Threat Database Trojans Trojan.MSIL.Krypt.H

Trojan.MSIL.Krypt.H

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 21,198
Threat Level: 80 % (High)
Infected Computers: 7
First Seen: January 8, 2013
Last Seen: July 29, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.MSIL.Krypt.H
Signature status: No Signature

Known Samples

MD5: b6952760839e6c317da89195194831c4
SHA1: 87f481263bc58afcee1c5c4dcb336c244ca88758
SHA256: 06E3DBB39311A5F40112BEC2DE199DCC29155BB83208CCA4F19539F7A53560DA
File Size: 6.49 MB, 6493942 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
Comments Software
Company Name Software
File Description Software
File Version 1.0.0.0
Internal Name Software.exe
Legal Copyright Software
Legal Trademarks Software
Original Filename Software.exe
Product Name Software
Product Version 1.0.0.0

File Traits

  • .NET
  • big overlay
  • x86

Block Information

Total Blocks: 56
Potentially Malicious Blocks: 8
Whitelisted Blocks: 41
Unknown Blocks: 7

Visual Map

0 0 0 0 0 x 0 ? x x x x ? ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x x 0 0 x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
User Data Access
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
Other Suspicious
  • AdjustTokenPrivileges
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • VirtualAllocEx
Process Shell Execute
  • CreateProcess

Shell Command Execution

c:\users\user\downloads\87f481263bc58afcee1c5c4dcb336c244ca88758_0006493942