Threat Database Trojans Trojan.MSIL.Krypt.GBBCD

Trojan.MSIL.Krypt.GBBCD

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 21,354
Threat Level: 80 % (High)
Infected Computers: 179
First Seen: February 24, 2023
Last Seen: January 24, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.MSIL.Krypt.GBBCD
Signature status: No Signature

Known Samples

MD5: cf57eddaa0a819b1ee3e7927f4a4e920
SHA1: c3566fdca0836ea20d0f5fdccd1419cbb61ab4e5
SHA256: 2EC06EEE5FCB37DF76955D47CD77B9A6A9094BAFAB6D6EAF28CC3E2B18B7C6EC
File Size: 273.92 KB, 273920 bytes
MD5: f3c22f3672481bf7ee64b8ee0209067b
SHA1: 41e72bf623a5f82e0193bfa3b19ed91e518145a3
SHA256: 4EEF00F93CE9110EA699C7D6C0C7F33BCD6957BF70184DF79D64E9175B66AD42
File Size: 9.31 MB, 9312256 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Power Software Ltd
File Description PowerISO Setup
File Version 8.3.0.0
Legal Copyright Copyright(c) 2004-2022
Product Name PowerISO Setup
Product Version 8.3.0.0

File Traits

  • .NET
  • HighEntropy
  • Installer Version
  • No Version Info
  • RijndaelManaged
  • SmartAssembly
  • x86

Block Information

Total Blocks: 194
Potentially Malicious Blocks: 18
Whitelisted Blocks: 169
Unknown Blocks: 7

Visual Map

? 0 ? 0 ? ? x 0 ? 0 x x 0 x x 0 x x 0 x 0 x x 0 x 0 x ? x ? x 0 x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Agent.VCA
  • MSIL.Krypt.GBBCD
  • MSIL.Krypt.GBBH
  • MSIL.Krypt.GBBU
  • MSIL.Krypt.GBBW
Show More
  • MSIL.Krypt.GBBY
  • MSIL.Krypt.GFH
  • MSIL.RedLine.P

Windows API Usage

Category API
User Data Access
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
Anti Debug
  • NtQuerySystemInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
  • VirtualAllocEx

Trending

Most Viewed

Loading...