Trojan.Kryptik.BGK
Trojan.Kryptik.BGK is a detection name used to identify a malicious program classified under the broad "Kryptik" family of Trojans. Threats in this family are typically packed or obfuscated to make them harder for security tools to analyze and to disguise their true purpose. As with most Trojans, Trojan.Kryptik.BGK does not announce itself to the user; instead, it tries to operate quietly in the background while carrying out actions that can compromise the security, privacy, or stability of an infected device.
Table of Contents
What Trojan.Kryptik.BGK Does
While the exact capabilities of any specific Kryptik variant can vary, threats detected under this family name typically behave like generic Trojans. This commonly includes attempting to download or install additional malicious components, modifying system settings to maintain a foothold on the infected machine, and attempting to evade detection by security software through code obfuscation or packing techniques. Some Kryptik-type Trojans are designed to collect information from the infected system, while others may act as a delivery mechanism for further malware, such as ransomware, spyware, or other unwanted programs. Because the "Kryptik" label mainly refers to the obfuscation technique used rather than a single fixed behavior, the precise actions of this Trojan can differ from one infected system to another.
How It Usually Spreads
Trojans like Trojan.Kryptik.BGK typically find their way onto computers through common infection vectors. These often include malicious email attachments or links, bundled downloads from untrustworthy or pirated software sources, fake software updates, cracked applications, and deceptive advertisements that prompt users to download or run a file. In many cases, the user is tricked into manually executing the malicious file because it is disguised as something legitimate, such as a document, installer, or media file.
Risks for the User
Because Trojans in this category are built to operate covertly and can serve multiple malicious purposes, an infected computer may be exposed to several risks. These typically include theft of personal or financial information, unauthorized remote access to the system, installation of additional malware, degraded system performance, and compromised online privacy. In some cases, an infected machine may be used as part of a larger malicious operation without the owner's knowledge.
Signs of Infection
Trojans are designed to be stealthy, so visible symptoms are not always present. However, typical warning signs associated with this type of threat can include unexpected slowdowns, unfamiliar processes running in the background, increased network activity without a clear cause, security software being disabled or malfunctioning, new or unfamiliar programs appearing on the system, and unusual pop-ups or browser behavior.
How to Stay Protected
To reduce the risk of encountering threats like Trojan.Kryptik.BGK, users should avoid downloading software from unofficial or untrusted sources, be cautious with email attachments and links from unknown senders, keep the operating system and installed applications up to date, and avoid using cracked or pirated software. Regularly backing up important data, using a reputable and updated security solution, and staying alert to unusual system behavior can also help detect and prevent infections before they cause significant harm. If a Trojan infection is suspected, running a full system scan with updated security software is typically recommended to identify and remove the threat.
Analysis Report
General information
| Family Name: | Trojan.Kryptik.BGK |
|---|---|
| Signature status: | No Signature |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
7dd653ea6bc5abbbeaaa1289e80d24f6
SHA1:
ad36ca517b78a384f5aea4e6f4aba29875bc1f43
SHA256:
BF743DE62F47A8B09DAF4F7E42F28E3B2ADCB5E73793682C12ED91B6864D1BEE
File Size:
1.02 MB, 1017856 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have exports table
- File doesn't have security information
- File has TLS information
- File is 64-bit executable
- File is either console or GUI application
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is Native application (NOT .NET application)
- File is not packed
- IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
File Icons
File Icons
This section displays icon resources found within family samples. Malware often replicates icons commonly associated with legitimate software to mislead users into believing the malware is safe.Windows PE Version Information
Windows PE Version Information
This section displays values and attributes that have been set in the Windows file version information data structure for samples within this family. To mislead users, malware actors often add fake version information mimicking legitimate software.| Name | Value |
|---|---|
| Company Name | Befalora, Corp. |
| File Description | Befalora |
| File Version | 10.1.8.25162 |
| Internal Name | befalora.exe |
| Legal Copyright | Copyright © 2016 Befalora, Corp.. All rights reserved. |
| Original Filename | befalora.exe |
| Product Name | Befalora |
| Product Version | 10.1.8.25162 |
File Traits
- ntdll
- x64
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 897 |
|---|---|
| Potentially Malicious Blocks: | 145 |
| Whitelisted Blocks: | 610 |
| Unknown Blocks: | 142 |
Visual Map
? - Unknown Block
x - Potentially Malicious Block
Similar Families
Similar Families
This section lists other families that share similarities with this family, based on EnigmaSoft’s analysis. Many malware families are created from the same malware toolkits and use the same packing and encryption techniques but uniquely extend functionality. Similar families may also share source code, attributes, icons, subcomponents, compromised and/or invalid digital signatures, and network characteristics. Researchers leverage these similarities to rapidly and effectively triage file samples and extend malware detection rules.- Trojan.Kryptik.Gen.KPF
Files Modified
Files Modified
This section lists files that were created, modified, moved and/or deleted by samples in this family. File system activity can provide valuable insight into how malware functions on the operating system.| File | Attributes |
|---|---|
| c:\program files (x86)\tableplus\schmieuviutch.txt | Generic Write,Read Attributes |
| c:\programdata\mantissas\swiohnist.dat | Generic Write,Read Attributes |
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API usage analysis is a valuable tool that can help identify malicious activity, such as keylogging, security privilege escalation, data encryption, data exfiltration, interference with antivirus software, and network request manipulation.| Category | API |
|---|---|
| Syscall Use |
|
| User Data Access |
|