Threat Database Trojans Trojan.MSIL.Krypt.EDCR

Trojan.MSIL.Krypt.EDCR

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 6,990
Threat Level: 80 % (High)
Infected Computers: 430
First Seen: August 25, 2022
Last Seen: August 1, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Krypt.EDCR on your system indicates a potential security threat that requires immediate attention. This report provides an overview of the threat, its operating mechanisms, symptoms of infection, and steps to remove it from your system.

What Is Trojan.MSIL.Krypt.EDCR?

Trojan.MSIL.Krypt.EDCR is identified as a Trojan-type threat, which is a broad category of malware designed to deceive users by appearing as legitimate software. The name suggests it may involve encryption or cryptographic techniques, but without specific details, it's crucial to understand the general behavior of Trojans. They can be used for various malicious purposes, including data theft, unauthorized access to systems, or as a vector for other malware.

How Trojan.MSIL.Krypt.EDCR Operates

Trojans, like Trojan.MSIL.Krypt.EDCR, typically operate by disguising themselves as useful or harmless applications. Once installed, they can create backdoors for remote access, allowing attackers to control the infected system. They may also engage in data theft, including login credentials, personal files, or sensitive information. The specific mechanisms of Trojan.MSIL.Krypt.EDCR are not detailed here, but understanding the general modus operandi of Trojans is key to mitigating their impact.

Symptoms of Infection

Symptoms of a Trojan infection can be subtle and may not always be immediately apparent. Common signs include unusual system behavior, such as unexpected pop-ups, slow performance, or frequent crashes. Users may also notice unauthorized changes to their system settings or the presence of unfamiliar programs. Since Trojans can be designed to remain stealthy, some infections may only be discovered through proactive scanning with security software.

How to Remove Trojan.MSIL.Krypt.EDCR

  1. Enter Safe Mode with Networking: This will limit the malware's ability to interfere with the removal process. Restart your computer, and as it boots up, press the key to access your boot menu (this varies by manufacturer but is often F8, F12, or Del). Select Safe Mode with Networking.
  2. Conduct a Full Scan: Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. Ensure your antivirus software is updated with the latest definitions before scanning.
  3. Uninstall Suspicious Programs: Go through your installed programs and remove any that you do not recognize or that were installed around the time you suspect the infection occurred.
  4. Reset Your Browsers: Trojans can affect your web browsers, so resetting them to their default settings can help remove any malicious changes. This can usually be done in the settings or options menu of Chrome, Firefox, Edge, or whatever browser you use.
  5. Reboot and Re-scan: After completing the above steps, restart your computer in normal mode and run another full scan with your anti-malware software to ensure the threat has been fully removed.

Conclusion

Removing Trojan.MSIL.Krypt.EDCR requires a systematic approach to ensure your system is thoroughly cleaned and protected against future threats. By understanding the nature of Trojan-type malware and taking proactive steps to secure your system, you can minimize the risk of infection and maintain the integrity of your data. Regularly updating your operating system, using reputable security software, and practicing safe computing habits are essential in today's digital landscape.

Analysis Report

General information

Family Name: Trojan.MSIL.Krypt.EDCR
Signature status: No Signature

Known Samples

MD5: 0ef107ba3be09eab56c60bd0bf6a9747
SHA1: 723332a9cb33a21d42dd78b7eb7a1fdd56298cc7
SHA256: CE220A02FA38E159349F740D3A6527EE4CD60E33DB0CE8C24A608A0D31E02A45
File Size: 94.25 KB, 94248 bytes
MD5: 1a64a024e8e3e5b00c5680342835d20e
SHA1: 4b64a114c7132a900de7789afce383943c2f1fd0
SHA256: BC85B835C0F62C6E747290FD3273857F188DA9B780635001213887465A544FF4
File Size: 543.23 KB, 543232 bytes
MD5: 52232c848005d4db4148ee20d221878c
SHA1: 16b4fdb0de291f1c1a2eaa51b4c21b1c77dbbc20
SHA256: 974A66E2850BDE427353B8C07CB1FA2630C225D99396CF1FBA66186640D2ECBA
File Size: 392.70 KB, 392704 bytes
MD5: e7da9f91754344d22fe5a7d3584c95d3
SHA1: 17090b5c362d1c581d830900d2ce7b7623cf366d
SHA256: 03661A35364A5422D0D07636936AFA1146BF75783C9E5E987F44258C815799D8
File Size: 1.01 MB, 1012736 bytes
MD5: b0a3d95080a55f9890f5103e2bab6ddc
SHA1: a55f0302799cc1ea41c71f754216da828199a87b
SHA256: AA8F9063592D137DC0BF8ED03A411ECE57A89F243D8543A335EB317CBB5CBF4E
File Size: 432.13 KB, 432128 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
Comments Mohel Banqueters
Company Name Shorten Buddleias
File Description tribulation amobarbital tarnishes
File Version 1.0.0.0
Internal Name
  • Eceug.exe
  • Kaeatfyp.exe
  • MSG.exe
  • Wgazix.exe
  • Xqgwpmvx.exe
Legal Copyright Copyright © 2024
Original Filename
  • Eceug.exe
  • Kaeatfyp.exe
  • MSG.exe
  • Wgazix.exe
  • Xqgwpmvx.exe
Product Name Grippers
Product Version 1.0.0.0

Digital Signatures

Signer Root Status
NVIDIA Corporation DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Hash Mismatch

File Traits

  • .NET
  • GenKrypt
  • HighEntropy
  • Reactor
  • RijndaelManaged
  • x64
  • x86

Block Information

Total Blocks: 89
Potentially Malicious Blocks: 9
Whitelisted Blocks: 69
Unknown Blocks: 11

Visual Map

x x ? ? ? ? ? x ? x ? x ? 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Agent.ONR
  • MSIL.AgentTesla.LP
  • MSIL.RustHack.H
  • MSIL.Stealer.BDP

Files Modified

File Attributes
\device\namedpipe\dav rpc service Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\pshost.134246480116325911.6308.defaultappdomain.powershell Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
\device\namedpipe\pshost.134299770928202060.7396.defaultappdomain.powershell Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
\device\namedpipe\wkssvc Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\__psscriptpolicytest_40pl20nm.onq.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_aunrftcu.r0z.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_bworq5d4.l0j.psm1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_yyxmt0yi.kib.psm1 Generic Write,Read Attributes
c:\users\user\appdata\roaming\microsoft\windows\start menu\programs\startup\svhost.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\microsoft.net\framework\v4.0.30319\regasm.exe Synchronize,Write Attributes

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 鄓徯ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 阂ᮟ⃮ǝ RegNtPreCreateKey

Windows API Usage

Category API
User Data Access
  • GetUserDefaultLocaleName
  • GetUserName
  • GetUserNameEx
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAllocateLocallyUniqueId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreateResourceReserve
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcQueryInformationMessage
  • ntdll.dll!NtAlpcSendWaitReceivePort
Show More
  • ntdll.dll!NtAlpcSetInformation
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelTimer2
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCompareSigningLevels
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtGetCachedSigningLevel
  • ntdll.dll!NtGetContextThread
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtQueueApcThreadEx2
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationObject
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSetTimerEx
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtSuspendThread

15 additional items are not displayed above.

Other Suspicious
  • AdjustTokenPrivileges
Process Shell Execute
  • CreateProcess

Shell Command Execution

"powershell.exe" -NoProfile -Command "Add-MpPreference -ExclusionPath 'C:\Users\Peatncwd\AppData\Roaming\FLiNG\auto_updating.exe'