Threat Database Trojans Trojan.Kryptik.IOC

Trojan.Kryptik.IOC

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 26,443
Threat Level: 80 % (High)
Infected Computers: 27
First Seen: November 14, 2025
Last Seen: July 15, 2026
OS(es) Affected: Windows

The detection of Trojan.Kryptik.IOC on your system indicates a potential security threat. This report aims to provide you with general guidance on understanding and removing this threat. It's essential to approach this situation with caution and follow the recommended steps to ensure the security of your system and data.

What Is Trojan.Kryptik.IOC?

Trojan.Kryptik.IOC is a type of malware that can compromise the security of your system. The term "Trojan" refers to a broad category of malicious software that can disguise itself as legitimate programs, allowing it to bypass security measures and gain unauthorized access to your computer. The specific characteristics and behaviors of Trojan.Kryptik.IOC can vary, but its primary goal is to cause harm or exploit your system for malicious purposes.

How Trojan.Kryptik.IOC Operates

Malware like Trojan.Kryptik.IOC typically operates by exploiting vulnerabilities in software or tricking users into installing it. Once installed, it can perform a variety of malicious actions, such as stealing sensitive information, installing additional malware, or providing unauthorized access to your system. The exact mechanisms and tactics used by Trojan.Kryptik.IOC are not specified here, as they can depend on various factors, including the malware's design and the system it infects.

Symptoms of Infection

Systems infected with Trojan.Kryptik.IOC may exhibit a range of symptoms, including but not limited to, unusual system behavior, slow performance, frequent crashes, or the appearance of unwanted programs or toolbars. However, some malware is designed to operate stealthily, making it difficult to detect without the use of specific security tools. If you suspect that your system is infected, it's crucial to take immediate action to minimize potential damage.

How to Remove Trojan.Kryptik.IOC

  1. Boot your system into Safe Mode with Networking to prevent the malware from loading and to allow for internet access. This will make it easier to download and install removal tools.
  2. Download and run a full scan with a reputable anti-malware tool, such as SpyHunter, to detect and remove Trojan.Kryptik.IOC and any other malware that may be present on your system.
  3. Uninstall any suspicious programs that you do not recognize or that were installed around the time the malware was detected. Be cautious and only remove programs that you are certain are not essential to your system's operation.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or settings that the malware may have installed.
  5. Reboot your system and perform another full scan with your anti-malware tool to ensure that all traces of the malware have been removed. This step is crucial to verify that your system is clean and secure.

Conclusion

The removal of Trojan.Kryptik.IOC requires careful attention to detail and adherence to best practices for malware removal. By following the steps outlined in this report and maintaining a proactive approach to system security, you can significantly reduce the risk of future infections. Remember, prevention is key, and using reputable security software, keeping your operating system and applications up to date, and being cautious when downloading and installing software can help protect your system from threats like Trojan.Kryptik.IOC.

Analysis Report

General information

Family Name: Trojan.Kryptik.IOC
Signature status: No Signature

Known Samples

MD5: d646e56169d0760b259cee658cc6c426
SHA1: 9a7ac0f4f15c754d3a3512f147a192c77531688d
SHA256: E48EC0BD3F1C4CE9E13B2A010BDBDD0EAC0B33511458478127762FC02D6A1920
File Size: 4.67 MB, 4668992 bytes
MD5: d4ae3614af5f1b042ed23e89535ddf41
SHA1: b62339a2f54c91f2b5bf6421ef0f09210c10e4a7
SHA256: 1953BB3E9AA0D2BA609ACE8D08104BACF65F366734E97CD18F37D3AFF94FEEC1
File Size: 9.83 MB, 9825857 bytes
MD5: a4082e6929cbd767b475f56315b6876c
SHA1: e9e855548b7c5f2c51483ba621d69e2621103160
SHA256: FCE8BAABEE544CE0B1C14404B1EB0B84D1EC63D50636D3B598B265CE967E275C
File Size: 5.49 MB, 5486144 bytes
MD5: c450dfa416e535a0ecf00aafe4b0e8d3
SHA1: ea0a55e8d1c594a7897a427a1acce2756961a06a
SHA256: 84672D86CA44479FD388F451CD97002EB1E7EA94AAFD62786D52ECA5A2FF1FCE
File Size: 3.65 MB, 3653128 bytes
MD5: 4f4b54718385c350cd8aa5c222475c9c
SHA1: 23832326714adeb5699e0210871c85eca960128b
SHA256: 5C7B9621AAEC04698B0069E2F8226FC181FC432D40E93BD6C3A5F09520AA626D
File Size: 3.54 MB, 3542144 bytes
Show More
MD5: 550e2af9997e24eaf1c94cf25b36b245
SHA1: 10342c2e752c44685f2b5f54aaea8c024093c04c
SHA256: A85181C3D9F6069873759D9C29E0D6F1581CF7CCD6752034F04D0992073E831B
File Size: 4.10 MB, 4100240 bytes
MD5: bde5ab469fb4d105c0d14bcd9e5d9ebe
SHA1: 77c02b64fc84fac611519fdd128e115886f1d9f1
SHA256: B81C97C384B7C6E01594CEE96D53A262530D4A69AA1D1EC6EF177FDAA723E929
File Size: 3.73 MB, 3725440 bytes
MD5: a8821241e8713b979401cf29c02d4449
SHA1: 019beb3d2c896438967d8ab5a939392002bbfd58
SHA256: 880C09AC158CCC9DC96E5E3AB674B20F3FC56F3EA6A21E7F6384183655857DDE
File Size: 4.13 MB, 4129584 bytes
MD5: f49f47e9ee42a3dbcadd25822811ed54
SHA1: bc67af39cef2c613ebb92abfc75328bcce59ad20
SHA256: 19EAFE6C2F779DD6F53EB028D4C70EC7AB2646E99906FEA5A2A90BCB11F9503E
File Size: 4.43 MB, 4433472 bytes
MD5: 8bb565d2f3dd7d9ad41401d547ec109e
SHA1: b869ecd713380275c21f55f2311d8478bb44045f
SHA256: C8C7DF951CF11FD13CF2134465836BD1E4013B200667638516AC04ACA1BF9225
File Size: 4.11 MB, 4112072 bytes
MD5: 2d6c5dc1648c07d8d435fe02a61e15be
SHA1: 6fa7b3bd6cf602e27a455bc8215eca15ea3c0bd2
SHA256: 4AF4860E696C35949993DBEE6F72BBE61755B546836832C1DE4D6FDA9CAFF04F
File Size: 3.70 MB, 3704776 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments https://mobaxterm.mobatek.net
Company Name
  • HTC Corp.
  • Mobatek
File Description
  • MobaXterm
  • twintaillauncher
  • VIVE Software Setup
File Version
  • 25.3.0.5384
  • 2.0.41.3
  • 1.1.11
Internal Name
  • MobaXterm
  • ViveSoftwareSetup.exe
Legal Copyright
  • HTC Corp.(c) All rights reserved.
  • Mobatek - https://mobaxterm.mobatek.net
Legal Trademarks Mobatek - https://mobaxterm.mobatek.net
Original Filename
  • MobaXterm
  • ViveSoftwareSetup.exe
Product Name
  • MobaXterm
  • twintaillauncher
  • VIVE Software
Product Version
  • 25.3
  • 2.0.41.3
  • 1.1.11

Digital Signatures

Signer Root Status
HTC Corp. DigiCert SHA2 Assured ID Code Signing CA Hash Mismatch
HTC Corp. DigiCert SHA2 Assured ID Code Signing CA Hash Mismatch
Shenzhen CBD Technology Co., Ltd. DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Hash Mismatch
Mobatek Sectigo Public Code Signing Root R46 Hash Mismatch
dark.shopping dark.shopping Self Signed
Show More
www.tripadvisor.com www.tripadvisor.com Self Signed

File Traits

  • big overlay
  • dll
  • golang
  • HighEntropy
  • Installer Version
  • No Version Info
  • x64

Block Information

Total Blocks: 4,882
Potentially Malicious Blocks: 409
Whitelisted Blocks: 3,809
Unknown Blocks: 664

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.IDA
  • Agent.KOFA
  • Agent.LKGG
  • Agent.LPX
  • Agent.TKJ
Show More
  • Agent.TRFE
  • Dropper.JD
  • Filecoder.PFA
  • Filecoder.YA
  • Kryptik.FSK
  • Kryptik.FST
  • Kryptik.GSH
  • Kryptik.IOA
  • Kryptik.IOB
  • Kryptik.IOC
  • Kryptik.MDA
  • Kryptik.MHD
  • Kryptik.MHE
  • Quasar.LD
  • Quasar.SA
  • Reconyc.FH
  • Reconyc.FI
  • ReverseShell.XF
  • ShellcodeRunner.HCA
  • ShellcodeRunner.TO
  • Trojan.Metasploit.Gen.AF
  • Trojan.ReverseShell.Gen.W
  • Trojan.ShellcodeRunner.Gen.AQ
  • Vidar.PA
  • Vidar.PB

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtAlpcSetInformation
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
Show More
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRemoveIoCompletionEx
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetIoCompletion
  • ntdll.dll!NtSetTimerEx
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtYieldExecution
  • UNKNOWN
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • VirtualAllocEx
Process Shell Execute
  • CreateProcess

Shell Command Execution

C:\\Windows\\SysWOW64\\explorer.exe

Trending

Most Viewed

Loading...