Threat Database Trojans Trojan.MSIL.Krypt.MBVSR

Trojan.MSIL.Krypt.MBVSR

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 3
First Seen: January 23, 2026
Last Seen: April 2, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.MSIL.Krypt.MBVSR
Signature status: No Signature

Known Samples

MD5: 6acfc5427d17033b4dac50e601d20c0e
SHA1: 8bf1ea4c705f35b3460f18d04dce67cd2cae9780
SHA256: 106E554628C27E84B06B88652149C5468BCA392B0DE55322D6C96735E21235C4
File Size: 1.55 MB, 1545216 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 2.0.3.3
Company Name Priform
File Description Haritasi Exporter
File Version 2.0.3.3
Internal Name AmFs.exe
Legal Copyright Copyright © Priform 2026
Original Filename AmFs.exe
Product Name Haritasi Exporter
Product Version 2.0.3.3

File Traits

  • .NET
  • HighEntropy
  • x86

Block Information

Total Blocks: 223
Potentially Malicious Blocks: 92
Whitelisted Blocks: 131
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x x x x 0 0 x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x 0 x x x x x x x x x x x x x 0 0 0 0 x x x 0 0 x x 0 0 0 0 0 0 x 0 0 x x x x x x x x 0 x x x x x x x x x x x x x 0 x 0 x x 0 0 0 0 0 0 0 0 0 x x 0 x x x 0 x x x 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Krypt.MBVSR

Windows API Usage

Category API
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation