Threat Database Keyloggers Trojan.MSIL.Keylogger.B

Trojan.MSIL.Keylogger.B

By CagedTech in Keyloggers, Trojans

Threat Scorecard

Popularity Rank: 16,866
Threat Level: 80 % (High)
Infected Computers: 10,921
First Seen: January 7, 2013
Last Seen: August 17, 2025
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.MSIL.Keylogger.B
Signature status: No Signature

Known Samples

MD5: 7d940b57682a7ecb26fef5c2051727bb
SHA1: f83f7069505598e3f63a706f57e17af925fcfc3f
SHA256: 6668697465B825984AE16D116E20CC3085C59D02019089406D75273428770466
File Size: 7.68 KB, 7680 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
File Description KeyloggerSample
File Version 1.0.0.0
Internal Name KeyloggerSample.exe
Legal Copyright Copyright © 2022
Original Filename KeyloggerSample.exe
Product Name KeyloggerSample
Product Version 1.0.0.0

File Traits

  • .NET
  • Run
  • x86

Block Information

Total Blocks: 5
Potentially Malicious Blocks: 5
Whitelisted Blocks: 0
Unknown Blocks: 0

Visual Map

x x x x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Keylogger.B

Files Modified

File Attributes
c:\windowsh\f83f7069505598e3f63a706f57e17af925fcfc3f_0000007680 Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windowsh\h.dat Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windowsh\h.dat Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\run::f83f7069505598e3f63a706f57e17af925fcfc3f_0000007680 C:\WindowsH\f83f7069505598e3f63a706f57e17af925fcfc3f_0000007680 RegNtPreCreateKey

Windows API Usage

Category API
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Other Suspicious
  • AdjustTokenPrivileges
Encryption Used
  • BCryptOpenAlgorithmProvider

Related Posts

Trending

Most Viewed

Loading...