Threat Database Trojans Trojan.MSIL.Krypt.GJLD

Trojan.MSIL.Krypt.GJLD

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 1,079
Threat Level: 80 % (High)
Infected Computers: 355
First Seen: October 13, 2025
Last Seen: July 30, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Krypt.GJLD on your system indicates a potential security threat that requires immediate attention. This report aims to provide you with a comprehensive understanding of the threat, its operations, symptoms, and most importantly, the steps to remove it from your system.

What Is Trojan.MSIL.Krypt.GJLD?

Trojan.MSIL.Krypt.GJLD is identified as a Trojan-type threat, which is a broad category of malware designed to deceive users into installing it on their systems. The name itself does not specify a known malware family, but rather indicates it's a type of Trojan written in MSIL (Microsoft Intermediate Language), possibly with encryption or obfuscation techniques to evade detection. Trojans are known for their ability to disguise themselves as legitimate software, making them particularly dangerous as they can lead to unauthorized access, data theft, and further malware infections.

How Trojan.MSIL.Krypt.GJLD Operates

Although specific details about the operation of Trojan.MSIL.Krypt.GJLD are not available, Trojans generally operate by exploiting vulnerabilities in software or tricking users into executing them. Once installed, they can create backdoors for remote access, steal sensitive information such as passwords and credit card numbers, and install additional malware. Their ability to remain hidden and the variety of actions they can perform make them a significant threat to system security and user privacy.

Symptoms of Infection

Symptoms of a Trojan infection can vary widely depending on the specific actions the malware is designed to perform. Common signs include unusual system behavior such as slow performance, frequent crashes, and unexpected pop-ups or ads. Users might also notice unfamiliar programs or icons, changes in system settings, or difficulties accessing certain files or programs. In some cases, the infection might not exhibit noticeable symptoms, making regular system checks and the use of antivirus software crucial for detection.

How to Remove Trojan.MSIL.Krypt.GJLD

  1. Enter Safe Mode with Networking: This will limit the malware's ability to interfere with the removal process. Restart your computer and press the key to access the boot menu (usually F8), then select Safe Mode with Networking.
  2. Perform a Full Scan with a Reputable Tool: Utilize a reputable anti-malware tool such as SpyHunter to scan your system for the Trojan and other potential threats. Ensure the tool is updated to the latest version for the best results.
  3. Uninstall Suspicious Programs: Go through the list of installed programs on your system and uninstall any that are unfamiliar or were installed around the time the malware was detected.
  4. Reset Your Browser: If the Trojan has affected your browser (Chrome, Firefox, Edge), reset it to its default settings. This can usually be done through the browser's settings or options menu.
  5. Reboot and Re-scan: After completing the above steps, restart your computer and perform another full scan with your anti-malware tool to ensure all components of the Trojan have been removed.

Conclusion

The removal of Trojan.MSIL.Krypt.GJLD requires careful and thorough steps to ensure all components of the malware are eliminated from your system. It's also crucial to adopt preventive measures such as keeping your operating system and software up to date, using strong antivirus software, and being cautious when opening email attachments or downloading software from the internet. By understanding the nature of Trojan-type threats and taking proactive steps, you can significantly reduce the risk of future infections and protect your digital security.

Analysis Report

General information

Family Name: Trojan.MSIL.Krypt.GJLD
Signature status: No Signature

Known Samples

MD5: 31e275e5be67394935d3bc5645c9e9b9
SHA1: e326b276e37dd141c9cc85201f338ca63623e5ca
SHA256: F905525C7CCC65679C0AE5D2709F189D3686B31CA087687C665A1E4D849DDB16
File Size: 645.12 KB, 645120 bytes
MD5: deb6a84e4407b9dc630d097399723337
SHA1: 0356a228c569a14ed0fd0bdfbb7ee9e287061626
SHA256: E695E4B61AD27CDF59C13E839D04D2EC9782FB9521ABF97371BCD14D90D223FB
File Size: 969.73 KB, 969728 bytes
MD5: 59296a21c5f9d89c59606577be4413d4
SHA1: 70288821ec0ca3adac055a5b5bc11091d3962603
SHA256: 92340A2808BF87AEF8620CB9B2399B7D62282BBC43682C63289517C849AE3B60
File Size: 646.14 KB, 646144 bytes
MD5: 37d7aeb4bc68e2eab6b7921698c17776
SHA1: 88673423ec6197a4dd908f2eeea08fd18162b50c
SHA256: 6B2AD2D76A80070A5398E7FB3149F03E0D3DA7496A0CFD215119C0A8F8CE7E1C
File Size: 648.19 KB, 648192 bytes
MD5: 8aae0c875702b49c1f00cadfeeb3a013
SHA1: 8d95d9048dbd67454775621f6e9c075fd9018534
SHA256: AA4599BA65ECA0D7AF69455F16B7E343E8F60EA76D2CA75C90B5BF965C4A1E56
File Size: 971.78 KB, 971776 bytes
Show More
MD5: 603c27f4aa6142aa5e55bba91bd20a79
SHA1: 3b64b3d339c3787259a0b21861b3da75ff32ce95
SHA256: BDB5EF300F28A0CEAFBF74D215C79CEDDE15D90E1ADC36F198DD49F7227ECB19
File Size: 645.12 KB, 645120 bytes
MD5: 4cbf553f39b5776dbffd2e5b4eed6775
SHA1: c1d752f3b136f8cca5eab9415315f60cb48fe8ff
SHA256: 7C4C5ABFD7F2C8227EB4BC2B945765EE03B9AB372D2E05AD20BAE7010630D74D
File Size: 642.05 KB, 642048 bytes
MD5: 16dc55ced2ca8781d835a8126cd66f4d
SHA1: 5e45ab460a2bfea8061e9b97d9ded9174ce1e14c
SHA256: CD9B47C5A07E5A9AA78994CEBEE7ED6F2E631A4C482B6B2EE8481682C16DC667
File Size: 1.02 MB, 1015808 bytes
MD5: f6a20608a943f771685c4aaf2988c0b3
SHA1: ebba09c4136e1b6af7c41505afc94ac90d06214f
SHA256: FCD87D1F18832F3F22583EF08F1145FB9C030764CD9CE5B74D7F1E2A21D0882F
File Size: 620.03 KB, 620032 bytes
MD5: a415ae5b96e1b361430a97f0ea50a7ce
SHA1: 7b57a6999afc34ff5d15a217ffe0d8552cba9a7a
SHA256: 975807A4FC3F81E4385D210673306C61EC31BA89E9E2828EF7C36168F31651CD
File Size: 636.42 KB, 636416 bytes
MD5: 47f14821d9ae0e9ab9a6cc9322d19184
SHA1: b3083f93cb871dc64f005f9dd11d83549a1f0045
SHA256: 52DCF74BC12A1D627847054F516C6689156401B8ADFF8BF386081D0CA9001A89
File Size: 793.09 KB, 793088 bytes
MD5: 714a3c9cb6022a3518c3e621384fb6e3
SHA1: fca806ce2816fe3b1361b0708b33c0c5dd431ea4
SHA256: DC1E8A2FCC34AACE7B525115E6CA8D697775643D866AAB5395FAB0C754F05927
File Size: 790.53 KB, 790528 bytes
MD5: 52bbb984cf2b39e1f30ebd78130e1aed
SHA1: c63044660a12e51fc2fa4dda84b53ea7dfc57ea7
SHA256: ABB7C0EF2C15DEC3B73834B1F07D2AA0D5C65246FC0F34A930796C3DD7876BC6
File Size: 681.47 KB, 681472 bytes
MD5: 24bc3e0679b2c6c14b72279210959059
SHA1: 3bfd72b9e03bf6a5be81b9d1cb772c9f224776bd
SHA256: 64D93CEB3286438B0B7339F5AD544C21591BBDD667FBD794C1CEA3F09AAB99F9
File Size: 523.26 KB, 523264 bytes
MD5: 9f6c041acdff34eda5cb551ecbf1f816
SHA1: 3e684f938fe81291f0e004fb963c8f4faccf30d1
SHA256: 9FBC60F60338D0A4014CF46FFAFFEE4AE8F3F5B3C7D6FAC0F258C574580A4BB0
File Size: 522.75 KB, 522752 bytes
MD5: c36079e5adb5a0c176d7705a1d6ea31a
SHA1: b59c9cad969372f0da9cc794c543c850e8a22542
SHA256: E68CCFE0F785C2C4938385CE466361569791C9D37033FA6135DC570A9FE3D770
File Size: 703.49 KB, 703488 bytes
MD5: 8e6ce7e2357c38c7c71144e8d16a69f1
SHA1: adcdae379a92af047f6fc73f0a68522c1cce614d
SHA256: E487E8A4DAC44ADFEEBF0F6F0DF59B90D3E1B00244FA024983FD573D2EFDD68F
File Size: 568.32 KB, 568320 bytes
MD5: 23c6863584934819cafcc7c2dd72c964
SHA1: 4cc9ef239e9465fe8bd07e9874c42e5189ed71dd
SHA256: 55357C1468AC99C2B2A8ECF55151C3E80FE023712AB40B1A6BCB990EC1A85E18
File Size: 577.02 KB, 577024 bytes
MD5: a4f0b2b60debd830f659bc429c24f978
SHA1: 28c4ee4e97bb8f7be3c7433ff8e1fd7602aee834
SHA256: 8931F3A1FDA7881F6472DD4A6692BA8CC2C831CC6DF333BD9E2233557DE8EB0C
File Size: 578.05 KB, 578048 bytes
MD5: 2de0031388566aa23e568aa76b12c352
SHA1: 28510d8bf4f28444efb4a19c687bcd82fc0231fb
SHA256: 5F242A99C4E56F8A9897708027F30FEF39319C621766A45C6443E83A8BEDF058
File Size: 576.51 KB, 576512 bytes
MD5: ef4bcb110376f885c7a38fd64517179b
SHA1: 49de6c7ab21ca282497487fee27c5eb1d4f59253
SHA256: 5D33185C1C4B086E87334F7435660E5E9F4E8765E25BF6AAFD4A96E7B46DDAE9
File Size: 531.46 KB, 531456 bytes
MD5: 379c0fdfcf8273b5190ee2b4543ca8cf
SHA1: dc9c48fc99bb271c19507e99705ea247d386181d
SHA256: E6F250CEFEFF5E6D0659FFF225D59C1ED5C6030B48FE6F6FD2E28976A739E5A4
File Size: 622.08 KB, 622080 bytes
MD5: b348c872fa60d4cb0915874c57279c1d
SHA1: 5d8e5aeb5a6a88b497e9123211961db145f8839b
SHA256: 801BF88F5FD2A843B3FE502B1361AF51F3FC3C6C4141E17596D671197A635732
File Size: 528.38 KB, 528384 bytes
MD5: 198f9ce83c59fb86229244b95a7673f5
SHA1: 8ebcc4510a302b4edea8a44987b755b69ff7ce03
SHA256: 639D7D9017C70405D60E39F54821432BB34BCC87C3612EEA5CAD1B5780242078
File Size: 685.57 KB, 685568 bytes
MD5: e0752840a54cb4647f82c80a50fca80e
SHA1: d7c6a1917f4744210795b4e4f472ac7656bfbcbe
SHA256: 19D1DD64F3E5A052FE931BA0B8A9CAB6723DB541A9AECE3812DC78C46B46672E
File Size: 686.08 KB, 686080 bytes
MD5: 385a9bded9b073b18b168bc034f934b5
SHA1: cbe3d0301f0274a3f9cbd223033a619ecdd2e59d
SHA256: 86B9FC468E13235003066C38F0606CEEC093FC1130DA10A4C12EB7B15C54387C
File Size: 785.41 KB, 785408 bytes
MD5: 39a19118f2d38bfdb9421f69a84e5dec
SHA1: be34707cb56d7b41393d14c67b4ad8626c4519d7
SHA256: 8A82DA328A3DB0FCA63F31E7B464B5989CECFD619EBAB0B238C07B63544BF823
File Size: 786.43 KB, 786432 bytes
MD5: 8651b93f925078cfc567e234ea355ac4
SHA1: a035971e352a592a9783c7d31313c4888180a3d9
SHA256: 1C254078609515371EF4C25B4E8EE3FA892BB6432FBA7430581DFC9878BA3261
File Size: 784.90 KB, 784896 bytes
MD5: 3a62a6fdd9372b5cbaa82f91740baf5a
SHA1: 600a9b073b98040c935767da80719ccbdcccf1b1
SHA256: A634C7105A87384125615A99C88EC334654EEC4063FF2650FE9A227EF1F3723C
File Size: 784.90 KB, 784896 bytes
MD5: 757b09fc557de9bc5d316a52998649a0
SHA1: fbf15b1e1c4ccd819508ac9e88ffa159347a7a62
SHA256: 58A05E5D5FFD86BA2F2A8E65156B5D8127A1F1381BE3FBC87B9A4A51E0A3AD9B
File Size: 784.90 KB, 784896 bytes
MD5: 1f1d36bf90164ce7d6f2ef2b158cf4d2
SHA1: 18dd534a7d95ac8fd6067b1d03f56391620f15de
SHA256: 08F7ECC4BFA5230F379B7FB74AC3819F26412A6CF5FD2964ED27F1291848D2DB
File Size: 785.41 KB, 785408 bytes
MD5: c17ced7a966fbddb5ad8b4ba1cc9b5b3
SHA1: c589e55118e38adca58345773b64d5f5bc56b1a4
SHA256: D8C817B52B56072C6ED0143A4626C7CFC60529340670975EC22EAF5CB17EB91C
File Size: 605.18 KB, 605184 bytes
MD5: c469914597f384467532eb040705b7f7
SHA1: fc591c2a117a32dd566efb8f4314ed01a41ef36a
SHA256: C7647AA83DD73D30C7C55F50044F1061D3C0F4B9A42FBB69CFB91776935A9ADC
File Size: 605.18 KB, 605184 bytes
MD5: 306f001ffc2032847954ce8d0ee6eef2
SHA1: 84dd1802e4f56b8e11cd28d61a9236e71dd445bb
SHA256: A61B02B235AC041F12A1CCE7AE4E40E4A845E2265666CC266F72B5C13B94FA88
File Size: 608.26 KB, 608256 bytes
MD5: 4aeff1b8916c6a4c9e6b4c65f4012994
SHA1: 66da0fd03399463971ca71d898a8f2ec49a13c4e
SHA256: 942F2668E6611CE547411BA1A04224AEFE461ACF710F29A9CE7663607A125B41
File Size: 829.44 KB, 829440 bytes
MD5: 02db485105be3075a8fff129ad9f105a
SHA1: acd23fc4348f98845d907e7bc57e151d182fcc91
SHA256: 4BC0F3939BFB316CCFD6458797CBB9595F4F76D435A087478EA46BFF60C89089
File Size: 786.43 KB, 786432 bytes
MD5: 0444dfa4bd00c74c8335cbcba1b667ea
SHA1: d88346deaec3d03a09ba430630dda992decd5bc4
SHA256: 6A0FB35B3584468D5395C3D1402AE9AC568E04A883FEBD2CE495E3DA7599E6AE
File Size: 820.74 KB, 820736 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
File Version 1.0.0.0
Internal Name
  • Bdmdz.exe
  • Bqdaxl.exe
  • Cpgyjjcbh.exe
  • Cutggonnjpn.exe
  • Cywnahmizl.exe
  • Ebktuhnl.exe
  • Ecscysoyv.exe
  • Fcfsx.exe
  • Fxbgbradrxf.exe
  • Gcorenbjw.exe
Show More
  • Gsepsayswk.exe
  • Hdvsi.exe
  • Hjziw.exe
  • Jafhavuxrar.exe
  • Jnwarzpl.exe
  • Jxbbmqrs.exe
  • Kdnvm.exe
  • Lcahqhwkzj.exe
  • Lmhopm.exe
  • Miyinhylx.exe
  • Ndgxzuwg.exe
  • Nenucbu.exe
  • Npkzvazxvd.exe
  • Nqsjntiwuib.exe
  • Ohnzgtxfrd.exe
  • Pdxnvgaglz.exe
  • Sholflulvh.exe
  • Ufhcuhsp.exe
  • Umlkn.exe
  • Wlyfpwqqbik.exe
  • Wokfar.exe
  • Wqouxuwmxr.exe
  • Xhvnmar.exe
  • Xjorcmmhk.exe
  • Zctknzd.exe
  • Zofywo.exe
  • Zvcbwo.exe
Original Filename
  • Bdmdz.exe
  • Bqdaxl.exe
  • Cpgyjjcbh.exe
  • Cutggonnjpn.exe
  • Cywnahmizl.exe
  • Ebktuhnl.exe
  • Ecscysoyv.exe
  • Fcfsx.exe
  • Fxbgbradrxf.exe
  • Gcorenbjw.exe
Show More
  • Gsepsayswk.exe
  • Hdvsi.exe
  • Hjziw.exe
  • Jafhavuxrar.exe
  • Jnwarzpl.exe
  • Jxbbmqrs.exe
  • Kdnvm.exe
  • Lcahqhwkzj.exe
  • Lmhopm.exe
  • Miyinhylx.exe
  • Ndgxzuwg.exe
  • Nenucbu.exe
  • Npkzvazxvd.exe
  • Nqsjntiwuib.exe
  • Ohnzgtxfrd.exe
  • Pdxnvgaglz.exe
  • Sholflulvh.exe
  • Ufhcuhsp.exe
  • Umlkn.exe
  • Wlyfpwqqbik.exe
  • Wokfar.exe
  • Wqouxuwmxr.exe
  • Xhvnmar.exe
  • Xjorcmmhk.exe
  • Zctknzd.exe
  • Zofywo.exe
  • Zvcbwo.exe
Product Version 1.0.0.0

File Traits

  • .NET
  • GenKrypt
  • HighEntropy
  • Reactor
  • RijndaelManaged
  • x64
  • x86

Block Information

Total Blocks: 39
Potentially Malicious Blocks: 2
Whitelisted Blocks: 37
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.MOU
  • MSIL.Agent.ONR
  • MSIL.Agent.XDFA
  • MSIL.Krypt.GJLD
  • MSIL.Krypt.GJLF
Show More
  • MSIL.Mardom.TJA
  • MSIL.Mardom.TK
  • MSIL.Stealer.LKA
  • MSIL.Stealer.LKB

Files Modified

File Attributes
\device\namedpipe\dav rpc service Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\pshost.134184613086641008.7804.defaultappdomain.powershell Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
\device\namedpipe\pshost.134207209880921577.6700.defaultappdomain.powershell Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
\device\namedpipe\pshost.134210173871448413.2772.defaultappdomain.powershell Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
\device\namedpipe\pshost.134212658730818527.5728.defaultappdomain.powershell Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
\device\namedpipe\pshost.134213986267673891.7428.defaultappdomain.powershell Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
\device\namedpipe\pshost.134228562882993273.4400.defaultappdomain.powershell Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
\device\namedpipe\pshost.134239534494283041.4004.defaultappdomain.powershell Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
\device\namedpipe\pshost.134247983802275707.8600.defaultappdomain.powershell Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
\device\namedpipe\pshost.134253667006813977.1672.defaultappdomain.powershell Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
Show More
\device\namedpipe\pshost.134266984656351735.2744.defaultappdomain.powershell Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
\device\namedpipe\pshost.134270717858926057.6528.defaultappdomain.powershell Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
\device\namedpipe\pshost.134271451053731057.6132.defaultappdomain.powershell Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
\device\namedpipe\wkssvc Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.0.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.1.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.2.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\__psscriptpolicytest_03yrj4bo.5q1.psm1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_0tkvf5fz.m1v.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_134g43ko.mda.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_305mmnxl.ps3.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_3bnvck0k.u2e.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_3ox3hk31.jao.psm1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_4wlade1u.dts.psm1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_a330xyqt.aed.psm1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_c5gaogjr.ue0.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_cyecqs13.pmq.psm1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_dxqzgt23.b2j.psm1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_fcv5j1ql.0cs.psm1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_kt44qbhm.og4.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_m3zlrlwl.lzb.psm1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_ps1xjjcc.iat.psm1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_r5r1h2l4.rzn.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_suiwfsez.12m.psm1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_ta24s3a0.fzl.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_u5zdlbrn.sof.psm1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_urmhtweg.mkl.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_vwjg21zi.iuv.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_yrdrauut.bdn.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_zp5kse2v.fb4.psm1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_zv0xxt3c.lmd.ps1 Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\tracing\rasapi32::enablefiletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::enableautofiletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::enableconsoletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::maxfilesize  RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::filedirectory %windir%\tracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::enablefiletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::enableautofiletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::enableconsoletracing RegNtPreCreateKey
Show More
HKLM\software\microsoft\tracing\rasmancs::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::maxfilesize  RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::filedirectory %windir%\tracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enablefiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enableautofiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::maxfilesize  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::filedirectory %windir%\tracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enablefiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enableautofiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::maxfilesize  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::filedirectory %windir%\tracing RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 㣬핛렱ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 籬ཇ첿ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe T⫝̸콱ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 睪렆톳ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ꈽ콧틨ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 滖녣ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 㒜㡠ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 釄穟ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ﷚도ǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 滑疊̜ǝ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 蚇ꦿځǝ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe �ۏ_,� RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAllocateLocallyUniqueId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreatePortSection
  • ntdll.dll!NtAlpcCreateResourceReserve
  • ntdll.dll!NtAlpcCreateSectionView
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcDeleteSecurityContext
Show More
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcQueryInformationMessage
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtAlpcSetInformation
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelTimer2
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCompareSigningLevels
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtGetCachedSigningLevel
  • ntdll.dll!NtGetCompleteWnfStateSubscription
  • ntdll.dll!NtGetContextThread
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtPowerInformation
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryObject
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtQueueApcThread
  • ntdll.dll!NtQueueApcThreadEx2
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationObject

32 additional items are not displayed above.

User Data Access
  • GetComputerName
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserName
  • GetUserNameEx
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Other Suspicious
  • AdjustTokenPrivileges
Network Info Queried
  • GetAdaptersAddresses
  • GetNetworkParams
Network Winsock2
  • WSASend
  • WSASocket
  • WSAStartup
  • WSAttemptAutodialName
Network Winsock
  • bind
  • closesocket
  • freeaddrinfo
  • getaddrinfo
  • setsockopt
Network Winhttp
  • WinHttpOpen
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess

Shell Command Execution

"powershell.exe" -NoProfile -Command "Add-MpPreference -ExclusionPath 'C:\Users\Gfzzomzv\AppData\Roaming\WindowsServices\FLiNG-AutoUpdate.exe'
"powershell.exe" -NoProfile -Command "Add-MpPreference -ExclusionPath 'C:\Users\Kdhwwjgn\AppData\Roaming\msvcp110_win\msvcp110.exe'
"powershell.exe" -NoProfile -Command "Add-MpPreference -ExclusionPath 'C:\Users\Ejpjzmjm\AppData\Roaming\msvcp110_wins\msvcps10.exe'