Threat Database Trojans Trojan.MSIL.Krypt.EEBQC

Trojan.MSIL.Krypt.EEBQC

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 24,557
Threat Level: 80 % (High)
Infected Computers: 1
First Seen: January 10, 2023
Last Seen: April 13, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.MSIL.Krypt.EEBQC
Signature status: No Signature

Known Samples

MD5: 117932476318415d4c184b0ad9e33ec0
SHA1: 81d3ff34d802d1078fa450ecdd8a0c79f7443d18
SHA256: A323B5E5AC277B7B315347EB5CB9549FA891DEFB9E99CF4CF1BFA51B9C6E3E87
File Size: 259.58 KB, 259584 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 3.10.31.655
Comments e4b2tjoi
File Description WDSync
File Version 3.10.31.655
Internal Name WDSync.dll
Legal Copyright Copyright © 2023
Original Filename WDSync.dll
Product Name WDSync
Product Version 3.10.31.655

File Traits

  • .NET
  • dll
  • x86

Block Information

Total Blocks: 1,143
Potentially Malicious Blocks: 508
Whitelisted Blocks: 635
Unknown Blocks: 0

Visual Map

x x x 0 x x x x x x 0 x x 0 x x x x x x x x x x 0 0 x x x x 0 0 0 x 0 0 x x x 0 0 x 0 x x x x 0 x 0 x 0 x 0 0 x 0 0 0 0 0 x x 0 x x 0 0 0 0 x x x x x x x 0 0 x x x 0 0 x x x 0 0 0 0 0 0 0 0 x 0 x 0 x 0 0 0 x x x 0 x x 0 0 0 0 0 x 0 x 0 0 0 0 0 0 x 0 x 0 0 0 x x x 0 x x 0 0 0 0 0 x 0 x x 0 x 0 0 0 0 x x 0 0 0 x 0 x x x x x 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 x 0 x 0 0 x x x x x 0 x x 0 x x x 0 0 0 0 0 0 0 0 0 x 0 0 0 x x 0 0 0 0 x 0 x x 0 x 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 0 0 0 0 x x x x x x x x 0 0 0 0 0 0 x 0 x 0 0 0 x x x 0 x x 0 0 0 0 0 0 0 x 0 x x x x x x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x 0 x 0 0 0 0 x x 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x x x x 0 x 0 0 x x 0 x x x x x x x x 0 x 0 0 0 0 x x x 0 0 0 0 0 0 0 x 0 0 0 x x x x x x x 0 x x 0 0 x x x x x 0 0 x 0 0 0 0 x 0 x 0 0 x 0 0 0 0 0 0 x 0 0 x 0 x 0 0 0 0 0 0 0 0 0 x 0 x 0 0 x 0 0 0 0 x x 0 x 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 x x x x x x x x x x 0 0 0 x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x 0 x 0 x x x 0 0 0 x x 0 x 0 0 0 x x x x x x x x x x 0 x 0 x x 0 0 0 x x x x 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x 0 x x 0 0 0 0 0 0 0 0 x x 0 0 0 x x 0 x 0 0 x x 0 x 0 x 0 0 x 0 0 0 x x 0 0 0 0 0 0 x x x 0 x 0 0 x 0 x x x 0 x x x x x 0 0 x x x x x 0 0 x x x x x 0 0 x x x x x x 0 0 x x x 0 0 x 0 x x x x x x x x x x 0 x x x x 0 x x x x x x x x x x x 0 0 0 0 0 x x x x x x x x x x x x x x 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 x x x x x 0 0 0 x x 0 0 0 0 x x 0 x x x 0 0 0 x 0 0 x 0 0 0 x x x 0 x 0 0 0 0 0 x 0 0 0 0 0 x 0 x 0 0 x x x x 0 0 0 0 0 0 x 0 0 x x 0 0 x x x x x 0 0 0 0 0 0 x x x x x 0 0 x 0 0 x x x 0 0 0 x x 0 0 0 0 0 0 x x x x x x x x x 0 x 0 0 0 0 0 x x 0 0 0 x x x x 0 x x 0 x x x x x x x 0 x 0 x x x x x x x 0 x x x x x x 0 x 0 x 0 x x x 0 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Krypt.EEBQC

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
Show More
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Trending

Most Viewed

Loading...