Threat Database Trojans Trojan.MSIL.Krypt.MDKN

Trojan.MSIL.Krypt.MDKN

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 20,640
Threat Level: 80 % (High)
Infected Computers: 2
First Seen: July 2, 2026
Last Seen: July 14, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.MSIL.Krypt.MDKN
Signature status: No Signature

Known Samples

MD5: 683c7276bbdc7df8740788e245a461d5
SHA1: e8a104ec01ee0fa1c25022eb13ae28150485f212
SHA256: 02727498170EDCB29C041A632172EDA8B43C89F7235346B03B174B3E5985BB38
File Size: 1.34 MB, 1344000 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 0.0.0.0
File Version 0.0.0.0
Internal Name fDlG.exe
Original Filename fDlG.exe
Product Version 0.0.0.0

File Traits

  • .NET
  • HighEntropy
  • x86

Block Information

Total Blocks: 68
Potentially Malicious Blocks: 49
Whitelisted Blocks: 19
Unknown Blocks: 0

Visual Map

0 0 0 0 x x x x x 0 x x x x x x x x x x x x 0 0 x x x 0 x x x x x x x x x x 0 0 x x x x 0 x x 0 x x x x x x x x x x 0 0 x 0 0 0 0 x 0 x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Krypt.MDKN

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey

Windows API Usage

Category API
User Data Access
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Encryption Used
  • BCryptOpenAlgorithmProvider