Threat Database Trojans Trojan.MSIL.Krypt.CCW

Trojan.MSIL.Krypt.CCW

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 20,886
Threat Level: 80 % (High)
Infected Computers: 236
First Seen: October 25, 2021
Last Seen: August 17, 2025
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.MSIL.Krypt.CCW
Signature status: No Signature

Known Samples

MD5: 4e91832f34fa6559280ebdab1c15ae23
SHA1: 45b1bf1f6d39209d57b88c75f8e49301a04546ae
SHA256: F06125E3B21885903499C1AA04D5D23CC30BD440E76B7868F7E87D7BBF9BCC0C
File Size: 134.14 KB, 134144 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.0.1.9
File Description DecrtittaGuid
File Version 1.0.1.9
Internal Name TServeServizi.exe
Legal Copyright Copyright © 2020
Original Filename TServeServizi.exe
Product Name DecrtittaGuid
Product Version 1.0.1.9

File Traits

  • .NET
  • CryptoObfus
  • x86

Block Information

Total Blocks: 48
Potentially Malicious Blocks: 5
Whitelisted Blocks: 17
Unknown Blocks: 26

Visual Map

? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? x ? x 0 0 x 0 0 0 0 ? 0 0 ? ? x ? ? ? ? 0 ? x 0 ? ? 0 0 ? 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
User Data Access
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
Anti Debug
  • CheckRemoteDebuggerPresent
  • IsDebuggerPresent
  • NtQuerySystemInformation

Trending

Most Viewed

Loading...