Threat Database Trojans Trojan.MSIL.Krypt.GHFE

Trojan.MSIL.Krypt.GHFE

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 28,073
Threat Level: 80 % (High)
Infected Computers: 17
First Seen: August 26, 2024
Last Seen: March 2, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.MSIL.Krypt.GHFE
Signature status: No Signature

Known Samples

MD5: 71758fcc968c48c7db3f4f0ce2cadd0a
SHA1: ad59881eba2beec64330506faf07ed2b85ef88f5
SHA256: 2CE6374DCBAC52BA819CE67A77A63F1A6AED0747E741B1611BB56DB14216558E
File Size: 157.70 KB, 157696 bytes
MD5: cf99deb7a4ff5c357473b6168a6779a7
SHA1: e6f0b988f6c72789bcb2e38709a438f7aaf808dd
SHA256: 0A02457D05BC8A0AA8A2BC36245C630CA94D566E13FBAA4861227457371FBE9C
File Size: 154.11 KB, 154112 bytes
MD5: d8a328bd2a9fdfd3b83384300d8268d3
SHA1: 8dd15790a022ce2ac1da7dbc103e61c683c3cf58
SHA256: 948076B38242BE1268D8120E77E25933052E0B0D47762EA53F69C364F0CE851F
File Size: 157.70 KB, 157696 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
File Description
  • nasidnio
  • olomuhsa
  • omeixlul
File Version 1.0.0.0
Internal Name
  • nasidnio.exe
  • olomuhsa.exe
  • omeixlul.exe
Legal Copyright Copyright © 2015
Original Filename
  • nasidnio.exe
  • olomuhsa.exe
  • omeixlul.exe
Product Name
  • nasidnio
  • olomuhsa
  • omeixlul
Product Version 1.0.0.0

File Traits

  • .NET
  • HighEntropy
  • x86

Block Information

Total Blocks: 71
Potentially Malicious Blocks: 0
Whitelisted Blocks: 37
Unknown Blocks: 34

Visual Map

0 ? ? 0 0 0 0 0 0 ? 0 0 0 0 ? ? ? ? ? ? ? ? ? 0 0 ? 0 0 ? 0 0 0 0 ? ? 0 0 ? ? ? ? ? 0 0 ? ? 0 0 ? ? 0 0 0 ? ? ? 0 0 0 ? 0 0 0 ? ? 0 0 ? ? ? 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
User Data Access
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Encryption Used
  • CryptAcquireContext

Trending

Most Viewed

Loading...