Threat Database Trojans Trojan.MSIL.Krypt.MDFI

Trojan.MSIL.Krypt.MDFI

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 18,056
Threat Level: 80 % (High)
Infected Computers: 7
First Seen: October 12, 2024
Last Seen: December 12, 2025
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.MSIL.Krypt.MDFI
Signature status: No Signature

Known Samples

MD5: 1403ab69ae0ef567f6b48951e8685208
SHA1: 40b00d666b58aed42b4f3f4eb3c287f4606e6bd1
SHA256: 118FAF33BEA0E1BBCA037C6ACC9EAB3EA2BD2223818E58DEDE1E32CE7DA9189A
File Size: 1.73 MB, 1726800 bytes
MD5: f9297fb6dc677dde32229e69e6fe0017
SHA1: ca4f90b5a9a4df7f3fcc520c96833cb62df3e2f7
SHA256: 5113F3D281B84FDBA2AD26ADA88816914003076122695E55D14FEC3564E2D5D1
File Size: 1.48 MB, 1476096 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
Comments BI2F79E=J3C=:6E>?8F5?;
Company Name
  • Bitwarsoft Limited
  • F97F<3H5GD44A@>@
File Description
  • 6H?;636BDB?5@4<2>@<D4DJ
  • Bitwar Renamer
File Version
  • 2.0.0.0
  • 1.2.3.3
Internal Name
  • Adobe-Acrobat-Pro-DC-2024.exe
  • bitwarrenamer.exe
Legal Copyright
  • Copyright (C) Bitwarsoft Limited All Rights Reserved.
  • Copyright © 2024 F97F<3H5GD44A@>@
Original Filename Adobe-Acrobat-Pro-DC-2024.exe
Product Name
  • 6H?;636BDB?5@4<2>@<D4DJ
  • Bitwar Renamer
Product Version
  • 2.0.0.0
  • 1.2.3.3

Digital Signatures

Signer Root Status
Holmez Softsolutions Pte. Ltd. DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Hash Mismatch
Holmez Softsolutions Pte. Ltd. DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Hash Mismatch

File Traits

  • .NET
  • HighEntropy
  • NewLateBinding
  • x86

Block Information

Total Blocks: 698
Potentially Malicious Blocks: 55
Whitelisted Blocks: 219
Unknown Blocks: 424

Visual Map

0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 ? ? x ? ? 0 0 0 0 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? 0 ? 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? ? 0 0 0 0 0 ? 0 0 0 x 0 0 ? ? x x ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? ? x 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? x ? ? 0 ? ? x 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 0 0 ? 0 0 0 ? 0 0 0 0 ? 0 0 ? ? ? ? ? x ? ? ? ? ? ? 0 ? ? ? ? ? ? x 0 ? 0 ? ? ? ? ? 0 ? x ? ? ? ? 0 x ? ? ? 0 x 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x x 0 0 0 0 0 0 ? 0 0 ? 0 x 0 0 0 0 0 ? ? ? ? ? ? ? ? x ? ? ? x x x x x 0 0 0 0 ? ? 0 0 ? x ? ? x 0 0 0 x ? x ? ? x x ? ? x x ? ? ? ? x 0 x ? ? ? x ? x ? 0 x x x ? ? x x ? ? x 0 ? 0 ? x x ? x x ? ? ? ? ? 0 0 ? ? x ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? 0 0 x 0 x 0 ? 0 ? 0 x x 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.AgentTesla.CX

Windows API Usage

Category API
User Data Access
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Other Suspicious
  • AdjustTokenPrivileges

Trending

Most Viewed

Loading...