Threat Database Trojans Trojan.MSIL.Krypt.GBBCE

Trojan.MSIL.Krypt.GBBCE

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 14,219
Threat Level: 80 % (High)
Infected Computers: 27
First Seen: March 11, 2023
Last Seen: September 29, 2025
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.MSIL.Krypt.GBBCE
Signature status: Self Signed

Known Samples

MD5: a753541c3c0d0b8bd9b431532fc9d833
SHA1: 67290731d2906f5ec13b3cfb76ac7180da0ffedb
SHA256: 7DCEA4C0A35C4EF826C934086A765D6F4999AAAC0DF78AB8F9C3B2FAEBADE2DB
File Size: 1.05 MB, 1050824 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.4.19.1
Company Name PageBites, Inc.
File Description Imo Messenger
File Version 1.4.19.1
Internal Name ImoDesktopApp.exe
Legal Copyright Copyright © 2016
Original Filename ImoDesktopApp.exe
Product Name Imo Messenger
Product Version 1.4.19.1

Digital Signatures

Signer Root Status
Pagebites, Inc. SSL.com Code Signing Intermediate CA RSA R1 Self Signed

File Traits

  • .NET
  • 00 section
  • 2+ executable sections
  • RijndaelManaged
  • x86

Block Information

Total Blocks: 590
Potentially Malicious Blocks: 38
Whitelisted Blocks: 304
Unknown Blocks: 248

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 ? ? 0 ? ? ? ? ? 0 0 0 0 0 0 ? 0 0 0 x ? ? ? ? 0 ? ? 0 0 x 0 ? x 0 0 0 0 x 0 ? 0 0 0 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 0 0 0 0 ? 0 0 0 0 x 0 0 ? 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 x 0 ? ? 0 0 0 0 0 0 ? 0 x ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 x 0 x 0 0 x 0 0 0 ? ? ? ? ? ? ? 0 ? ? 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 ? 0 x 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 ? ? 0 0 ? 0 0 0 0 0 x 0 0 0 ? 0 0 0 0 0 0 0 ? 0 0 x ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 ? ? ? 0 ? ? 0 ? x x 0 0 0 0 0 0 0 0 x 0 ? ? ? ? ? 0 ? ? 0 0 0 0 ? x 0 ? 0 0 0 0 x ? ? 0 0 0 ? ? 0 0 x 0 0 0 0 0 0 ? 0 ? 0 ? 0 ? ? ? 0 x ? ? ? ? x x ? ? x 0 0 0 ? ? ? ? 0 0 0 0 ? x 0 x 0 0 0 0 x 0 0 0 0 0 ? ? 0 0 0 0 ? 0 x 0 0 0 0 0 0 0 0 0 0 0 ? ? ? x 0 0 0 0 ? x x 0 0 0 0 0 0 0 ? ? ? ? ? ? ? x 0 x 0 x x ? x 0 ? ? ? ? ? 0 0 ? ? ? 0 ? 0 ? ? ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? x ? ? ? 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation

Trending

Most Viewed

Loading...