Threat Database Trojans Trojan.MSIL.Krypt.ZADD

Trojan.MSIL.Krypt.ZADD

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 5,781
Threat Level: 80 % (High)
Infected Computers: 1,876
First Seen: January 15, 2022
Last Seen: July 7, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Krypt.ZADD on your system indicates a potential security threat that requires immediate attention. This report aims to provide you with a comprehensive understanding of the threat, its operation, symptoms, and most importantly, the steps to remove it from your system. It's crucial to approach this situation with caution and follow the recommended removal procedures to ensure your system's security and integrity.

What Is Trojan.MSIL.Krypt.ZADD?

Trojan.MSIL.Krypt.ZADD is identified as a Trojan-type threat. Trojans are malicious programs that can cause significant harm to computer systems. They are designed to allow unauthorized access to the victim's system, potentially leading to data theft, system compromise, and further malware infections. The name suggests it may involve encryption or cryptographic functions, but without specific details, it's essential to focus on general removal and system cleaning procedures.

How Trojan.MSIL.Krypt.ZADD Operates

Trojan-type threats like Trojan.MSIL.Krypt.ZADD typically operate by disguising themselves as legitimate software or attachments. Once installed, they can create backdoors, allowing remote access to the attacker. This access can be used for various malicious activities, including data theft, keystroke logging, and the installation of additional malware. Understanding how Trojans operate is key to preventing future infections and highlights the importance of being cautious with email attachments, downloads, and links from unknown sources.

Symptoms of Infection

Symptoms of a Trojan infection can vary widely. Common indicators include unexpected system crashes, slow performance, and unusual network activity. You might also notice new, unfamiliar programs or toolbars in your browser, or find that your system settings have been altered without your consent. Sometimes, infections can be asymptomatic, making regular system scans with reputable antivirus software crucial for early detection.

How to Remove Trojan.MSIL.Krypt.ZADD

  1. Enter Safe Mode with Networking to limit the malware's ability to interfere with the removal process. This mode allows you to access the internet, which is necessary for downloading removal tools if needed.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter. Ensure your antivirus and anti-malware software are updated to the latest versions to increase the chances of detection and removal.
  3. Uninstall suspicious programs that you do not recognize or that were installed around the time the malware was detected. Be cautious and only remove programs you are certain are malicious or unnecessary.
  4. Reset your browsers (Chrome, Firefox, Edge, etc.) to their default settings. This can help remove any malicious extensions or settings changes made by the Trojan.
  5. After completing the above steps, reboot your system and perform another full scan to ensure that the threat has been successfully removed. Repeat the scan a few days later as a precautionary measure to confirm the system remains clean.

Conclusion

Removing Trojan.MSIL.Krypt.ZADD and similar threats requires a combination of the right tools and cautious system management. By understanding the nature of Trojan threats and following the outlined removal steps, you can significantly reduce the risk of further infections and protect your system and data. Remember, prevention is key; maintaining updated antivirus software, being cautious with downloads and email attachments, and regularly scanning your system can help keep your computer secure.

Analysis Report

General information

Family Name: Trojan.MSIL.Krypt.ZADD
Signature status: No Signature

Known Samples

MD5: 22a3c557d469862250d862310541479b
SHA1: 5959a140d956dead99f3b5079c747d1f20c1a34a
SHA256: E10B2D653E07097AF1935A3A24ADB92560A32B118862D6465C5A8564B4402E63
File Size: 189.70 KB, 189696 bytes
MD5: df2787eaa74b7b3903f77a6cbeaf6c97
SHA1: ec0ef391c2f5c9e91edd266531ed65c3aa16f4ac
SHA256: 3BF9A10BE29889E8963830CCF8DFC54E377C766CE6E0B16BC8D5EE5080FCC707
File Size: 182.78 KB, 182784 bytes
MD5: e7d6437b6da811b26faacdd695de0b54
SHA1: 1608abb67bfdc29ec31c083835e9721f233c5654
SHA256: 1AF6996A085859F9FC9F868477288D94884BB946ADC0456B354822233ECE7F52
File Size: 204.68 KB, 204684 bytes
MD5: 85db3dac75448149f61ba326ca05e96d
SHA1: fc04f04ffd819dbd0f1f7d65a8a8983fb0b7a8ff
SHA256: 4E5562C53E41483BC2AE584A2A8F6C87AE6C43F2AA035631C47DA2DC224935AC
File Size: 340.99 KB, 340992 bytes
MD5: c39216ac483dab1dea94e3810c62ab1e
SHA1: 2cdccb66ddc828f4dcf980d8fa0a78c9e3665bbb
SHA256: A41F173F71574479E8769B03242C3AEBEAD3EF5D63283FFA9A450179D66D08B6
File Size: 155.65 KB, 155648 bytes
Show More
MD5: bbc840bc13b1e203c746c3d6ea9da4b8
SHA1: 449187e3fe0eb9adaac118ac87ebaf95867379b0
SHA256: FE97AC17A7D95FD0668B1A26CEB14D29A49542A6346B924FC5E22D908C913794
File Size: 4.23 MB, 4233814 bytes
MD5: 68f9fea4b5558c9e13b4c73c412ebc1b
SHA1: d827ae9b6591cfe49abb578d663e460a84b146b0
SHA256: F02C2BA99B69A6C0BE58EC0EED006A8B8C61A8A8BC3A60FC0775CB813B23C2C9
File Size: 279.55 KB, 279552 bytes
MD5: 517189b2389625dcdfba5fea18603f26
SHA1: d06dd7bd0e63baeb5725a60147232f9bb101097f
SHA256: 13EB22D7B2979484D8DEC8220749C41063A31FB90A4E431D65FCBC9E69F72766
File Size: 202.75 KB, 202752 bytes
MD5: bac8cd3c67b43777fd9e82a05fdae2cd
SHA1: 0656d3d417b621b54bd60e9cd149623b6cd4a153
SHA256: F27F48903D3D4966B98D38F08AEC95704E097F338153777339B1CA9832551C8A
File Size: 4.21 MB, 4205382 bytes
MD5: 4e83f200987936f9c8a05d972fbe328c
SHA1: 8aec87a38f40c7809d52a90ac16274c0a43449ec
SHA256: 188395F5A1F886B4EFF366F678D00E8E519E5267D8E9CB7809297816EA68E4EC
File Size: 276.99 KB, 276992 bytes
MD5: 0788feecd759de779577782d160a8955
SHA1: b9c65116dbd044a42af0cab2ec48a4f5c7ba3534
SHA256: FFB813E7E59C0B8A184748F3E98BD47EE2E4851626C2749A1B94A3673DA2B312
File Size: 230.91 KB, 230912 bytes
MD5: 41d6dd6a4b1506900a23980474b6cc22
SHA1: c2b066111aa452c59e1d05629bc941df48be2d82
SHA256: 768F47CDB0E3DCD99B70DD83DC408A948ED5362B83302B73524ACA3D8E50F8B0
File Size: 214.02 KB, 214016 bytes
MD5: e7c0b4b59b605841af035a438990ed83
SHA1: cb513f6fa3dc68d73c97259b204bc907d5778af7
SHA256: ADCF4CC9C7D3DD678294D82EE5FEE49D4036E0191E65CE9C0BB1B85A5FA1BC15
File Size: 418.22 KB, 418217 bytes
MD5: 2c3c5e0394e4323ef6534575ee39e940
SHA1: 19a74ce28d34a62888e2bd2bbd87a3e9c3750433
SHA256: 175FC7CFC0E299786B6D93E330DFE5EEEC01658DAAAF0C0A721CD81F641A79A7
File Size: 153.60 KB, 153600 bytes
MD5: 07813bbc0b03c78b35f3732ad038a16f
SHA1: 12ee5c4e14b292ed2690d550bcb3b607f915afbb
SHA256: EDA0CED22AA28A3810620D93D4C132CBC32943F0C772B5D61196D0B42801AA86
File Size: 380.93 KB, 380928 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 25.1.9.0
  • 7.1.4.20
  • 1.1.16.0
  • 1.1.14.0
  • 1.1.9.0
  • 1.0.40324.1712
  • 1.0.0.0
Comments
  • Ativador de produtos WAVES
  • Build on TCPOS 7.1.4
  • DbMakerR3
  • This installation was built with Inno Setup.
Company Name
  • Bechiro
  • Eaton
  • Grundfos
  • Technoserv
  • twostars
  • WAVES informática
  • Zucchetti Hospitality Srl
File Description
  • Ativador de produtos WAVES
  • ATUALIZADOR_LANCER
  • BusbarPlan SketchServer
  • DbMakerR3
  • Eaton MaxLoader
  • FLVmPlayer Uninstaller uninstaller
  • FLVMpubG Player
  • Mytec.MyTotem.Sicom.Store.LocalDb.SyncService Setup
  • nPodpis
  • PC Tool RSI Upgrade
Show More
  • VClassesDesktop
  • WarpGateEditor
  • Zimport
File Version
  • 25.1.9
  • 7.1.4.20
  • 3.0.0.0
  • 1.2.7.0
  • 1.1.16.0
  • 1.1.14.0
  • 1.1.9.0
  • 1.00
  • 1.0.40324.1712
  • 1.0.0.695
Show More
  • 1.0.0.2
  • 1.0.0.0
Internal Name
  • ATUALIZADOR_LANCER.exe
  • BusbarPlan SketchServer.exe
  • DbMakerR3.exe
  • nPodpis.exe
  • SUT.exe
  • TJprojMain
  • VClassesDesktop.dll
  • WarpGateEditor.exe
  • WS4_ACTIVATOR.exe
  • Zimport.exe
Legal Copyright
  • AppInstaller 2014 (141631231)
  • Copyright @ 2023
  • Copyright © 2014 Bechiro
  • Copyright © 2015 Kennedy Souza
  • Copyright © 2016
  • Copyright © 2021
  • Copyright © 2024
  • Copyright © 2025
  • Copyright © Zucchetti Hospitality Srl 2020
  • Eaton
Show More
  • Grundfos
  • © 2016
Original Filename
  • ATUALIZADOR_LANCER.exe
  • BusbarPlan SketchServer.exe
  • DbMakerR3.exe
  • nPodpis.exe
  • SUT.exe
  • TJprojMain.exe
  • VClassesDesktop.dll
  • WarpGateEditor.exe
  • WS4_ACTIVATOR.exe
  • Zimport.exe
Product Name
  • Ativador de produtos WAVES
  • ATUALIZADOR_LANCER
  • BusbarPlan SketchServer
  • DbMakerR3
  • FLVM Player
  • FLVmPlayer Uninstaller
  • MaxLoader
  • Mytec.MyTotem.Sicom.Store.LocalDb.SyncService
  • nPodpis
  • PC Tool RSI Upgrade
Show More
  • Project1
  • VClassesDesktop
  • WarpGateEditor
  • Zmenu for TCPOS 7.1.4
Product Version
  • 25.1.9
  • 7.1.4.20
  • 3.0.0.0
  • 1.1.16.0
  • 1.1.14.0
  • 1.1.9.0
  • 1.00
  • 1.0.40324.1712
  • 1.0.126.0
  • 1.0.0.0

File Traits

  • .NET
  • CryptoObfus
  • HighEntropy
  • Installer Version
  • RijndaelManaged
  • x86

Block Information

Total Blocks: 572
Potentially Malicious Blocks: 2
Whitelisted Blocks: 518
Unknown Blocks: 52

Visual Map

0 0 ? ? ? ? 0 0 0 0 ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 ? 0 0 ? 0 0 ? ? ? ? 0 ? ? ? ? ? ? 0 0 0 0 0 x 0 0 0 ? ? ? ? 0 0 x 0 0 ? ? 0 0 0 ? 0 0 ? 0 0 0 0 ? ? 0 0 ? 0 ? 0 ? ? 0 0 0 0 0 ? ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Agent.DFYA
  • MSIL.Agent.GDGC
  • MSIL.Agent.HGN
  • MSIL.Agent.YJ
  • MSIL.ArchSMS.A
Show More
  • MSIL.Coinminer.AK
  • MSIL.Downloader.DNHH
  • MSIL.Downloader.DNHI
  • MSIL.Downloader.DNND
  • MSIL.Downloader.Tiny.FG
  • MSIL.Downloader.Tiny.RF
  • MSIL.Downloader.Tiny.UA
  • MSIL.Downloader.XC
  • MSIL.Downloader.XH
  • MSIL.Dropper.SEA
  • MSIL.Gamehack.G
  • MSIL.Keylogger.BE
  • MSIL.Keylogger.BF
  • MSIL.Krypt.CCYE
  • MSIL.Krypt.GDOG
  • MSIL.Krypt.MBJY
  • MSIL.Krypt.RDC
  • MSIL.Krypt.XCJ
  • MSIL.Mardom.AM
  • MSIL.Patcher.E
  • MSIL.Perseus.AI
  • MSIL.Redline.LA
  • MSIL.Redline.RC
  • MSIL.Redline.RD
  • MSIL.Spy.DH
  • MSIL.Spy.DO
  • MSIL.Spy.RG
  • MSILZilla.PL
  • Sabsik.D
  • SimpleRAT.C

Files Modified

File Attributes
\device\namedpipe Generic Read,Write Attributes
\device\namedpipe Generic Write,Read Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\users\user\appdata\local\temp\is-r67ts.tmp\0656d3d417b621b54bd60e9cd149623b6cd4a153_0004205382.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsi20dc.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete
c:\users\user\appdata\local\temp\nslc4f7.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nslc4f7.exe.config Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nslc4f7.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsn20fc.tmp\dmr.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsn20fc.tmp\nsexec.dll Generic Write,Read Attributes
Show More
c:\windows\appcompat\programs\amcache.hve Read Data,Read Control,Write Data
c:\windows\appcompat\programs\amcache.hve Write Attributes
c:\windows\assembly Synchronize,Write Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\wow6432node\microsoft\tracing::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enablefiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enableautofiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::maxfilesize  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::filedirectory %windir%\tracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enablefiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enableautofiletracing RegNtPreCreateKey
Show More
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::maxfilesize  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::filedirectory %windir%\tracing RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 k �v��&�-(�1�1HO@V�H[u�P��/�����X����m��$��B1_ RegNtPreCreateKey
HKLM\system\software\microsoft\tip\aggregateresults::data 隞̃☁耀꧌ЎȮ RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
Process Shell Execute
  • CreateProcess
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAdjustPrivilegesToken
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelTimer2
Show More
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCompareSigningLevels
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeleteValueKey
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtGetCachedSigningLevel
  • ntdll.dll!NtLoadKeyEx
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtUnsubscribeWnfStateChange
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject

5 additional items are not displayed above.

User Data Access
  • GetComputerName
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • CheckRemoteDebuggerPresent
  • IsDebuggerPresent
  • NtQuerySystemInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Other Suspicious
  • AdjustTokenPrivileges
  • SetWindowsHookEx
Network Winsock2
  • WSAConnect
  • WSASocket
  • WSAStartup
  • WSAttemptAutodialName
Network Winsock
  • closesocket
  • freeaddrinfo
  • getaddrinfo
  • recv
  • send
  • setsockopt
Network Winhttp
  • WinHttpOpen
Network Info Queried
  • GetAdaptersAddresses
  • GetNetworkParams

Shell Command Execution

"C:\Users\Phmtfauj\AppData\Local\Temp\nslC4F7.exe"
C:\Users\Ksptcnkg\AppData\Local\Temp\nsn20FC.tmp\dmr.exe /a /e 12869173 /u 08b0e20b-f140-11e3-8a58-80c16e6f498c /lp "c:\users\user\downloads\1608abb67bfdc29ec31c083835e9721f233c5654_0000204684"
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\\dw20.exe dw20.exe -x -s 860
"C:\Users\Uigamkgs\AppData\Local\Temp\is-R67TS.tmp\0656d3d417b621b54bd60e9cd149623b6cd4a153_0004205382.tmp" /SL5="$60348,3953769,58368,c:\users\user\downloads\0656d3d417b621b54bd60e9cd149623b6cd4a153_0004205382"
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\\dw20.exe dw20.exe -x -s 880

Related Posts

Trending

Most Viewed

Loading...