Threat Database Trojans Trojan.MSIL.Agent.KAB

Trojan.MSIL.Agent.KAB

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 24,808
Threat Level: 80 % (High)
Infected Computers: 40
First Seen: October 11, 2024
Last Seen: April 20, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Agent.KAB indicates that your system has been compromised by a potentially malicious program. This type of threat is known to cause significant disruptions to your computer's normal functioning and can lead to serious security breaches if not addressed promptly. It is essential to understand the nature of this threat and take immediate action to remove it from your system.

What Is Trojan.MSIL.Agent.KAB?

Trojan.MSIL.Agent.KAB is a type of Trojan horse malware that can infect your system through various means, such as downloading malicious software, opening infected email attachments, or visiting compromised websites. Once inside, it can perform a range of malicious activities, including stealing sensitive information, installing additional malware, and disrupting system operations.

How Trojan.MSIL.Agent.KAB Operates

Trojan horses like Trojan.MSIL.Agent.KAB are designed to operate stealthily, making it difficult for users to detect their presence. They can create backdoors, allowing remote access to your system, and can also modify system settings and files to maintain their presence. These malware programs can also communicate with their command and control servers to receive updates and instructions, making them highly adaptable and dangerous.

Symptoms of Infection

Identifying the symptoms of a Trojan.MSIL.Agent.KAB infection can be challenging, as they can vary depending on the specific actions of the malware. However, common signs of infection include slow system performance, frequent crashes, and unexpected changes to system settings. You may also notice unfamiliar programs or icons on your desktop, or receive strange error messages. If you suspect that your system has been infected, it is crucial to take immediate action to remove the threat.

  • Unexplained changes to system settings or files
  • Slow system performance or frequent crashes
  • Appearance of unfamiliar programs or icons
  • Strange error messages or pop-ups

How to Remove Trojan.MSIL.Agent.KAB

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for internet access.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove the Trojan.MSIL.Agent.KAB malware.
  3. Uninstall any suspicious programs or applications that may be related to the infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform another full scan to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.MSIL.Agent.KAB from your system requires careful attention to detail and a thorough understanding of the malware's operations. By following the steps outlined above and using reputable anti-malware tools, you can effectively remove this threat and restore your system to its normal functioning state. It is essential to remain vigilant and take proactive measures to protect your system from future infections, including keeping your operating system and software up to date, using strong antivirus programs, and avoiding suspicious downloads and links.

Analysis Report

General information

Family Name: Trojan.MSIL.Agent.KAB
Signature status: No Signature

Known Samples

MD5: 06d7db9c8e903c13ee56ae3f3b678c71
SHA1: 299ea52917c318ac8f3a6346184cdc589073ba40
File Size: 6.52 MB, 6523392 bytes
MD5: 21e9bed2464cabcd57dba55ce963aade
SHA1: eff5adb859af12dd258f347dc856f15626a14450
File Size: 8.12 MB, 8121344 bytes
MD5: 52ab3b42a5f85608ddf635c7de6f53b7
SHA1: 21b0a9402fbf73e0ed59b78d4c289d825fdf36c9
File Size: 4.43 MB, 4432896 bytes
MD5: 71b65e7539138b45250d2071708c9c70
SHA1: d5a0156ad9a91d1b013f14d81b7a05154cd9fad9
File Size: 1.47 MB, 1467904 bytes
MD5: 2e452649a954c56f0f83fc0289ea72d8
SHA1: e4d96c289aa6ad546602c5e2f3f48de0a1475dfd
SHA256: 362AC35F7B0ACC6C7D3E9AFD20ED23118E5A80F3902CF9A9321632D21E33F354
File Size: 8.55 MB, 8545792 bytes
Show More
MD5: f825b91fad37af30d9d8ae9f41b65fdf
SHA1: 5c27c519576ed5ba0c5fe2e43cd16f0e566f6f31
SHA256: 5AC7ABA812E01FDA82DF8553BD2F8278669AB83779BE3C55CA30107F0A337E23
File Size: 1.50 MB, 1497600 bytes
MD5: 25245f395b429b068fbf27e88f578cba
SHA1: 9ede6f78bcc578569c3a08b297305484f722dbcf
SHA256: 8C3AEC90F4CFBDD9BD6433B44F35B24BE2429C4A777C86EEAECFC354F1D5E46E
File Size: 8.01 MB, 8006656 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 2.7.0.0
  • 1.0.0.0
Company Name Bloxstrap
File Description Bloxstrap
File Version
  • 2.7.0.0
  • 1.0.0.0
Internal Name
  • Bloxstrap-v2.7.0.exe
  • Brutal 0.8zZzZZ.exe
  • LoaderAkashii.exe
  • ReaperUltimate.exe
  • Setup.exe
  • Soundpad.exe
  • tool.exe
Original Filename
  • Bloxstrap-v2.7.0.exe
  • Brutal 0.8zZzZZ.exe
  • LoaderAkashii.exe
  • ReaperUltimate.exe
  • Setup.exe
  • Soundpad.exe
  • tool.exe
Product Name Bloxstrap
Product Version
  • 2.7.0.0
  • 1.0.0.0

File Traits

  • .NET
  • HighEntropy
  • Installer Version
  • NewLateBinding
  • Run
  • x86

Block Information

Total Blocks: 19
Potentially Malicious Blocks: 6
Whitelisted Blocks: 12
Unknown Blocks: 1

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 ? x x x x x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Kazy.QA
  • MSIL.Agent.KAB
  • MSIL.Cerbu.C
  • MSIL.Dropper.EDC
  • MSIL.Dropper.EDD
Show More
  • MSIL.Dropper.X
  • MSIL.Dropper.XC
  • MSIL.Dropper.XF
  • MSIL.Inject.AB
  • MSIL.Inject.YT
  • MSIL.Krypt.GDSC
  • MSIL.Krypt.GDSG
  • MSIL.Krypt.GTD
  • MSIL.Krypt.SEA
  • MSIL.Krypt.TDJ
  • MSIL.Kryptik.XC
  • Wacatac.AR

Files Modified

File Attributes
c:\users\user\appdata\local\temp\aaaaaaaaaaaaaaaaaa.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\loaderakashii.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\reaperultimate.exe Generic Write,Read Attributes
c:\users\user\brutal 0.8zz.exe Generic Write,Read Attributes

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
Show More
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtGetContextThread
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtSuspendThread
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtYieldExecution
  • UNKNOWN
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Process Manipulation Evasion
  • ReadProcessMemory
Encryption Used
  • BCryptOpenAlgorithmProvider

Related Posts

Trending

Most Viewed

Loading...