software from unofficial sources, be cautious with email attachments and links from unknown senders, and keep your operating system and applications updated. Running regular full-system scans with reputable security software, enabling automatic threat detection, and maintaining backups of important files can also help minimize damage if an infection does occur. If a detection appears, it is best to let your security software quarantine or remove the file and to review your system for any additional suspicious activity afterward.

Analysis Report

General information

Family Name: Trojan.Kryptik.UBR
Signature status: No Signature

Known Samples

MD5: ef82adf68e32f7e2539ad81d026ea5a5
SHA1: abadaef511ee7ab3329685ba15d267914083f73a
SHA256: D39D472AB15F807A71AC1B86D09031D8B1508B64C5D9D31DBEF71A618F37C32A
File Size: 535.04 KB, 535040 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • Microsoft Corporation
File Description
  • Win32 Cabinet Self-Extractor
  • Самоизвлечение CAB-файлов Win32
File Version
  • 11.00.17763.1 (WinBuild.160101.0800)
Internal Name
  • Wextract
Legal Copyright
  • © Microsoft Corporation. All rights reserved.
  • © Корпорация Майкрософт. Все права защищены.
Original Filename
  • WEXTRACT.EXE .MUI
Product Name
  • Internet Explorer
Product Version
  • 11.00.17763.1

File Traits

  • 2+ executable sections
  • HighEntropy
  • No Version Info
  • x86

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\dnx74.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\dnx74.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\lrh86.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\lrh86.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\tmp4351$.tmp Generic Write,Read Attributes,Delete

Registry Modifications

Key::Value Data API Name
HKLM\software\wow6432node\microsoft\windows\currentversion\runonce::wextract_cleanup0 rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Ogzblasn\AppData\Local\Temp\IXP000.TMP\" RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess

Shell Command Execution

C:\Users\Ogzblasn\AppData\Local\Temp\IXP000.TMP\dnX74.exe