Threat Database Trojans Trojan.MSIL.Kryptik.AFB

Trojan.MSIL.Kryptik.AFB

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 17,313
Threat Level: 80 % (High)
Infected Computers: 3
First Seen: May 2, 2026
Last Seen: August 21, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.MSIL.Kryptik.AFB
Signature status: No Signature

Known Samples

MD5: 2722a279912136b74cb00d807eab1cdf
SHA1: 491a7e337ec72fe2915cb6fb3f219f2b723cf30b
SHA256: 3585CEAA1C7A90F482D14458D8F78B9C3C762D09D3C0503276C3DAF77347023E
File Size: 1.31 MB, 1307648 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 6.17.9024.6796
Comments EnablingTitanicSingular
Company Name CulturedContractualGamespyDominanceDresden
File Description LoweringVirtuesImporters
File Version 6.17.9024.6796
Internal Name RegistrantTelevisionTelefloraRecreation_ObituaryCarrierApocalypseIntimateCastles.exe
Legal Copyright Copyright © 2026
Original Filename RegistrantTelevisionTelefloraRecreation_ObituaryCarrierApocalypseIntimateCastles.exe
Product Name CustomizedTransistorOffenderTravelocity
Product Version 6.17.9024.6796

File Traits

  • .NET
  • SmartAssembly
  • x86

Block Information

Total Blocks: 164
Potentially Malicious Blocks: 12
Whitelisted Blocks: 137
Unknown Blocks: 15

Visual Map

? ? ? ? ? 0 0 ? 0 ? 0 ? 0 ? ? 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 x 0 x 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 ? x 0 0 0 0 ? 0 0 0 ? 0 ? 0 x 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Agent.VC
  • MSIL.Agent.VGA
  • MSIL.CsgoHack.RX
  • MSIL.Injector.BSC
  • MSIL.Krypt.GBBQ
Show More
  • MSIL.Kryptik.AFB

Windows API Usage

Category API
User Data Access
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
Other Suspicious
  • AdjustTokenPrivileges
Anti Debug
  • NtQuerySystemInformation