Threat Database Trojans Trojan.MSIL.Krypt.GBDG

Trojan.MSIL.Krypt.GBDG

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 28,262
Threat Level: 80 % (High)
Infected Computers: 2
First Seen: March 5, 2024
Last Seen: December 27, 2025
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.MSIL.Krypt.GBDG
Signature status: No Signature

Known Samples

MD5: cb4cb617a42b0701b65b2ac87308f4d9
SHA1: f76bce0fd91669a08f48da3175f130e7fab586d8
SHA256: 3D554455990E373EE1C6F40A8C81FE18DB3493A6FE66EE3F6BC7B34BEAD4D0AE
File Size: 223.66 KB, 223655 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Build Time 5/5/2017 1:06:52 AM
Company Name Skype Technologies S.A.
File Description Skype
File Version 7.35.0.103
Internal Name Skype.exe
Legal Copyright © 2003 - 2012 Skype and/or Microsoft
Original Filename Skype.exe
Product Name Skype
Product Version 7.35

File Traits

  • .NET
  • big overlay
  • HighEntropy
  • RijndaelManaged
  • x86

Block Information

Total Blocks: 238
Potentially Malicious Blocks: 118
Whitelisted Blocks: 120
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 x 0 x x x x 0 0 0 x x x x 0 x 0 0 0 x x 0 x x x x x 0 x 0 0 x 0 0 x 0 0 0 x x x x x 0 x x x x x 0 0 0 0 0 0 0 x x 0 0 x x 0 x 0 0 0 x 0 x 0 x 0 0 0 x x 0 0 0 x 0 x x x x 0 0 0 0 x x x x x 0 x 0 x x x x x 0 0 0 0 0 x 0 0 x 0 x x x x x x 0 x x x 0 0 x x x x 0 0 0 0 0 x x x 0 0 x 0 0 0 x x 0 0 0 0 0 0 x 0 x x x 0 x 0 x x x x x x x 0 x x x x x 0 0 x x x x x x x x 0 x 0 x x 0 0 x x 0 0 x x 0 x 0 x x x 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Krypt.GBDB
  • MSIL.Krypt.GBDE
  • MSIL.Krypt.GBDG

Windows API Usage

Category API
User Data Access
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Other Suspicious
  • AdjustTokenPrivileges
Encryption Used
  • BCryptOpenAlgorithmProvider
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
  • VirtualAllocEx
Process Shell Execute
  • CreateProcess

Shell Command Execution

c:\users\user\downloads\f76bce0fd91669a08f48da3175f130e7fab586d8_0000223655

Trending

Most Viewed

Loading...