Threat Database Trojans Trojan.MSIL.Krypt.UAB

Trojan.MSIL.Krypt.UAB

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 20,654
Threat Level: 80 % (High)
Infected Computers: 1,739
First Seen: April 22, 2021
Last Seen: September 21, 2025
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.MSIL.Krypt.UAB
Signature status: No Signature

Known Samples

MD5: 7987c18d52974c6525a620eec6859b7a
SHA1: 2368c00317ab909566de99f9357b5b2f2e94978c
SHA256: 98935779C33329358CAA28C9452C932C58B6F1EE2C1C8EF549B9D08883C537E2
File Size: 296.45 KB, 296448 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 197.98.173.35
Company Name VLC Media Player
File Description Bitdefender Antivirus
File Version 199.299.7.262
Internal Name Microsoft Word Host.exe
Legal Copyright Microsoft Edge Host
Legal Trademarks Adobe Photoshop
Original Filename Microsoft Word Host.exe
Product Name FileZilla Upgrade
Product Version 197.98.173.35

File Traits

  • .NET
  • x86

Block Information

Total Blocks: 1,025
Potentially Malicious Blocks: 914
Whitelisted Blocks: 5
Unknown Blocks: 106

Visual Map

0 0 0 x 0 0 ? ? ? ? x x x x x x x x x x x ? x x x x x x ? ? x x x x x x x x x x x x x x x x x x ? ? x x ? ? ? ? ? x x ? x x x ? x ? x ? x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x ? x ? x x ? x x x x x x x x x x x ? ? ? ? x ? x ? x ? x x x x ? x ? ? ? x x x x x x x x x x x x x x ? x x x x ? x x x ? x x x x x x x ? x x x x x x x x x x x x x x x x x x x x x x x x x x x ? ? ? x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x ? x x x x x x x x x x x x x x x x x x ? x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x ? x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x ? x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x ? x x x x x x x ? x x x x x x x x x x x x x x x ? x x x x x x ? x x x x x x x x ? x x x x ? x x x x x x x ? x x x x x x ? x x x x x x x x ? x x x x x x x ? x x x x x x ? x x x x x x x ? x x x x x ? x x x x x x x x ? x x x x x ? x x x x ? x x x x x x x x x x x x x x x ? x x x x x x x x ? x x x x x x ? x x x x x x ? x x x x x x ? x x x x x x x x ? x x x x x x x ? x x x x x x ? x x x x x x x x x ? x x x ? x x x x x x ? x x x x x ? x x x x x ? x x x x x ? x x x x x ? x x x ? x x x x x x x ? x x x x x x ? x x x x x ? x x x x x ? x x x ? x x x x x ? x x x x x x ? x x x x ? x x x x ? x x x x x ? x x ? x x x x x x ? x x x x x x x ? x x x x x ? x x x x ? x x x x ? x x x x x x ? x x x x x x x x ? x x x x x ? x x x x x x x x ? x x x x ? x x x x ? x x x x x x ? x x x x x ? x x x x x x x ? x x x x x x ? x x x x x x x ? x x x x x ? x x x x x x x x x ? x x x x x x ? x x ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Krypt.YAGC

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
Show More
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtYieldExecution
  • UNKNOWN
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent

Trending

Most Viewed

Loading...