Threat Database Trojans Trojan.Kryptik.UFS

Trojan.Kryptik.UFS

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.Kryptik.UFS
Signature status: No Signature

Known Samples

MD5: 93d9f872885dd4d696945a9ffad3b3ef
SHA1: 9da620832de31c7f23c42e4d898631cd5b85e753
SHA256: 8A221BABF9B849A39E497851421A4A5104FA65BD0A759FAE899B1DF163B46258
File Size: 719.87 KB, 719872 bytes
MD5: 374d40495d2ffc6923bf26c82174ca5c
SHA1: c175c1f5efbef469fa831e6c6b9b1f3f10632aa2
SHA256: 057101DBC17C797ED801BD908A8B1CE6101F427BF36759E5A851B2C8C9B30899
File Size: 720.38 KB, 720384 bytes
MD5: c688aea1212f818d27d882b5bb2e3da8
SHA1: fddb4fee8648dd9a4ad10dfe872c0832a3de3fda
SHA256: 956AD2F4E3E194B80AC4B7CF05FBFAE237912E7B6814610A95850BB0F5257AD8
File Size: 719.87 KB, 719872 bytes
MD5: ff37d535b9fb00a7188e9e5fd09a45db
SHA1: c9ded82463f7f870e1bdddf2f8b090017a2fd62e
SHA256: 1461EB6DEF13D2DD0DDFA87C1E0AC2CE9F3D7EB7F16469C7754B67C30C4D8E63
File Size: 719.87 KB, 719872 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name
  • Cosmic Industries
  • Matrix Zenith Nano Digital Systems
  • Soft Nano Services
  • Timeless Apex Ageless League Solutions
File Description
  • Editor Swarm Powerful Flexible Matrix
  • Protected Aggregator Collector Tracker Precision
  • Quantum Leadership Proactive Adapter
  • Stream Automated Bridge
File Version
  • 79.12.752.81795
  • 56.28.376.41588
  • 23.83.159.9213
  • 15.8.603.90818
Internal Name
  • customizable_grid_mesh
  • exceptional_productive
  • proxy_standard_reader
  • set_interactive_loader
Legal Copyright
  • Copyright (C) 2019 Soft Nano Services
  • Copyright (C) 2020 Cosmic Industries
  • Copyright (C) 2020 Matrix Zenith Nano Digital Systems
  • Copyright (C) 2023 Timeless Apex Ageless League Solutions
Original Filename
  • excep.exe
  • sdkapp.exe
  • set_i.exe
  • subscriber.exe
Product Name
  • Customizable Grid Mesh Extractor
  • Exceptional Productive Super Hash Interpreter
  • Proxy Standard Reader
  • Set Interactive Loader
Product Version
  • 79.12.752.81795
  • 56.28.376.41588
  • 23.83.159.9213
  • 15.8.603.90818

File Traits

  • dll
  • HighEntropy
  • x64

Block Information

Total Blocks: 419
Potentially Malicious Blocks: 44
Whitelisted Blocks: 375
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 x 0 x x x x x 0 0 x x 0 0 x x 0 x 0 0 0 x 0 x 0 x 0 0 x x x 0 x 0 x x 0 x x 0 x x x x 0 0 0 x 0 0 0 x x x x 0 0 0 0 x 0 x x x x 0 0 0 x 0 0 0 x x x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.FDQ
  • Agent.FHM
  • Agent.KPJ
  • Agent.KPU
  • Agent.OFST
Show More
  • Agent.UFSD
  • Agent.UFSF
  • Kryptik.UFS
  • ShellcodeRunner.TT
  • Sonbokli.N
  • Spy.Agent.KP
  • Stealer.IFS
  • Trojan.Agent.Gen.ALE
  • Trojan.Agent.Gen.AOU
  • Trojan.ShellcodeRunner.Gen.Q

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
Show More
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Trending

Most Viewed

Loading...