Threat Database Trojans Trojan.MSIL.Krypt.DAOG

Trojan.MSIL.Krypt.DAOG

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 0
First Seen: February 19, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.MSIL.Krypt.DAOG
Signature status: No Signature

Known Samples

MD5: 94ca032414219144fda6ff5d6c3ad68e
SHA1: 7498a43038b8d510a0026ea9dd04f5716fa0bbc3
SHA256: 1907F5AABF118DD685F88DB5564E4ACCC4C0934725909196D79704F2FFA0F192
File Size: 1.01 MB, 1006080 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 0.0.0.0
File Version 0.0.0.0
Internal Name LlWKQ.exe
Original Filename LlWKQ.exe
Product Version 0.0.0.0

File Traits

  • .NET
  • HighEntropy
  • x86

Block Information

Total Blocks: 132
Potentially Malicious Blocks: 89
Whitelisted Blocks: 43
Unknown Blocks: 0

Visual Map

0 0 0 0 0 x 0 x x x x x x x x x x x 0 x x x x x 0 0 x 0 0 x x x x x 0 x x 0 0 x x x x 0 0 x x 0 x x 0 0 0 0 0 x 0 0 0 x x x 0 0 x 0 x x x x x x x x x x x x x x 0 x x x x x x 0 x 0 x x x x x 0 x x 0 x 0 x x x x x x x x x x x x x x x x x x 0 0 0 x x x x 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Krypt.DAOG

Windows API Usage

Category API
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation