Threat Database Trojans Trojan.MSIL.Krypt.GDAJ

Trojan.MSIL.Krypt.GDAJ

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 21,037
Threat Level: 80 % (High)
Infected Computers: 7
First Seen: August 22, 2024
Last Seen: April 12, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.MSIL.Krypt.GDAJ
Signature status: Hash Mismatch

Known Samples

MD5: 628aea57a86d73914247cbd9d8a214bd
SHA1: a76b074595cbe841a60cbd382f57618376a9fece
SHA256: 201389F314AAEE5052611C753E9D5FEA7C9AB184BD392247FDF2D301AC952FAE
File Size: 206.70 KB, 206696 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
Comments Windows Write
Company Name Microsoft Corporation
File Description Windows Write
File Version 6.3.9600.17415
Internal Name write.exe
Legal Copyright © Microsoft Corporation. All rights reserved.
Original Filename write.exe
Product Name Microsoft® Windows® Operating System
Product Version 6.3.9600.17415

Digital Signatures

Signer Root Status
ViewSonic Corporation VeriSign Class 3 Code Signing 2009-2 CA Hash Mismatch

File Traits

  • .NET
  • HighEntropy
  • x86

Block Information

Total Blocks: 106
Potentially Malicious Blocks: 6
Whitelisted Blocks: 60
Unknown Blocks: 40

Visual Map

? ? ? ? ? ? 0 0 0 0 0 0 0 ? ? ? ? ? ? ? 0 ? 0 x 0 ? ? ? x ? 0 0 0 0 ? ? ? 0 x ? ? 0 ? 0 0 0 0 0 0 0 ? 0 0 0 ? ? 0 0 0 0 0 0 0 0 ? 0 0 0 ? ? 0 0 ? x 0 0 0 ? ? ? 0 x ? ? 0 ? x 0 0 0 0 0 0 ? 0 0 0 0 ? 0 0 ? 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.0.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.1.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.2.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\music\dialer_work.exe Synchronize,Write Attributes
c:\users\user\music\dialer_work.exe Synchronize,Write Data

Windows API Usage

Category API
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Other Suspicious
  • AdjustTokenPrivileges

Trending

Most Viewed

Loading...