Threat Database Trojans Trojan.Kryptik.VGSA

Trojan.Kryptik.VGSA

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 4,986
Threat Level: 80 % (High)
Infected Computers: 63
First Seen: February 9, 2026
Last Seen: May 30, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Kryptik.VGSA
Packers: UPX!
Signature status: No Signature

Known Samples

MD5: 3fe8b7cb92d6715e44263a4c2360ff83
SHA1: 0d735c4f0403d97d94eb55b12358ebfa63216cb6
SHA256: 9615BA52930A5CA605D4AC46C064D69E4A6579E33226365631F7A6D20FB6820B
File Size: 7.92 MB, 7920684 bytes
MD5: f2a6af1869eae97c27bbb32b4de91dcf
SHA1: ba98579467ef345e71cac0f48f5cd286adaf6f80
SHA256: 372D2FB87062294BEF89362BC8E0F6CDAD13377750EE96FFB9FEC4F1CF3EC9A6
File Size: 9.81 MB, 9810024 bytes
MD5: d5f6e2675bf463a3b7fb7ce8b581f6b8
SHA1: 319403d89aafe8a4d18631868c0f258a5c7e0970
SHA256: 2657DFA0909CBF6CE9A63A16B6E79465E8CD4ACB1ACF83F6119D46B842A6BC49
File Size: 9.81 MB, 9811595 bytes
MD5: afdb24b7cec61b0e0ca6d5b9fe191127
SHA1: 0d528488939f1c3c2c586dcf189d5a4a7cc56290
SHA256: 8C4C92A36CA374C2403E606A4EB88D798F24ED5418EA6D3780DEE96988E5A6D9
File Size: 9.81 MB, 9808316 bytes
MD5: 5c294857d6cc4ecce77c749992d47329
SHA1: d03da10782ab49bb3ef9655928c7afa8f48351c5
SHA256: F96EB4712F172963BF13FC81D7617AD9A7B22DCA04048F3C03301BBC9BF29664
File Size: 8.66 MB, 8663040 bytes
Show More
MD5: 495bb631fd702ed0e41f224ef7926f1e
SHA1: b12eba3f47a71b25ca22feaf3e11828412bee605
SHA256: C024EA8B3A6B3FB4009971FFFE3839930406E1F5AF4569E4FC748B94C95C340B
File Size: 7.94 MB, 7938967 bytes
MD5: 34a9ffc06002648599c4b99383d8710f
SHA1: 61cac89fd69cbdc65788602fb5cdd02b46a4d43d
SHA256: 237474F6831CBDC363B5104EF8BFE45CFC4873299CF539DED748287C573F4E56
File Size: 5.47 MB, 5467136 bytes
MD5: 0e8a9c2ddeb893f13e71b562b6a9ebc5
SHA1: 54747d2b15081ec4d98feb3489a0509a8d17941d
SHA256: 660BA64A22CAD661DAC62BAF9454426626F7DE7DC36348501183EA3068125250
File Size: 7.19 MB, 7190528 bytes
MD5: 811a2ced7c3eb4e1a256afe1f7ba5e1a
SHA1: 88cba63f20fc8a1278c4b963f6af41983f87bbc2
SHA256: B4051319C625C4C5C6FAA6DA7A0D4A990AA2AB06373C3582BE9932718ADA6A5B
File Size: 8.22 MB, 8224167 bytes
MD5: 2cd7df5d92352c3e5a7e178ec9325170
SHA1: 423d619b992ff11193a2063e6bf7c8813fde6cc1
SHA256: 0E7C20608403C9819B4B47EA03779E634C1DF60EC792B0A8505BF5E111FA53A3
File Size: 5.34 MB, 5343232 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have security information
  • File has been packed
  • File has exports table
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name
  • Cess grice LLC
  • Cloud flare Ltd
  • Future systems
  • Harn siser GmbH
  • Labs Co
  • NanoTech Analytics
  • Nexlify Ventures
  • Smart Adimich so
  • Stoppit AG
  • Velaria Bubblement
File Description
  • Flatbed scanner still image devices client dll. media foundation proxy dll.
  • Host for thunking apis from 32-bit to 16-bit metafile conversion dll.
  • Host process for windows portable device class extension for pl080 dma controller.
  • Microsoft odbc desktop driver pack 3.5. ole db core services resources.
  • Nvidia compiler, version 566.24. nvidia optical flow api, version 566.24. nvidia cuda 12.7.33 opencl 1.2 driver, version 566.24. nvidia cuda driver, version 566.24. nvidia d3d10 driver, version 566.24. nvidia video server.
  • Printer settings user account control panel applet; network id page.
  • Provides infrastructure Support for windows portable device shell service object.
  • Smart card key storage provider for system resource usage monitor service.
  • Windows connect now - config function discovery print provider dll.
  • Workstation service plugin, version 566.24. nvidia driver, version 566.24. nvidia vgpu config service, version 566.24.
File Version
  • 99.46.21.68
  • 83.44.28.57
  • 64.32.83.74
  • 59.23.6.18
  • 49.95.60.42
  • 35.15.19.82
  • 34.2.7.79
  • 33.47.0.59
  • 32.85.64.85
  • 4.78.4.95
Internal Name
  • build
  • cert64
  • db_tunix
  • enumsystericher
  • findows_amd64-w
  • hellcontesschec
  • ll
  • mslog
  • mv
  • sampromeldgent
Legal Copyright
  • Copyright (C) 2017 Labs Co
  • Copyright (C) 2025 Future systems
  • Copyright (C) 2077 Stoppit AG
  • Copyright 2023-2024 Cloud flare Ltd
  • Copyright © 2041 Nexlify Ventures
  • Copyright © 2061 NanoTech Analytics
  • Copyright © 2061 Smart Adimich so
  • Copyright © 2062 Cess grice LLC
  • © 2033 Harn siser GmbH. All rights reserved.
  • © 2059 Velaria Bubblement. All rights reserved.
Original Filename
  • build
  • cert64
  • db_tunix
  • enumsystericher
  • findows_amd64-w
  • hellcontesschec
  • ll
  • mslog
  • mv
  • sampromeldgent
Product Name
  • build
  • cert64
  • db_tunix
  • enumsystericher
  • findows_amd64-w
  • hellcontesschec
  • ll
  • mslog
  • mv
  • sampromeldgent
Product Version
  • 99.46.21
  • 83.44.28
  • 64.32.83
  • 59.23.6
  • 49.95.60
  • 35.15.19
  • 34.2.7
  • 33.47.0
  • 32.85.64
  • 4.78.4

File Traits

  • 2+ executable sections
  • big overlay
  • dll
  • HighEntropy
  • ntdll
  • packed
  • vlizer
  • x64

Block Information

Total Blocks: 7,963
Potentially Malicious Blocks: 168
Whitelisted Blocks: 6,699
Unknown Blocks: 1,096

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 x 0 x 0 0 0 0 x 0 0 0 0 0 ? x x x ? ? 0 x x 0 ? 0 0 0 0 ? x x x ? 0 x 0 x 0 ? ? ? 0 ? 0 0 ? 0 0 ? x ? 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 ? 0 0 0 0 0 x 0 0 x 0 x 0 0 0 ? ? x ? x 0 0 0 0 0 0 0 0 0 0 x x x x 0 x x 0 0 0 0 0 0 0 0 0 x x x x x 0 0 0 0 0 0 0 0 0 0 0 x x x 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • ClipBanker.XC
  • Kryptik.VGR
  • Kryptik.VGSA
  • Kryptik.VGT
  • ShellcodeRunner.LLB
Show More
  • ShellcodeRunner.THA
  • Spy.Agent.LLA
  • Trojan.Agent.Gen.BTQ
  • Trojan.Filecoder.Gen.DB

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
Show More
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Trending

Most Viewed

Loading...