Threat Database Trojans Trojan.Kryptik.UBWH

Trojan.Kryptik.UBWH

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.Kryptik.UBWH
Signature status: No Signature

Known Samples

MD5: c284627c8c2b3b7bb93680b59b54482b
SHA1: 48ba29bf03ef3f8014ad23f2d4dc005ffa2fa8da
SHA256: 9C061CA97EB51D33BEE08D866715AF76F2B98679C732638C97F53C0EA649EB13
File Size: 777.73 KB, 777728 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name Microsoft Corporation
File Description Windows Performance Analyzer
File Version 10.0.19042.3929
Internal Name WPA.exe
Legal Copyright © Microsoft Corporation. All rights reserved.
Original Filename WPA.exe
Product Name Microsoft® Windows® Operating System
Product Version 10.0.19042.3929

File Traits

  • HighEntropy
  • x86

Block Information

Total Blocks: 713
Potentially Malicious Blocks: 283
Whitelisted Blocks: 89
Unknown Blocks: 341

Visual Map

? ? 0 ? ? 0 0 0 ? ? x x x x ? ? x x x ? x x ? x 0 0 0 ? x 0 x x x x x x x x 0 ? x ? ? 0 x x x x x 0 x 0 0 x 0 0 ? ? ? ? ? x ? ? ? x ? 0 x x x ? x ? x 0 ? ? x 0 x x ? ? ? ? x x ? ? x ? ? x ? x x x ? ? x ? ? ? x ? x ? x x ? 0 x x x x 0 ? x x ? ? x x x x ? ? ? ? x x x x x x ? x ? x ? ? x x 0 x 0 ? x x ? ? ? ? ? x x x x ? ? 0 ? 0 0 x ? ? ? ? ? 0 x 0 0 x 0 x ? ? ? ? x x ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? 0 ? ? x x ? x x x x ? x x x x ? ? x x ? ? ? ? x ? ? ? ? ? ? 0 ? ? ? ? ? ? ? 0 ? 0 x 0 0 x 0 ? x ? ? ? ? ? ? 0 0 ? ? 0 0 ? ? ? ? ? ? ? ? 0 ? ? x ? ? 0 ? ? x ? x x ? ? ? 0 ? ? ? ? x ? ? 0 x ? 0 ? ? ? 0 ? ? x ? 0 x x ? ? ? ? 0 ? ? x x x ? 0 ? ? x x ? x x ? x ? x x x x x ? x x x x x 0 x 0 0 0 0 0 0 ? x ? 0 x x 0 x x ? 0 0 x ? ? ? x ? ? x ? x ? x ? x x x ? ? ? ? x ? x x x ? ? 0 x ? ? ? ? 0 0 x x x ? x ? x x x x x ? ? x x x x x ? x ? x x ? x x x ? ? ? ? x ? ? x ? ? ? ? ? ? ? ? ? 0 ? ? ? x ? ? ? ? ? ? ? x x ? ? ? ? ? ? ? ? ? x 0 ? x ? x x ? x x x ? x ? x ? 0 ? ? ? x 0 x x 0 0 0 x x ? x ? ? 0 ? 0 ? ? 0 ? x ? 0 0 x x ? 0 x 0 x ? x ? ? x 0 ? ? 0 x ? x x ? x ? x ? 0 x x ? x x ? ? ? 0 x x ? ? x x ? ? ? ? ? ? ? ? ? x ? x ? x ? ? ? ? x x ? x ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? x x ? ? ? ? ? ? ? ? ? ? ? ? ? ? x x ? x x x x x x 0 x 0 x x x 0 x x x x 0 x x x x x x ? ? ? ? x ? x x ? ? x ? ? x ? ? x ? ? x ? ? ? ? x ? ? 0 ? ? ? x x x x x x x x x x x ? ? x x x x x x x ? x x x x x x ? x ? x x x x x x x x x ? x x ? x x x 1
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Trending

Most Viewed

Loading...