Threat Database Trojans Trojan.MSIL.Krypt.KEF

Trojan.MSIL.Krypt.KEF

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 9
First Seen: March 10, 2022
Last Seen: March 4, 2024
OS(es) Affected: Windows

The detection of Trojan.MSIL.Krypt.KEF on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the security and integrity of your computer, and it's essential to understand its nature and how to remove it effectively.

What Is Trojan.MSIL.Krypt.KEF?

Trojan.MSIL.Krypt.KEF is a type of Trojan horse malware that can infect your computer through various means, such as downloading malicious software, visiting compromised websites, or opening infected email attachments. The name "Trojan" refers to the fact that this malware disguises itself as a legitimate program, allowing it to bypass security measures and gain access to your system.

Once inside, Trojan.MSIL.Krypt.KEF can cause significant damage, including data theft, system crashes, and unauthorized access to your computer. It's crucial to take prompt action to remove this malware and prevent further harm.

How Trojan.MSIL.Krypt.KEF Operates

Trojan.MSIL.Krypt.KEF operates by exploiting vulnerabilities in your system, allowing it to install itself and run without your knowledge or consent. It can then connect to remote servers, download additional malware, and transmit sensitive information back to its creators.

This type of malware can also modify system settings, disable security software, and create backdoors for future attacks. Its primary goal is to remain undetected, allowing it to continue causing harm and stealing valuable data.

Symptoms of Infection

Identifying the symptoms of a Trojan.MSIL.Krypt.KEF infection can be challenging, as it often disguises itself as a legitimate program. However, some common signs of infection include slow system performance, frequent crashes, and unfamiliar programs or icons on your desktop.

You may also notice unusual network activity, such as unexpected data transfers or unfamiliar connections. If you suspect that your system is infected, it's essential to take immediate action to remove the malware.

How to Remove Trojan.MSIL.Krypt.KEF

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for a more effective removal process.
  2. Run a full scan with a reputable anti-malware tool, such as SpyHunter, to detect and remove all instances of the malware.
  3. Uninstall any suspicious programs or applications that may be related to the infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your computer and run another scan to ensure that the malware has been completely removed.

It's essential to note that removing Trojan.MSIL.Krypt.KEF requires patience and caution. Be sure to follow the removal steps carefully, and consider seeking professional help if you're unsure or uncomfortable with the process.

Conclusion

The detection of Trojan.MSIL.Krypt.KEF on your system is a serious issue that requires immediate attention. By understanding the nature of this malware and following the removal steps outlined above, you can help protect your computer and sensitive data from further harm.

Remember to always be cautious when downloading software, visiting websites, and opening email attachments, as these are common ways for malware to infect your system. By staying vigilant and taking proactive measures, you can help prevent future infections and keep your computer secure.

Analysis Report

General information

Family Name: Trojan.MSIL.Krypt.KEF
Signature status: No Signature

Known Samples

MD5: b91191613897ec505b2500148ae19195
SHA1: bcbcf616b52ac4f507cb98d2018a42aba60dc4d9
SHA256: BF4912CFF3D5B486382608B1A390D06ABB9BC895C9159D31341693E86E2A9285
File Size: 4.89 MB, 4886528 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is .NET application
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 5.9.27.0
Company Name CADViewer
File Description CADViewer
File Version 5.9.27
Internal Name CADViewer.exe
Original Filename CADViewer.exe
Product Name CADViewer
Product Version 5.9.27

File Traits

  • .NET
  • HighEntropy
  • Run
  • x64

Block Information

Total Blocks: 1,447
Potentially Malicious Blocks: 138
Whitelisted Blocks: 659
Unknown Blocks: 650

Visual Map

0 0 0 0 0 0 0 0 0 x x x x x x 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 x x x 0 0 x x x x 0 x x x x x ? x 0 x x 0 x 0 x x x 0 0 0 0 0 0 0 0 ? 0 ? ? ? 0 ? 0 0 0 0 0 0 ? 0 ? 0 ? ? ? ? ? ? ? ? 0 ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? 0 0 ? ? ? ? 0 0 ? ? 0 ? ? ? ? ? ? 0 0 0 ? ? ? 0 ? 0 0 0 0 0 0 ? ? ? ? 0 0 0 0 0 ? 0 ? ? ? ? 0 x ? 0 0 0 0 ? 0 0 0 0 0 ? ? 0 0 0 0 ? ? 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? ? 0 0 0 0 0 0 ? 0 0 0 0 ? ? ? 0 0 ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 0 ? 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? 0 x 0 0 0 0 0 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 ? 0 ? 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x ? 0 x ? 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? 0 ? 0 0 ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 ? 0 x 0 ? 0 x 0 x 0 0 0 0 0 0 0 0 ? 0 x 0 x 0 x 0 x 0 ? ? ? 0 0 0 ? ? ? ? ? ? ? x ? 0 ? 0 x 0 x 0 x 0 x 0 x ? ? ? ? ? 0 x 0 x 0 x ? 0 0 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 x 0 x ? ? ? 0 0 0 0 0 x 0 x 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 x 0 x ? 0 x 0 x 0 x 0 x ? 0 0 0 0 ? ? 0 0 0 ? ? ? ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 x 0 x 0 x ? 0 0 0 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 ? ? ? ? 0 x ? 0 ? ? ? ? ? ? 0 0 ? ? 0 0 0 0 0 x 0 x 0 x 0 x 0 0 0 0 ? ? ? ? ? 0 0 ? ? ? ? 0 x 0 x 0 x 0 x 0 x ? ? ? ? ? ? 0 0 0 ? ? ? 0 0 ? ? ? 0 ? 0 x 0 x ? ? ? ? ? ? ? ? ? ? 0 0 0 ? 0 0 0 ? ? 0 x ? 0 x ? 0 ? ? ? x x x x x 0 ? ? ? ? ? 0 0 ? 0 0 ? 0 x 0 x 0 x ? ? ? ? 0 0 ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? x 0 0 0 0 ? 0 ? ? ? ? ? ? 0 ? 0 0 ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? 0 0 0 ? 0 0 0 ? 0 ? 0 0 ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? ? ? 0 ? 0 ? 0 0 ? ? ? 0 0 ? 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? x ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? x ? ? ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 ? ? ? 0 0 0 0 0 0 0 ? 0 ? ? ? 0 ? ? 0 0 0 0 0 0 ? ? 0 ? ? ? 0 0 0 ? 0 ? 0 x 0 0 x x x x x x 0 x x ? 0 0 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 0 ? ? 0 ? 0 ? 0 ? ? ? ? 0 ? 0 ? ? ? 0 ? ? 0 ? ? ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 ? ? ? ? ? x ? ? 0 0 0 0 ? 0 ? 0 ? 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 0 0 0 0 ? ? ? 0 ? ? ? 0 0 0 0 0 ? ? 0 0 0 0 0 ? ? ? x 0 ? 0 ? 0 ? 0 0 ? ? x x x x x x x ? x x x x x x x x x x x ? 0 ? ? ? ? 0 0 ? 0 0 ? ? ? ? ? ? ? ? 0 ? 0 0 0 ? ? ? ? ? ? ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
Show More
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider

Related Posts

Trending

Most Viewed

Loading...