Threat Database Trojans Trojan.MSIL.Krypt.EEBQC

Trojan.MSIL.Krypt.EEBQC

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 1
First Seen: January 10, 2023
Last Seen: April 13, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Krypt.EEBQC on your system indicates a potential security threat that requires immediate attention. This malware is classified as a Trojan, which is a type of malicious software designed to gain unauthorized access to a computer system. Trojans can be used to steal sensitive information, install additional malware, or provide a backdoor for remote access to the infected system.

What Is Trojan.MSIL.Krypt.EEBQC?

Trojan.MSIL.Krypt.EEBQC is a type of malware that can infect a computer system without the user's knowledge or consent. The name suggests that it is written in MSIL (Microsoft Intermediate Language), which is a platform-agnostic intermediate representation of the .NET Common Intermediate Language (CIL). The "Krypt" part of the name may indicate that the malware has encryption capabilities, which could be used to conceal its activities or protect its communication with command and control servers.

How Trojan.MSIL.Krypt.EEBQC Operates

Like other Trojans, Trojan.MSIL.Krypt.EEBQC operates by exploiting vulnerabilities in software or tricking users into installing it. Once installed, the malware can communicate with its command and control servers to receive instructions, upload stolen data, or download additional malware. It may also attempt to evade detection by using anti-debugging techniques, code obfuscation, or other methods to conceal its presence.

Symptoms of Infection

Infected systems may exhibit a range of symptoms, including slow performance, frequent crashes, or unusual network activity. Users may also notice unfamiliar programs or icons on their desktop, or receive unexpected pop-ups or warnings. However, some Trojans can operate silently, making it difficult to detect them without the aid of security software.

How to Remove Trojan.MSIL.Krypt.EEBQC

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for easier removal.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malware components.
  3. Uninstall any suspicious programs or applications that may be related to the malware.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or settings.
  5. Reboot your system and perform another full scan to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.MSIL.Krypt.EEBQC requires a combination of technical expertise and caution. It is essential to follow the removal steps carefully and use reputable security software to ensure that the malware is completely eliminated. After removal, it is crucial to take steps to prevent future infections, such as keeping your operating system and software up to date, using strong passwords, and avoiding suspicious downloads or email attachments. By taking these precautions, you can help protect your system and sensitive information from the threats posed by Trojan.MSIL.Krypt.EEBQC and other types of malware.

Analysis Report

General information

Family Name: Trojan.MSIL.Krypt.EEBQC
Signature status: No Signature

Known Samples

MD5: 117932476318415d4c184b0ad9e33ec0
SHA1: 81d3ff34d802d1078fa450ecdd8a0c79f7443d18
SHA256: A323B5E5AC277B7B315347EB5CB9549FA891DEFB9E99CF4CF1BFA51B9C6E3E87
File Size: 259.58 KB, 259584 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 3.10.31.655
Comments e4b2tjoi
File Description WDSync
File Version 3.10.31.655
Internal Name WDSync.dll
Legal Copyright Copyright © 2023
Original Filename WDSync.dll
Product Name WDSync
Product Version 3.10.31.655

File Traits

  • .NET
  • dll
  • x86

Block Information

Total Blocks: 1,143
Potentially Malicious Blocks: 508
Whitelisted Blocks: 635
Unknown Blocks: 0

Visual Map

x x x 0 x x x x x x 0 x x 0 x x x x x x x x x x 0 0 x x x x 0 0 0 x 0 0 x x x 0 0 x 0 x x x x 0 x 0 x 0 x 0 0 x 0 0 0 0 0 x x 0 x x 0 0 0 0 x x x x x x x 0 0 x x x 0 0 x x x 0 0 0 0 0 0 0 0 x 0 x 0 x 0 0 0 x x x 0 x x 0 0 0 0 0 x 0 x 0 0 0 0 0 0 x 0 x 0 0 0 x x x 0 x x 0 0 0 0 0 x 0 x x 0 x 0 0 0 0 x x 0 0 0 x 0 x x x x x 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 x 0 x 0 0 x x x x x 0 x x 0 x x x 0 0 0 0 0 0 0 0 0 x 0 0 0 x x 0 0 0 0 x 0 x x 0 x 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 0 0 0 0 x x x x x x x x 0 0 0 0 0 0 x 0 x 0 0 0 x x x 0 x x 0 0 0 0 0 0 0 x 0 x x x x x x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x 0 x 0 0 0 0 x x 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x x x x 0 x 0 0 x x 0 x x x x x x x x 0 x 0 0 0 0 x x x 0 0 0 0 0 0 0 x 0 0 0 x x x x x x x 0 x x 0 0 x x x x x 0 0 x 0 0 0 0 x 0 x 0 0 x 0 0 0 0 0 0 x 0 0 x 0 x 0 0 0 0 0 0 0 0 0 x 0 x 0 0 x 0 0 0 0 x x 0 x 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 x x x x x x x x x x 0 0 0 x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x 0 x 0 x x x 0 0 0 x x 0 x 0 0 0 x x x x x x x x x x 0 x 0 x x 0 0 0 x x x x 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x 0 x x 0 0 0 0 0 0 0 0 x x 0 0 0 x x 0 x 0 0 x x 0 x 0 x 0 0 x 0 0 0 x x 0 0 0 0 0 0 x x x 0 x 0 0 x 0 x x x 0 x x x x x 0 0 x x x x x 0 0 x x x x x 0 0 x x x x x x 0 0 x x x 0 0 x 0 x x x x x x x x x x 0 x x x x 0 x x x x x x x x x x x 0 0 0 0 0 x x x x x x x x x x x x x x 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 x x x x x 0 0 0 x x 0 0 0 0 x x 0 x x x 0 0 0 x 0 0 x 0 0 0 x x x 0 x 0 0 0 0 0 x 0 0 0 0 0 x 0 x 0 0 x x x x 0 0 0 0 0 0 x 0 0 x x 0 0 x x x x x 0 0 0 0 0 0 x x x x x 0 0 x 0 0 x x x 0 0 0 x x 0 0 0 0 0 0 x x x x x x x x x 0 x 0 0 0 0 0 x x 0 0 0 x x x x 0 x x 0 x x x x x x x 0 x 0 x x x x x x x 0 x x x x x x 0 x 0 x 0 x x x 0 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Krypt.EEBQC

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
Show More
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Related Posts

Trending

Most Viewed

Loading...