Threat Database Trojans Trojan.MSIL.Krypt.DAGN

Trojan.MSIL.Krypt.DAGN

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 3
First Seen: June 14, 2023
Last Seen: November 23, 2025
OS(es) Affected: Windows

The detection of Trojan.MSIL.Krypt.DAGN on your system indicates a potential security threat that requires immediate attention. This report provides an overview of the threat, its operational characteristics, symptoms of infection, and steps to remove it from your system.

What Is Trojan.MSIL.Krypt.DAGN?

Trojan.MSIL.Krypt.DAGN is a type of malicious software, commonly referred to as a Trojan. The name itself suggests it is a Trojan-type threat, but without more specific information, it's difficult to determine its exact nature or the family it belongs to. Trojans are known for their ability to disguise themselves as legitimate software, making them particularly dangerous as they can bypass security measures and operate undetected for extended periods.

How Trojan.MSIL.Krypt.DAGN Operates

Generally, Trojans like Trojan.MSIL.Krypt.DAGN are designed to gain unauthorized access to a computer system. They can be spread through various means, including but not limited to, email attachments, downloadable software, or exploited vulnerabilities in operating systems or applications. Once inside a system, a Trojan can perform a wide range of malicious activities, such as data theft, installation of additional malware, or allowing remote access to the attacker. The specific operations of Trojan.MSIL.Krypt.DAGN would depend on its programming and the intentions of its creators.

Symptoms of Infection

Symptoms of a Trojan infection can vary widely, depending on the malware's purpose. Common indicators include unexpected changes to system settings, unusual network activity, slower than usual system performance, or the appearance of unwanted programs or toolbars. In some cases, the infection may not exhibit noticeable symptoms, making it difficult for users to detect without the aid of security software.

How to Remove Trojan.MSIL.Krypt.DAGN

  1. Enter Safe Mode with Networking to prevent the malware from loading and to allow for internet access to download removal tools if necessary.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all traces of the Trojan and any associated malware.
  3. Uninstall suspicious programs that you do not recognize or that were installed around the time the infection was detected.
  4. Reset your web browsers (Chrome, Firefox, Edge, etc.) to their default settings to remove any malicious extensions or settings changes made by the Trojan.
  5. After completing the above steps, reboot your system and perform another full scan to ensure that all malware has been removed.

Conclusion

Removing Trojan.MSIL.Krypt.DAGN requires careful and methodical steps to ensure that all components of the malware are eliminated from the system. It's also crucial to adopt preventive measures to avoid future infections, such as keeping your operating system and software up to date, using strong antivirus software, and being cautious when opening email attachments or downloading software from the internet. By understanding the nature of Trojan threats and taking proactive steps, you can significantly reduce the risk of infection and protect your digital assets.

Analysis Report

General information

Family Name: Trojan.MSIL.Krypt.DAGN
Signature status: No Signature

Known Samples

MD5: ac586cf1474d704c4303d3d202ccb858
SHA1: d3cd0da1468b43a343f3308d5deb74f831b89358
SHA256: C63272A7F02C1FF5BDB863664F45B95A5F7B283157BC343012C797351ED1A60B
File Size: 729.09 KB, 729088 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 3.0.0.0
Comments A save editor for the Ur-Quan Masters
File Description The UQM Save Editor
File Version 3.0.0.0
Internal Name UQMEdit.exe
Legal Copyright Copyright Serosis© 2019
Original Filename UQMEdit.exe
Product Name The UQM Save Editor
Product Version 3.0.0.0

File Traits

  • .NET
  • HighEntropy
  • x86

Block Information

Total Blocks: 105
Potentially Malicious Blocks: 68
Whitelisted Blocks: 37
Unknown Blocks: 0

Visual Map

x x x x x x x x x x 0 0 0 x x x x x x x x 0 x x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x x x x x x x x x x 0 x 0 x x x x 0 x x x 0 x 0 x x x x x 0 x x x x x x 0 0 0 0 0 0 0 0 x x x x 0 0 x x x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Krypt.DAGN

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
Show More
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
Encryption Used
  • BCryptOpenAlgorithmProvider

Related Posts

Trending

Most Viewed

Loading...