威胁数据库 特洛伊木马 Trojan.Kryptik.BSS

Trojan.Kryptik.BSS

通过CagedTech在 特洛伊木马
发布时间:
最后更新:

Trojan.Kryptik.BSS是一个检测名称,用于标记行为类似或打包方式与通用木马程序一致的文件。包含“Kryptik”的名称通常用于那些被创建者混淆或加密的威胁,目的是隐藏其真实目的,并增加分析和检测的难度。由于底层代码经过伪装,因此被标记的文件实际上可能属于多个不同的恶意软件家族,从简单的骚扰程序到更严重的窃取信息或下载程序,不一而足。

关于此次检测的具体技术细节,例如确切的有效载荷、文件名或传播活动,现有数据尚未得到证实。以下描述反映了此类木马的典型行为,仅供参考,并非对该特定威胁的确认。

这种威胁通常会造成什么后果?

像这样以通用打包文件标签检测到的木马程序通常会在后台静默运行,没有任何可见的界面,因此受害者不会察觉到任何异常情况。根据隐藏在混淆代码中的特定有效载荷,此类木马程序可能会尝试下载并安装其他恶意组件、从受感染的设备收集信息、修改系统设置,或者让远程攻击者以某种方式访问受感染的计算机。由于代码经过加密或打包,安全工具通常依赖行为模式而非精确的特征码来捕获它,因此检测名称较为宽泛,而非与某个特定的恶意软件家族相关联。

它通常是如何进入电脑的

这类木马通常通过欺骗手段传播,而非利用单一漏洞。典型的感染途径包括恶意电子邮件附件、钓鱼邮件中的链接、虚假软件更新、破解或盗版程序安装程序、来自不可信网站的捆绑下载以及被篡改的广告。大多数情况下,用户会被诱骗打开或运行这些文件,误以为是合法的软件、文档或媒体文件。

用户面临的风险

由于实际有效载荷可能有所不同,因此被标记为 Kryptik 的木马程序带来的风险也各不相同。潜在后果通常包括个人或财务信息被盗、未经授权的远程访问设备、安装其他恶意软件、系统性能下降以及已保存的密码或浏览数据泄露。任何此类后果都可能导致经济损失、身份盗窃,或进一步危及连接到同一网络的其他帐户和设备的安全。

感染迹象

  • 意外的运行速度变慢、卡顿或崩溃
  • 后台运行着不熟悉的进程,或者资源使用率过高而又找不到明显原因。
  • 系统中出现新的或无法解释的程序、工具栏或图标
  • 安全软件被禁用或无法更新
  • 异常的网络活动或数据使用情况
  • 弹出窗口、重定向或浏览器设置更改

如何做好防护

用户可以通过以下方式降低此类感染的风险:保持操作系统和软件更新;避免从非官方或盗版来源下载软件;谨慎对待来自未知发件人的电子邮件附件和链接;使用信誉良好且最新的安全软件在打开文件前进行扫描。定期备份重要数据也能最大限度地减少木马病毒感染造成的损失;定期检查已安装的程序和浏览器扩展程序有助于及早发现有害程序。

分析报告

一般信息

姓: Trojan.Kryptik.BSS
签名状态: No Signature

已知样本

MD5: f6da884b3e787c5158bac0a18a20ea4e
SHA1: 5477f4815fb148a1415ba1dbec607f01226aab8f
SHA256: 536819FC5A9F61160224707BB9035B3A7F97EE38C03D9F948AFE18FA1BDCEA69
文件大小: 3.22 MB,3221944字节

Windows 可移植可执行文件属性

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
显示更多
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

文件特征

  • HighEntropy
  • No Version Info
  • x64

区块信息

总区块数: 85
潜在恶意块: 16
白名单区块: 69
未知区块: 0

可视化地图

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x 0 x x 0 0 x x x 0 x x 0 0 x x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0
0 - 可能的保险箱
? - 未知区块
x - 潜在恶意拦截

相似家庭

  • Kryptik.BSS
  • ShellcodeRunner.FGA
  • Trojan.Injector.Gen.JTY
  • Trojan.Kryptik.Gen.JXW
  • Trojan.Kryptik.Gen.JYN
显示更多
  • Trojan.ReverseShell.Gen.FY

文件已修改

文件 属性
c:\programdata\microsoft\windows\perfhost\perfhostsvc.exe Generic Write,Read Attributes
c:\programdata\microsoft\windows\perfhost\perfhostsvc.exe Synchronize,Write Attributes
c:\windows\system32\wbem\wmiperfhost.exe Generic Write,Read Attributes
c:\windows\system32\wbem\wmiperfhost.exe Synchronize,Write Attributes

Windows API 使用情况

类别 API
Syscall Use
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcSetInformation
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateTimer2
显示更多
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDirectoryFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimerEx
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtYieldExecution
  • UNKNOWN
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Network Winsock2
  • WSAStartup
Other Suspicious
  • AdjustTokenPrivileges