Threat Database Trojans Trojan.MSIL.Krypt.VAA

Trojan.MSIL.Krypt.VAA

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 10,665
Threat Level: 80 % (High)
Infected Computers: 3,357
First Seen: January 3, 2013
Last Seen: October 10, 2025
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.MSIL.Krypt.VAA
Signature status: No Signature

Known Samples

MD5: 0963a72804b90f566eb2754f8c6a3af2
SHA1: f9423d32e612451cc2e53c2bdf101ad70468827d
SHA256: 16AEAA7EFF91A40984C42066BCE47F17545D9C0478850575741C6AFDD328141F
File Size: 183.30 KB, 183296 bytes
MD5: cf07ef9e5dc0a7c386637974c9733cca
SHA1: 5e0c9133eca9b424624b761a27f3812df827704e
SHA256: E8F58969694B57552D15189F2942B202B57F90D23AE9E068AE7DB0E086EE31A8
File Size: 813.06 KB, 813056 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
Comments Space Complexity Calculator
File Description SpaceCalculator
File Version 1.0.0.0
Internal Name bpNG.exe
Legal Copyright Copyright © 2025
Original Filename bpNG.exe
Product Name SpaceCalculator
Product Version 1.0.0.0

File Traits

  • .NET
  • HighEntropy
  • No Version Info
  • x86

Block Information

Total Blocks: 205
Potentially Malicious Blocks: 2
Whitelisted Blocks: 51
Unknown Blocks: 152

Visual Map

0 ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? x ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? 0 0 0 x ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? ? ? 0 0 0 0 0 0 ? 0 ? 0 0 ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\appdata\local\temp\tmp8964.tmp Generic Write,Read Attributes
c:\users\user\appdata\roaming\bfeb5820-9643-42ad-a79f-071dff4d8e64\run.dat Generic Write,Read Attributes

Windows API Usage

Category API
User Data Access
  • GetComputerName
  • GetUserDefaultLocaleName
  • GetUserName
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Process Shell Execute
  • CreateProcess
Network Winsock2
  • WSASend
  • WSASocket
  • WSAStartup
Network Winsock
  • bind
  • closesocket
  • getpeername
  • setsockopt

Shell Command Execution

"schtasks.exe" /create /f /tn "SMTP Subsystem" /xml "C:\Users\Cpinbezc\AppData\Local\Temp\tmp8964.tmp"

Trending

Most Viewed

Loading...