Threat Database Trojans Trojan.MSIL.Krypt.GJL

Trojan.MSIL.Krypt.GJL

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 23,378
Threat Level: 80 % (High)
Infected Computers: 24
First Seen: June 18, 2022
Last Seen: May 7, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.MSIL.Krypt.GJL
Signature status: No Signature

Known Samples

MD5: 26ec2e5edf498355e2a9f2174c229c76
SHA1: 974e13d20cb0c4555d160f69fbc60b3e1f7d287d
SHA256: 7874CF960283CC02FEA49F70D02AD07CD91A8BD77079B3ADFAEBA5B8F809A1C9
File Size: 2.93 MB, 2926080 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 120.32.54.10
Comments 31.0.0.28
Company Name UltraEdit Software
File Description defaultsoftone
File Version 120.32.54.10
Internal Name defaultsoftone.exe
Legal Copyright Copyright \xA9 2015 IDM Computer Solutions, Inc
Original Filename defaultsoftone.exe
Product Version 120.32.54.10

File Traits

  • .NET
  • GenKrypt
  • HighEntropy
  • NewLateBinding
  • Reactor
  • Reflective
  • RijndaelManaged
  • x86

Block Information

Total Blocks: 422
Potentially Malicious Blocks: 292
Whitelisted Blocks: 130
Unknown Blocks: 0

Visual Map

x x x x x x 0 x 0 x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x 0 x x x x x x x x 0 x x x x x x x x 0 x x x x x x x x x x x x x x 0 x x x x x x x x x x x x 0 x x x 0 x x x x x x x x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x 0 x 0 x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x 0 x x x x x x x x 0 x x x x x x x x 0 x x x x x x x x x x x x x x 0 x x x x x x x x x x x x 0 x x x 0 x x x x x x x x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x 0 x 0 x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x 0 x x x x x x x x 0 x x x x x x x x 0 x x x x x x x x x x x x x x 0 x x x x x x x x x x x x 0 x x x 0 x x x x x x x x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Krypt.GJLC

Windows API Usage

Category API
User Data Access
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Anti Debug
  • NtQuerySystemInformation
Other Suspicious
  • AdjustTokenPrivileges
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
  • VirtualAllocEx
Process Shell Execute
  • CreateProcess

Shell Command Execution

C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe

Related Posts

Trending

Most Viewed

Loading...