Threat Database Trojans Trojan.MSIL.Krypt.YDAH

Trojan.MSIL.Krypt.YDAH

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 12,114
Threat Level: 80 % (High)
Infected Computers: 4,217
First Seen: June 28, 2021
Last Seen: July 8, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Krypt.YDAH on your system indicates a potential security threat that requires immediate attention. This Trojan-type threat can compromise your system's security and put your personal data at risk. It is essential to understand the nature of this threat and take prompt action to remove it from your system.

What Is Trojan.MSIL.Krypt.YDAH?

Trojan.MSIL.Krypt.YDAH is a type of malware that can infect your system and allow unauthorized access to your data. The name itself does not indicate a specific malware family, but rather a detection label assigned by security software. Trojans are a common type of malware that can be used to steal sensitive information, install additional malware, or provide backdoor access to your system.

How Trojan.MSIL.Krypt.YDAH Operates

Trojan.MSIL.Krypt.YDAH, like other Trojans, can operate in various ways, depending on its intended purpose. It may be designed to collect sensitive information, such as login credentials, credit card numbers, or personal data. It can also be used to install additional malware, such as ransomware, spyware, or adware, which can further compromise your system's security. In some cases, Trojans can provide backdoor access to your system, allowing hackers to remotely control your computer.

Symptoms of Infection

The symptoms of a Trojan.MSIL.Krypt.YDAH infection can vary, but common signs include slow system performance, unexpected pop-ups, and suspicious network activity. You may also notice that your system is behaving erratically, such as crashing or freezing frequently. Additionally, you may receive warnings from your security software or notice that your antivirus program is disabled. If you suspect that your system is infected with Trojan.MSIL.Krypt.YDAH, it is essential to take immediate action to remove the threat.

How to Remove Trojan.MSIL.Krypt.YDAH

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow you to download and install removal tools.
  2. Download and install a reputable anti-malware tool, such as SpyHunter, and perform a full scan of your system to detect and remove the Trojan.
  3. Uninstall any suspicious programs or applications that may be related to the infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform another scan with your anti-malware tool to ensure that the threat has been completely removed.

Conclusion

Removing Trojan.MSIL.Krypt.YDAH from your system requires a combination of technical knowledge and the right tools. By following the steps outlined above, you can help ensure that your system is free from this threat and prevent future infections. It is essential to remain vigilant and take proactive measures to protect your system and personal data from malware threats. Regularly updating your security software, avoiding suspicious downloads, and being cautious when clicking on links or opening email attachments can help prevent infections and keep your system secure.

Analysis Report

General information

Family Name: Trojan.MSIL.Krypt.YDAH
Signature status: No Signature

Known Samples

MD5: d9ef1dcd8809498181d8300e7c304f1b
SHA1: 5922567fbf99f8a0115ffa404b8353e10dc5b200
File Size: 9.49 MB, 9487360 bytes
MD5: e909d06927515add2457953b8482e03b
SHA1: aad9713cb724079a323c74a0166c7582e6eb64fd
SHA256: 5B6C8B770AF7D7AD7A187BC769D9DC08A09F544FD887D5DDB20326FF0DA25DC5
File Size: 5.87 MB, 5873152 bytes
MD5: 50de8cebcbedf2a6439a968e6f5af2b4
SHA1: d5f314bd2994f74e84b8fbf408901733fa59f4f2
SHA256: B9871AC7470FD2DE0387BE87207F5FB6F0F4B8E4C767D21CC5DEC5856D64E56D
File Size: 2.81 MB, 2810880 bytes
MD5: 57d2fcafbc90ef538695c41a4074178d
SHA1: 2e9d8bf4d3c2e1323fe03e4604235d33f151c842
SHA256: F1E8E8809ACF51D5AEA24C717F5E800D1A44E871D1AFCC26C46730E7FC06A5EF
File Size: 4.13 MB, 4126208 bytes
MD5: 347e48d7e594897f0ab66782a7f952f6
SHA1: 606aab94ba402b31ef67163a45d967052b630709
SHA256: FDDFFC11AA5C6BAD7BFBAE0EB9343A7AFE5270857B015F840913318770904824
File Size: 3.88 MB, 3882496 bytes
Show More
MD5: a7c0d5053346cad216fc475eb403caa9
SHA1: bbcf88408b69a3029d5868be151e50f8a6195c4b
SHA256: 63BB33370A017AB654E2CFC9A785A1FDFCFCDD6EFFCB29603D3F72444DDCE1F4
File Size: 400.90 KB, 400896 bytes
MD5: 5b5a1f8292ddd73982618dc7cd79fca0
SHA1: 69d0cb62a56afc36227720586a1f9e9df6d19305
SHA256: 8D065621A24F3C12723A50A1BDDEDDCB15795ED86B0AAF8B6E87122217A2A564
File Size: 3.36 MB, 3359744 bytes
MD5: 8f21da26924b413b1e09f9c85eeaf13c
SHA1: 27bda3108e0a26bcd82528f523d269dfbea1126d
SHA256: 4A4EEA5D6F6468C273672E798B192B81D596323A17711DDF697AC1C025C447AE
File Size: 6.11 MB, 6108160 bytes
MD5: af394c3267daca92648575ae330bbd69
SHA1: 402015ba92ade84446847863e1c8b95d0e284ce2
SHA256: 4870F60895E8B8EDCE8A2E8D01AB6A5E2B94970A2DCAC60DFD5DFD4F6E9C948B
File Size: 3.69 MB, 3693297 bytes
MD5: c955ac25739e83df4de46dcf9468fb12
SHA1: b7d6aaad35f56934260bd8f961287af7c4d550a2
SHA256: 9C603FCB8086ACD741912E9EA60FC5F33785FDEB36D6B22A9771578E777F8CF6
File Size: 7.44 MB, 7440384 bytes
MD5: d98c1a898a2435854633b756b03ca6bc
SHA1: 1371f4cb617100e1fa6c3b42fbb776a8a768ef35
SHA256: 08C244BC98FCF25D240251619877EE0A9D46C28A04047BD38D365C7B60A85AD4
File Size: 3.84 MB, 3843072 bytes
MD5: 843237460913e360745585d61799649e
SHA1: fd6a6c5b10deb81518122e7be24512d74bd4425d
SHA256: 18E46F9E4D190AAAF56C97E39FF8F9C4DEB63BEC9C0D7D686820B7E8624D5070
File Size: 1.76 MB, 1759744 bytes
MD5: 5e1d089da171f4569c208d0eaa7fcc2a
SHA1: 68b126894f8ddae45c7930baedc35b660708c956
SHA256: 31DD54DA4627007F0CE7A4581BC1AD9761C21AFF0958526C002A2D0592489A1D
File Size: 3.71 MB, 3706107 bytes
MD5: 74fa1f4b490b694bb2591f9c8b0c409a
SHA1: aa73823d4765d82055b223d1072a1de90de4d384
SHA256: 611CF5601AB14FDC7E0FD2692201DD8B26FF1253C59EC9D89BF046DDD227A5AD
File Size: 828.93 KB, 828928 bytes
MD5: 4923c3c6f2078add84ccd1f64e299b07
SHA1: 81c7141c9107b66324c5d659717ac0ae565c62ff
SHA256: 71EA23FC0BC599A8A0668D70A63F6F0A39ED6BFEBC1C0A5102D0CD8CA54BFCD8
File Size: 5.36 MB, 5364736 bytes
MD5: ee8158b98e42dbe4686cc8e8a10c7512
SHA1: c96036ac0c4617a489b9fe203b33e2e0fd66e90a
SHA256: 4FD8A6562633110F897E27AD3186367F103856AD18B7E44E1C7FCBB2DD82420A
File Size: 9.69 MB, 9692672 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Show More

Windows PE Version Information

Name Value
Assembly Version
  • XWorm6.4
  • 2017.3.1.7475
  • 16.0.0.0
  • 9.0.0.6
  • 7.4.0.0
  • 3.1.8851.24335
  • 2.45.0.0
  • 1.0.0.0
Comments
  • EndlessLongju
  • PBLauncher
  • Phần mềm kiểm tra Vách
  • SmartCreator_Update
  • www.Dr-FarFar.com
  • XWorm V6.4 | @Ktama_Official
Company Name
  • @Ktama_Official
  • Autopatcher EndlessLongju Reloaded by KGO
  • Dr.FarFar | www.Dr-FarFar.com
  • PBL
  • SmartCreator
  • Tring doo
  • WEFLY Structure Ltd
Email inFo@Dr-FarFar.CoM
File Description
  • Auto Whatsapp Business Sender Turbo Pro
  • CadenceLicensePatcherWin
  • EndlessLongju - Official
  • ExamadminDesign
  • GstoneCAD
  • KCS KTV
  • KCS_GSA
  • PBLauncher
  • SmartCreator_Update
  • Tring.Fiscal.Server
Show More
  • Video Spin Blaster Pro Plus (ViP)
  • XWorm V6.4
  • 微信通讯录极速导出工具
File Version
  • v3.5.116+5d5daf5
  • 2017.3.1.7475
  • 16.0.0.0
  • 9.0.0.6
  • 7.4.0.0
  • 6.0.0.4
  • 2.45.0.0
  • 1.00
  • 1.0.0.0
Internal Name
  • Auto Whatsapp Business Sender Turbo Pro.exe
  • BALDI.exe
  • CadenceLicensePatcherWin.exe
  • ExamadminDesign.exe
  • GstoneCAD Manage.exe
  • KCS KTV.exe
  • KCS_GSA.exe
  • KingGherusio.exe
  • PBLauncher.exe
  • TJprojMain
Show More
  • Tring.Fiscal.Server.exe
  • update.exe
  • Video Spin Blaster Pro Plus.exe
  • XWorm V6.4.exe
  • 微信通讯录极速导出工具.exe
Legal Copyright
  • @Ktama_Official
  • Copyright © 2010
  • Copyright © 2018
  • Copyright © 2022
  • Copyright © 2025
  • Copyright © Dr.FarFar
  • Copyright © EndlessLongju - KGO 2025 - KingGherusio
  • Copyright © KetcauSoft 2017
  • Copyright © Zynect Indonesia 2024
Legal Trademarks
  • Dr.FarFar
  • KetcauSoft
  • KGO
  • Video Spin Blaster Pro Plus (ViP)
  • Zynect Team 2024
Original Filename
  • Auto Whatsapp Business Sender Turbo Pro.exe
  • BALDI.exe
  • CadenceLicensePatcherWin.exe
  • ExamadminDesign.exe
  • GstoneCAD Manage.exe
  • KCS KTV.exe
  • KCS_GSA.exe
  • KingGherusio.exe
  • PBLauncher.exe
  • TJprojMain.exe
Show More
  • Tring.Fiscal.Server.exe
  • update.exe
  • Video Spin Blaster Pro Plus.exe
  • XWorm V6.4.exe
  • 微信通讯录极速导出工具.exe
Product Name
  • Autopatcher EndlessLongju Reloaded KGO
  • Auto Whatsapp Business Sender Turbo Pro
  • CadenceLicensePatcherWin
  • ExamadminDesign
  • GstoneCAD
  • KCS KTV
  • KCS_GSA
  • LauncherGame
  • Project1
  • SmartCreator_Update
Show More
  • Tring.Fiscal.Server
  • Video Spin Blaster Pro Plus (ViP)
  • XWorm V6.4 | @Ktama_Official
  • 微信通讯录极速导出工具
Product Version
  • XWorm V6.4
  • v3.5.116+5d5daf5
  • 2017.3.1.7475
  • 16.0.0.0
  • 9.0.0.6
  • 7.4.0.0
  • 2.45.0.0
  • 1.00
  • 1.0.0.0
Website https://www.Dr-FarFar.com

File Traits

  • .NET
  • GenKrypt
  • HighEntropy
  • NewLateBinding
  • Reactor
  • Reflective
  • RijndaelManaged
  • SmartAssembly
  • x64
  • x86

Block Information

Total Blocks: 19
Potentially Malicious Blocks: 1
Whitelisted Blocks: 4
Unknown Blocks: 14

Visual Map

0 0 ? ? ? ? ? ? ? ? ? ? ? ? x 0 ? 0 ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Agent.KOG
  • MSIL.Agent.OAAR
  • MSIL.Agent.OAAU
  • MSIL.AgentTesla.PH
  • MSIL.BadJoke.XF
Show More
  • MSIL.Bladabindi.LB
  • MSIL.Bladabindi.LE
  • MSIL.ClipBanker.HJ
  • MSIL.Downloader.PFB
  • MSIL.Dropper.XC
  • MSIL.HackAgent.XD
  • MSIL.Heracles.IP
  • MSIL.Heracles.PW
  • MSIL.Injector.FSA
  • MSIL.Krypt.EDCPB
  • MSIL.Krypt.MJK
  • MSIL.Krypt.YDPI
  • MSIL.Kryptik.SA
  • MSIL.Tedy.F
  • MSIL.Tedy.NN
  • MSIL.Ursu.TJA
  • MSIL.Ursu.TJC
  • MSIL.Ursu.TJE
  • MSIL.Ursu.TJF
  • MSIL.Ursu.TJG
  • Stealer.UHAN

Files Modified

File Attributes
c:\users\user\appdata\local\temp\costura\526ad3bb6e6aa2bd107c0b26e44139ab\32\bass.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\costura\526ad3bb6e6aa2bd107c0b26e44139ab\32\flexnetpatchlibrary.dll Generic Write,Read Attributes
c:\users\user\appdata\local\tring_doo\aad9713cb724079a323c74a01_url_rj21fm4vfzalhucpmmh3sepyqwaqphwo\3.1.8851.24335\skdsu_en.newcfg Generic Write,Read Attributes
c:\users\user\appdata\local\tring_doo\aad9713cb724079a323c74a01_url_rj21fm4vfzalhucpmmh3sepyqwaqphwo\3.1.8851.24335\skdsu_en.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\tring_doo\aad9713cb724079a323c74a01_url_rj21fm4vfzalhucpmmh3sepyqwaqphwo\3.1.8851.24335\user.config Synchronize,Write Data
c:\users\user\downloads\.logs\error 18-12-2025.log Generic Write,Read Attributes
c:\users\user\downloads\app.cs Generic Write,Read Attributes
c:\users\user\downloads\patcher_log.txt Generic Write,Read Attributes
c:\users\user\downloads\tfsinterfacelog.txt Generic Write,Read Attributes
c:\users\user\downloads\zynect.cfg Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\content::cacheprefix RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\cookies::cacheprefix Cookie: RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\history::cacheprefix Visited: RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enablefiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enableautofiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::maxfilesize  RegNtPreCreateKey
Show More
HKLM\software\wow6432node\microsoft\tracing\rasapi32::filedirectory %windir%\tracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enablefiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enableautofiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::maxfilesize  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::filedirectory %windir%\tracing RegNtPreCreateKey

Windows API Usage

Category API
User Data Access
  • GetComputerName
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserNameEx
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Other Suspicious
  • AdjustTokenPrivileges
  • SetWindowsHookEx
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
Show More
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Process Shell Execute
  • ShellExecuteEx
Network Winsock2
  • WSAConnect
  • WSASocket
  • WSAStartup
  • WSAttemptAutodialName
Network Winsock
  • closesocket
  • freeaddrinfo
  • getaddrinfo
  • recv
  • send
  • setsockopt
Network Winhttp
  • WinHttpOpen
Network Info Queried
  • GetAdaptersAddresses
  • GetNetworkParams

Shell Command Execution

(NULL) https://www.Dr-FarFar.com/random

Related Posts

Trending

Most Viewed

Loading...