Threat Database Trojans Trojan.MSIL.Krypt.MBDF

Trojan.MSIL.Krypt.MBDF

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 8,698
Threat Level: 80 % (High)
Infected Computers: 10,460
First Seen: June 5, 2021
Last Seen: February 10, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.MSIL.Krypt.MBDF
Signature status: Self Signed

Known Samples

MD5: 6aec2d2080a2385e2ebd911c08a77415
SHA1: fd1513ab468ef7888304212dbd5c962eb2a54290
File Size: 2.24 MB, 2243520 bytes
MD5: 1d708edc1bc8b6afcb8bd44d43a08865
SHA1: 2532f805c253ec63ab58a5e73777667e99e14db3
SHA256: 4FDC4C0B7FE5F0B942E2028B9DA3EE5F5FE8DFA2169F90BBAF9704223348E067
File Size: 2.40 MB, 2395648 bytes
MD5: cfcabac94ea6aa319b766b0e32c4153d
SHA1: 05a2c972c5f91df14d201f0cbecc6c989d25d32b
SHA256: 1467DA1F49AF44D8E8472112B4E540354DB3A2A338753B8E171FE8B9910CB0F3
File Size: 2.24 MB, 2243584 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
Comments Ferramentas inteligentes para divulgação e marketing. Temos a solução para elevar seu negócio e trazer resultados expressivos, nossas ferramentas inteligentes irão automatizar todo o seu trabalho. Com nossas ferramentas você poderá fazer trabalhos que uma pessoa normal levaria dias ou até semanas em apenas minutos! É um prazer ter você junto com a gente...
File Description
  • Olx Extrator W.A
  • _구울서버 접속기
  • _탄탄 서버 접속기
File Version 1.0.0.0
Internal Name
  • Olx Extrator W.A.exe
  • _구울서버 접속기.exe
  • _탄탄 서버 접속기.exe
Legal Copyright
  • Copyright © 2022
  • Ver.2.0 / Date.2024 (Ex)
  • Ver.2.0 / Date.2024 (Fx)
Original Filename
  • Olx Extrator W.A.exe
  • _구울서버 접속기.exe
  • _탄탄 서버 접속기.exe
Product Name Olx Extrator W.A
Product Version 1.0.0.0

Digital Signatures

Signer Root Status
FX CA FX CA Self Signed

File Traits

  • .NET
  • .sdata
  • HighEntropy
  • NewLateBinding
  • Reactor
  • RijndaelManaged
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 52
Potentially Malicious Blocks: 0
Whitelisted Blocks: 45
Unknown Blocks: 7

Visual Map

0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Agent.FAT
  • MSIL.Agent.PI
  • MSIL.Coinminer.AV
  • MSIL.Gamehack.BOT
  • MSIL.Gamehack.BOWB
Show More
  • MSIL.Gamehack.BOWD
  • MSIL.Krypt.BFA
  • MSIL.Krypt.BFC
  • MSIL.Krypt.FHB
  • MSIL.Krypt.PDC
  • MSIL.Krypt.YCE
  • MSIL.Kryptik.FHM
  • NekoStealer.J
  • NekoStealer.JA

Windows API Usage

Category API
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Process Manipulation Evasion
  • ReadProcessMemory
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Encryption Used
  • BCryptOpenAlgorithmProvider

Trending

Most Viewed

Loading...