Threat Database Trojans Trojan.MSIL.Krypt.GDE

Trojan.MSIL.Krypt.GDE

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 12,509
Threat Level: 80 % (High)
Infected Computers: 1,107
First Seen: September 19, 2021
Last Seen: September 18, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.MSIL.Krypt.GDE
Signature status: No Signature

Known Samples

MD5: 4a6b93fa2aeb9ee02ad2b6592e3f61e3
SHA1: 5024cc2c60b4dbe93947e682508c58dca24f3fc0
SHA256: 6A227AF911A9516C75602B263CA0639D745BD98D280497FFAB3D98960E2F7563
File Size: 927.23 KB, 927232 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is .NET application
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 2.0.4.0
Company Name VoltX
File Description VoltX
File Version 2.0.4.0
Internal Name VoltX.dll
Original Filename VoltX.dll
Product Name VoltX
Product Version 2.0.4

File Traits

  • .NET
  • Confuser
  • HighEntropy
  • ntdll
  • x64

Block Information

Total Blocks: 1,136
Potentially Malicious Blocks: 33
Whitelisted Blocks: 433
Unknown Blocks: 670

Visual Map

? ? ? ? ? ? ? ? 0 0 0 ? ? ? 0 ? ? 0 0 0 ? ? ? 0 x x x 0 ? x 0 0 0 0 0 0 ? 0 0 0 ? ? 0 0 x 0 0 0 0 0 ? 0 0 0 ? 0 x 0 0 0 0 0 ? 0 x 0 ? 0 0 0 ? 0 0 0 ? 0 0 0 ? 0 x 0 0 0 0 0 ? 0 0 0 ? 0 0 0 x 0 0 ? ? ? ? ? 0 0 ? 0 ? 0 ? ? ? ? ? 0 ? 0 ? 0 ? ? ? 0 ? ? ? 0 0 ? 0 0 ? ? 0 ? ? ? ? ? 0 0 ? ? ? ? ? ? 0 ? ? x ? 0 0 0 0 ? 0 ? 0 ? 0 ? 0 ? ? ? ? ? ? 0 ? 0 ? 0 ? 0 0 ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 0 ? 0 ? 0 ? 0 0 0 ? ? ? 0 ? 0 ? 0 0 0 ? 0 0 0 ? ? 0 0 ? ? 0 ? 0 0 ? ? ? 0 ? ? 0 ? 0 0 ? 0 0 0 ? ? 0 ? 0 0 ? ? ? 0 ? ? 0 ? 0 0 ? 0 0 0 ? ? 0 0 0 0 ? 0 ? 0 0 0 ? ? ? ? ? 0 0 0 ? 0 ? ? 0 ? ? ? ? 0 0 ? ? 0 ? 0 0 ? 0 ? 0 ? ? 0 ? 0 0 ? ? ? ? 0 0 ? ? 0 0 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? 0 ? 0 0 ? ? 0 x 0 0 ? ? 0 0 ? ? 0 ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 0 ? ? ? x 0 0 ? ? 0 ? 0 0 ? 0 ? 0 0 0 ? 0 ? 0 ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? x ? ? ? 0 0 ? ? ? 0 ? 0 0 ? 0 ? ? 0 0 x x ? ? 0 ? ? ? ? 0 0 ? ? ? ? ? ? x ? 0 0 ? 0 ? ? 0 ? 0 ? 0 ? ? ? ? ? 0 ? ? ? 0 0 ? ? 0 0 0 0 ? 0 0 ? 0 ? ? 0 0 0 ? ? 0 ? ? ? 0 0 ? ? 0 ? 0 0 ? 0 ? ? 0 0 0 ? ? 0 ? 0 ? 0 0 0 ? 0 ? ? ? ? x 0 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 0 0 0 0 ? 0 ? x ? ? 0 0 ? 0 ? ? 0 ? 0 0 ? ? ? ? ? 0 ? 0 ? ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? 0 0 0 ? ? ? 0 ? 0 0 ? 0 0 0 0 ? x 0 0 0 ? 0 ? ? ? ? ? ? 0 0 ? ? ? 0 ? ? ? 0 ? ? ? ? ? ? ? 0 0 ? 0 0 ? 0 ? 0 ? ? ? 0 ? ? 0 x 0 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 x x x ? ? ? ? 0 ? ? ? ? 0 0 0 0 ? ? ? ? ? ? ? ? ? 0 0 ? ? 0 0 0 ? ? ? ? ? ? 0 ? ? ? ? 0 0 ? 0 ? ? ? ? ? ? ? 0 ? ? 0 0 0 0 ? 0 ? ? 0 0 ? ? 0 ? 0 0 ? ? ? 0 ? ? 0 0 ? ? ? 0 0 0 0 ? 0 ? 0 ? ? ? ? ? ? 0 ? 0 0 ? 0 ? 0 ? ? ? ? 0 ? ? 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? 0 ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? 0 0 ? ? 0 0 ? ? 0 ? 0 0 ? 0 ? x ? ? ? ? ? ? ? ? ? ? ? x 0 0 ? ? ? ? ? 0 0 0 0 ? ? 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? 0 ? ? 0 ? 0 0 ? ? ? 0 ? ? 0 ? 0 0 ? 0 ? 0 ? ? 0 x 0 0 ? 0 ? ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? ? ? 0 ? ? ? ? ? 0 0 ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? ? x ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? 0 0 ? ? ? ? ? 0 ? ? ? ? ? 0 0 ? ? 0 0 0 ? 0 0 0 0 0 ? 0 0 x 0 ? 0 0 ? 0 ? 0 ? ? ? x ? x x ? ? ? ? ? x ? ? ? ? ? 0 ? 0 0 ? ? ? ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
Show More
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWriteFile
  • UNKNOWN
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation