Threat Database Trojans Trojan.MSIL.Krypt.MBSA

Trojan.MSIL.Krypt.MBSA

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 23,657
Threat Level: 80 % (High)
Infected Computers: 102
First Seen: September 22, 2021
Last Seen: November 24, 2025
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.MSIL.Krypt.MBSA
Signature status: No Signature

Known Samples

MD5: b270e3b6f8730956d57328346f6e7e84
SHA1: 93e10502cb65c00eac74c7a6f91351639f3a671f
SHA256: 4A0A042CDF43593759488F99E62E50982D463DBC2101CF3D434A509B7091DC00
File Size: 235.01 KB, 235008 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name hFIF
File Version 4.9.3.9
Legal Copyright Amohd
Legal Trademarks Afcnk
Product Name krd
Product Version 4.9.3.9

File Traits

  • .NET
  • HighEntropy
  • SmartAssembly
  • x86

Block Information

Total Blocks: 21
Potentially Malicious Blocks: 10
Whitelisted Blocks: 6
Unknown Blocks: 5

Visual Map

x ? x ? x ? ? x ? x x x x 0 0 0 x 0 0 x 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
User Data Access
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext

Trending

Most Viewed

Loading...