Threat Database Trojans Trojan.Kryptik.WFD

Trojan.Kryptik.WFD

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 6,216
Threat Level: 80 % (High)
Infected Computers: 21
First Seen: May 19, 2026
Last Seen: August 2, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Kryptik.WFD
Signature status: No Signature

Known Samples

MD5: cd767ce65652543abba859040b4bceaf
SHA1: 752aa97f944956793d0fae231fc992a275689ce4
SHA256: F2BCA9210BEE15D2E4860BDDB490C7066A9E24A76CE338663D89462BD2CC6182
File Size: 9.67 MB, 9673183 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name Bedwarfs Inc
File Description Microsoft authentication package v1.0. windows nt base api server dll.
File Version 83.99.86.61
Internal Name facl
Legal Copyright Copyright (C) 2030 Bedwarfs Inc
Original Filename facl
Product Name facl
Product Version 83.99.86

File Traits

  • 2+ executable sections
  • big overlay
  • dll
  • HighEntropy
  • ntdll
  • upx
  • x86

Block Information

Total Blocks: 2
Potentially Malicious Blocks: 2
Whitelisted Blocks: 0
Unknown Blocks: 0

Visual Map

x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Kryptik.WR

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\752aa97f944956793d0fae231fc992a275689ce4_0009673183.,LiQMAxHB