Threat Database Trojans Trojan.MSIL.Downloader.KPA

Trojan.MSIL.Downloader.KPA

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 15,328
Threat Level: 80 % (High)
Infected Computers: 5
First Seen: January 13, 2026
Last Seen: April 25, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Downloader.KPA indicates that your system has been compromised by a malicious threat. This type of malware is designed to cause harm to your computer and potentially steal sensitive information. It is essential to take immediate action to remove the threat and prevent further damage.

What Is Trojan.MSIL.Downloader.KPA?

Trojan.MSIL.Downloader.KPA is a type of Trojan horse malware that can download and install additional malicious software on your computer. The name suggests that it is written in MSIL (Microsoft Intermediate Language), which is a programming language used by the .NET Framework. This type of malware can be particularly dangerous, as it can allow attackers to remotely control your computer and steal sensitive information.

How Trojan.MSIL.Downloader.KPA Operates

Trojan.MSIL.Downloader.KPA operates by exploiting vulnerabilities in your system to gain access and download additional malware. Once installed, it can communicate with its command and control servers to receive instructions and transmit stolen data. This type of malware can also spread through various means, including infected software downloads, phishing emails, and exploited vulnerabilities in operating systems or applications.

  • It can create backdoors to allow remote access to your computer
  • It can download and install additional malware, including ransomware, spyware, and adware
  • It can steal sensitive information, such as login credentials, credit card numbers, and personal data

Symptoms of Infection

The symptoms of a Trojan.MSIL.Downloader.KPA infection can vary, but common signs include slow system performance, unexpected pop-ups and ads, and suspicious network activity. You may also notice that your computer is behaving erratically, such as crashing or freezing frequently. If you suspect that your system has been infected, it is crucial to take immediate action to remove the threat.

  • Slow system performance and responsiveness
  • Unexpected pop-ups and ads
  • Suspicious network activity, such as unusual outgoing connections
  • Erratic system behavior, such as crashing or freezing

How to Remove Trojan.MSIL.Downloader.KPA

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and remove any detected threats
  3. Uninstall any suspicious programs or applications that may be related to the malware
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons
  5. Reboot your computer and perform another full scan to ensure that the threat has been completely removed

Conclusion

Removing Trojan.MSIL.Downloader.KPA requires immediate attention to prevent further damage to your system and sensitive information. By following the steps outlined above, you can help ensure that the threat is completely removed and your computer is secure. It is also essential to take preventive measures, such as keeping your operating system and software up to date, using strong antivirus software, and being cautious when downloading software or clicking on links from unknown sources.

Analysis Report

General information

Family Name: Trojan.MSIL.Downloader.KPA
Signature status: No Signature

Known Samples

MD5: 9400b77ec8c29d24df33278c3ee0d84a
SHA1: 6e091775833784f8de8890bbb16604e1973575eb
SHA256: C9294340CBD1E191F98DEF21E6CCE096425AB648D272EE6F9601DAE1C530F8B1
File Size: 19.46 KB, 19456 bytes
MD5: e4f62586f97b35339d695574e1a05abf
SHA1: d3d581b7b00e21a6048ebe474b8123f253453365
SHA256: A5EBA30ED387AA74A9CCFC4485635ADE233406A70003B6BE97C4E78007F85F54
File Size: 19.46 KB, 19456 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 0.0.0.0
File Version 0.0.0.0
Internal Name
  • conneecthost.exe
  • Driverwindeus.exe
Original Filename
  • conneecthost.exe
  • Driverwindeus.exe
Product Version 0.0.0.0

File Traits

  • .NET
  • ntdll
  • x86

Block Information

Total Blocks: 54
Potentially Malicious Blocks: 17
Whitelisted Blocks: 3
Unknown Blocks: 34

Visual Map

0 x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x x x x ? x x x x x x x x x x 0 x x 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
\device\namedpipe\dav rpc service Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\pshost.134214376274841384.5988.defaultappdomain.powershell Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
\device\namedpipe\pshost.134215370606827303.4012.defaultappdomain.powershell Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
\device\namedpipe\wkssvc Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.2.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\__psscriptpolicytest_flxbzrwo.5nt.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_lt1xeehq.rjb.psm1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_m3bldrai.dqo.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_vdbdvndr.0dp.psm1 Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 嵺鶞퍃ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 혫퐫ǜ RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAllocateLocallyUniqueId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreateResourceReserve
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcQueryInformationMessage
  • ntdll.dll!NtAlpcSendWaitReceivePort
Show More
  • ntdll.dll!NtAlpcSetInformation
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelTimer2
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCompareSigningLevels
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtGetCachedSigningLevel
  • ntdll.dll!NtGetWriteWatch
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtQueueApcThreadEx2
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResetWriteWatch
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationObject
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSetTimerEx
  • ntdll.dll!NtSubscribeWnfStateChange

23 additional items are not displayed above.

User Data Access
  • GetUserDefaultLocaleName
  • GetUserName
  • GetUserNameEx
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Encryption Used
  • BCryptOpenAlgorithmProvider
Other Suspicious
  • AdjustTokenPrivileges

Shell Command Execution

"powershell.exe" -WindowStyle Hidden -EncodedCommand QQBkAGQALQBNAHAAUAByAGUAZgBlAHIAZQBuAGMAZQAgAC0ARQB4AGMAbAB1AHMAaQBvAG4AUABhAHQAaAAgACcAQwA6AFwAVQBzAGUAcgBzAFwAQgByAHAAYwBwAGEAaQB1AFwAQQBwAHAARABhAHQAYQBcAEwAbwBjAGEAbABcAP3//f/9//3//f/9//3//f9cAP3//f/9//3//f/9//3//f8nAA==
"powershell.exe" -WindowStyle Hidden -EncodedCommand QQBkAGQALQBNAHAAUAByAGUAZgBlAHIAZQBuAGMAZQAgAC0ARQB4AGMAbAB1AHMAaQBvAG4AUABhAHQAaAAgACcAQwA6AFwAVQBzAGUAcgBzAFwARgBjAHEAegBmAGcAdAB6AFwAQQBwAHAARABhAHQAYQBcAEwAbwBjAGEAbABcAFcAaABsAEQAZQBmAG4AYgBcAFMAeAB2AHcAYQBoADUANQAnAA==

Trending

Most Viewed

Loading...