Threat Database Trojans Trojan.MSIL.Krypt.XCO

Trojan.MSIL.Krypt.XCO

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.MSIL.Krypt.XCO
Signature status: No Signature

Known Samples

MD5: 49517763ac186fb78bfdfb3cf7426150
SHA1: cb449d2285effd6a467ef5ff0b2a6fa6a3ccc194
File Size: 36.35 KB, 36352 bytes
MD5: 27cc12d9226b3ea5369446060599a8df
SHA1: 6440ed4145a3ddbea3864b808fc34c2f9209b2ba
SHA256: 9DBC4D3077B8B2F6E2156707C9A230E96E8CE3C18DD45C455804165D9AC83D0B
File Size: 247.33 KB, 247332 bytes
MD5: 72a601dce1c05344630d66a90dc352e1
SHA1: 73db6d3d15e0a1fd86e59da80e2e50b7f69094a6
SHA256: 5228F2C6E9B686B4CCF0A2842476EBF1E01FDD2B535EBE1750D45E7257DEB2FC
File Size: 247.31 KB, 247312 bytes
MD5: dd256f90da087f61afdfc5fdbedf29ab
SHA1: 586d7dcc8bb54271bc5307b34989494d23dc20fc
SHA256: E3D4FE13074374D1A432D040009CB01A428E1489E12C85C2A013213C887D885F
File Size: 247.31 KB, 247314 bytes
MD5: ef0454f1680b9e1590fec66c41d8953b
SHA1: 8f30e45e40b500a5095aef00d46b00be23f4cd75
SHA256: C9424A579CF3E2CDEDCA5F64CC095260F946F0BC5A37FCD9AEA8D6AE63C5E403
File Size: 255.69 KB, 255685 bytes
Show More
MD5: b9d08c041bb853bb59c59e0574498cc5
SHA1: 61b0c0de8b625f782d10e345cf0a7de366c3fd76
SHA256: 7C9926D42CF22FD5C64807469E7D1053CCD3EAD891DE35331FCA0B5F4D2CDCE8
File Size: 247.45 KB, 247449 bytes
MD5: d3b57554d055f6d44b24195d5f045815
SHA1: 854266e4dce5294bb7adcee2c1c9ebc296f36b79
SHA256: 7AA67C7D5E9AC23A155D7066688346FCA4F8F96FB6EB1AF9F8E28FD2243F4947
File Size: 247.43 KB, 247429 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
Company Name Choose
File Description Choose
File Version 1.0.0.0
Internal Name Webview.exe
Legal Copyright Copyright © Choose 2024
Original Filename Webview.exe
Product Name Choose
Product Version 1.0.0.0

File Traits

  • .NET
  • x86

Block Information

Similar Families

  • MSIL.Agent.SKE

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsc598e.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsc598e.tmp\gelfand.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsc598e.tmp\gelfand.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsc598e.tmp\gelfand.exe.config Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsc598e.tmp\gelfand.exe.config Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsc598e.tmp\microsoft.web.webview2.core.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsc598e.tmp\microsoft.web.webview2.core.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsc598e.tmp\microsoft.web.webview2.winforms.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsc598e.tmp\microsoft.web.webview2.winforms.dll Synchronize,Write Attributes
Show More
c:\users\user\appdata\local\temp\nsc598e.tmp\microsoft.web.webview2.wpf.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsc598e.tmp\microsoft.web.webview2.wpf.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsc598e.tmp\webview2loader.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsc598e.tmp\webview2loader.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nscc0fa.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nscc0fa.tmp\getty.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nscc0fa.tmp\getty.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nscc0fa.tmp\getty.exe.config Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nscc0fa.tmp\getty.exe.config Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nscc0fa.tmp\microsoft.web.webview2.core.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nscc0fa.tmp\microsoft.web.webview2.core.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nscc0fa.tmp\microsoft.web.webview2.winforms.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nscc0fa.tmp\microsoft.web.webview2.winforms.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nscc0fa.tmp\microsoft.web.webview2.wpf.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nscc0fa.tmp\microsoft.web.webview2.wpf.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nscc0fa.tmp\webview2loader.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nscc0fa.tmp\webview2loader.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsq5c0c.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsq5c0c.tmp\friel.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsq5c0c.tmp\friel.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsq5c0c.tmp\friel.exe.config Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsq5c0c.tmp\friel.exe.config Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsq5c0c.tmp\microsoft.web.webview2.core.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsq5c0c.tmp\microsoft.web.webview2.core.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsq5c0c.tmp\microsoft.web.webview2.winforms.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsq5c0c.tmp\microsoft.web.webview2.winforms.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsq5c0c.tmp\microsoft.web.webview2.wpf.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsq5c0c.tmp\microsoft.web.webview2.wpf.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsq5c0c.tmp\webview2loader.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsq5c0c.tmp\webview2loader.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsrfa7b.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsrfa7b.tmp\mcentire.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsrfa7b.tmp\mcentire.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsrfa7b.tmp\mcentire.exe.config Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsrfa7b.tmp\mcentire.exe.config Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsrfa7b.tmp\microsoft.web.webview2.core.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsrfa7b.tmp\microsoft.web.webview2.core.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsrfa7b.tmp\microsoft.web.webview2.winforms.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsrfa7b.tmp\microsoft.web.webview2.winforms.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsrfa7b.tmp\microsoft.web.webview2.wpf.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsrfa7b.tmp\microsoft.web.webview2.wpf.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsrfa7b.tmp\webview2loader.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsrfa7b.tmp\webview2loader.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsva469.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsva469.tmp\microsoft.web.webview2.core.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsva469.tmp\microsoft.web.webview2.core.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsva469.tmp\microsoft.web.webview2.winforms.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsva469.tmp\microsoft.web.webview2.winforms.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsva469.tmp\microsoft.web.webview2.wpf.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsva469.tmp\microsoft.web.webview2.wpf.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsva469.tmp\mutilated.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsva469.tmp\mutilated.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsva469.tmp\mutilated.exe.config Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsva469.tmp\mutilated.exe.config Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsva469.tmp\webview2loader.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsva469.tmp\webview2loader.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nszaddf.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nszaddf.tmp\braham.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nszaddf.tmp\braham.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nszaddf.tmp\braham.exe.config Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nszaddf.tmp\braham.exe.config Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nszaddf.tmp\microsoft.web.webview2.core.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nszaddf.tmp\microsoft.web.webview2.core.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nszaddf.tmp\microsoft.web.webview2.winforms.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nszaddf.tmp\microsoft.web.webview2.winforms.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nszaddf.tmp\microsoft.web.webview2.wpf.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nszaddf.tmp\microsoft.web.webview2.wpf.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nszaddf.tmp\webview2loader.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nszaddf.tmp\webview2loader.dll Synchronize,Write Attributes

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations \??\C:\Users\Ilmnhwaw\AppData\Local\Temp\nsq5C0C.tmp\friel.exe RegNtPreCreateKey
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations \??\C:\Users\Ilmnhwaw\AppData\Local\Temp\nsq5C0C.tmp\friel.exe\??\C:\Users\Ilmnhwaw\AppData\Local\Temp\nsq5C0C.tmp\ RegNtPreCreateKey
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations \??\C:\Users\Gpvanapn\AppData\Local\Temp\nsrFA7B.tmp\mcentire.exe RegNtPreCreateKey
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations \??\C:\Users\Gpvanapn\AppData\Local\Temp\nsrFA7B.tmp\mcentire.exe\??\C:\Users\Gpvanapn\AppData\Local\Temp\nsrFA7B.tmp\ RegNtPreCreateKey
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations \??\C:\Windows\SystemTemp\77e37ce0-8214-4414-aced-551c5ae204d7.tmp\??\C:\Windows\SystemTemp\e28eadcf-6ab0-4d8c-8821-7ce9a6aba1 RegNtPreCreateKey
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations *1\??\C:\Windows\SystemTemp\MicrosoftEdgeUpdate.exe.old122e4*1\??\C:\Windows\SystemTemp\CopilotUpdate.exe.old12352*1\??\C:\P RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
Show More
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ZwMapViewOfSection
Process Shell Execute
  • CreateProcess

Shell Command Execution

C:\Users\Ilmnhwaw\AppData\Local\Temp\nsq5C0C.tmp\Friel.exe ""
C:\Users\Gpvanapn\AppData\Local\Temp\nsrFA7B.tmp\Mcentire.exe ""
C:\Users\Xiqyarqz\AppData\Local\Temp\nsc598E.tmp\Gelfand.exe ""
C:\Users\Isfehygb\AppData\Local\Temp\nsvA469.tmp\Mutilated.exe ""
C:\Users\Izfbaghi\AppData\Local\Temp\nscC0FA.tmp\Getty.exe ""
Show More
C:\Users\Ueegeupv\AppData\Local\Temp\nszADDF.tmp\Braham.exe ""

Trending

Most Viewed

Loading...