Threat Database Trojans Trojan.MSIL.Krypt.MBARC

Trojan.MSIL.Krypt.MBARC

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 18,792
Threat Level: 80 % (High)
Infected Computers: 612
First Seen: May 22, 2023
Last Seen: February 18, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.MSIL.Krypt.MBARC
Signature status: Self Signed

Known Samples

MD5: 5a3725ae7b123f1d8ec09e8ea12d8230
SHA1: c11868fd862e57c6ebafd95826e1ff053e040858
SHA256: EBE2ABD4BBD24F3B0B55FB2F66134C9D65A80D4201BD6B29CE9E720AA5DC5FD9
File Size: 4.60 MB, 4595448 bytes
MD5: 6af7b58db29337a89f61f20caee4a657
SHA1: 861ed60021b640bdc9901ceb40d68e70b487eb79
SHA256: 28850F8C4436CC50289A40A5EBED216F410D230777C55EFA98C2286779C2CFB8
File Size: 1.31 MB, 1312912 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 1.2.0.0
  • 1.0.0.0
File Description
  • complete_supplement_with_textures
  • Game
File Version
  • 1.2.0.0
  • 1.0.0.0
Internal Name
  • complete_supplement_with_textures.exe
  • IsSignUnspecifiedBy.exe
Legal Copyright
  • Copyright © 2013
  • Copyright © 2023
Original Filename
  • complete_supplement_with_textures.exe
  • IsSignUnspecifiedBy.exe
Product Name
  • complete_supplement_with_textures
  • Game
Product Version
  • 1.2.0.0
  • 1.0.0.0

Digital Signatures

Signer Root Status
Oculus VR, LLC DigiCert Assured ID Root CA Hash Mismatch
Yamaha WXA-50 Yamaha WXA-50 Self Signed

File Traits

  • .NET
  • HighEntropy
  • NewLateBinding
  • RijndaelManaged
  • x86

Block Information

Total Blocks: 894
Potentially Malicious Blocks: 9
Whitelisted Blocks: 789
Unknown Blocks: 96

Visual Map

x ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? 0 0 x x x 0 0 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? ? ? ? 0 ? ? ? 0 ? 0 ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x ? ? ? ? ? 0 ? 0 0 0 ? 0 ? 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 0 ? 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 ? 0 ? 0 0 0 ? 0 ? ? ? ? ? 0 ? ? 0 ? ? ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x ? 0 ? 0 0 0 0 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 0 0 0 ? ? ? ? ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 ? 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Agent.ACLF
  • MSIL.Coinminer.AEA
  • MSIL.Downloader.CLQ
  • MSIL.HackAgent.SB
  • MSIL.Krypt.MBARC
Show More
  • MSIL.Krypt.MBARD
  • MSIL.Krypt.MBARG
  • MSIL.Krypt.MBARH
  • MSIL.Krypt.MBAXE
  • MSIL.Krypt.MBAXL
  • MSIL.Krypt.MBAXO
  • MSIL.Stealer.CL

Windows API Usage

Category API
User Data Access
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation

Trending

Most Viewed

Loading...