Threat Database Trojans Trojan.MSIL.Krypt.BFA

Trojan.MSIL.Krypt.BFA

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 25,043
Threat Level: 80 % (High)
Infected Computers: 50
First Seen: September 11, 2022
Last Seen: March 10, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.MSIL.Krypt.BFA
Signature status: No Signature

Known Samples

MD5: 4d850c80686c25f3d562776d3f32d78e
SHA1: 92f2e479bcdd654da6f604c26bdfbed18c5887f2
SHA256: 3210DD42C34B85141324968F810DB87E7FC4E1DE2DCFFEF9E1700D06F7375E0A
File Size: 388.10 KB, 388096 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 1.0.0.5
File Description G_Active_Key
File Version 1.1.1.1
Internal Name G_Active_Key.exe
Legal Copyright Copyright © 2023
Original Filename G_Active_Key.exe
Product Name G_Active_Key
Product Version 1.1.1.1

File Traits

  • .NET
  • RijndaelManaged
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 64
Potentially Malicious Blocks: 2
Whitelisted Blocks: 52
Unknown Blocks: 10

Visual Map

0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 ? x x 0 ? 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Coinminer.AV
  • MSIL.Gamehack.BOT
  • MSIL.Krypt.BFA
  • MSIL.Krypt.EO
  • MSIL.Krypt.FR
Show More
  • MSIL.Krypt.YCD

Windows API Usage

Category API
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • NtQuerySystemInformation
Process Manipulation Evasion
  • ReadProcessMemory

Trending

Most Viewed

Loading...