Threat Database Trojans Trojan.MSIL.Krypt.MBEAB

Trojan.MSIL.Krypt.MBEAB

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.MSIL.Krypt.MBEAB
Signature status: No Signature

Known Samples

MD5: 50e2ea7c62b8d89c03716124b89ea6c2
SHA1: bad198f1d3143990c030b558e737f3ab853d5340
SHA256: 75791AC60A89994F5645A2249B2E6214F43DB32F9B2BD006A81B67D659F53787
File Size: 1.17 MB, 1172992 bytes
MD5: 6736c06c09b1f1fdf2198324d8d0dfff
SHA1: 47d619fedce9d2e493402f013f70475962ffde70
SHA256: B23A175C0638BF851C2DBA369E796A3E15168EE77257886BEA42BEA8A642E61D
File Size: 1.17 MB, 1173504 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 2.4.2.6
Comments WinRAR archiver
Company Name WinRAR
File Description WinRAR archiver
File Version 4.4.2.2
Internal Name
  • KwJP.exe
  • kwql.exe
Legal Copyright Copyright © Alexander Roshal 1993-2014
Legal Trademarks WinRAR.exe
Original Filename
  • KwJP.exe
  • kwql.exe
Product Name WinRAR
Product Version 4.4.2.2

File Traits

  • .NET
  • HighEntropy
  • x86

Block Information

Total Blocks: 53
Potentially Malicious Blocks: 25
Whitelisted Blocks: 28
Unknown Blocks: 0

Visual Map

0 x 0 0 0 x x x x 0 x 0 x x x x 0 x 0 x x 0 0 x 0 x x 0 x 0 0 0 x 0 x 0 x x 0 x 0 x x x 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Krypt.MBEAB
  • MSIL.Krypt.MBEYC

Windows API Usage

Category API
User Data Access
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation

Trending

Most Viewed

Loading...