Threat Database Trojans Trojan.MSIL.Krypt.MBAXL

Trojan.MSIL.Krypt.MBAXL

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 234
First Seen: December 19, 2023
Last Seen: August 28, 2025
OS(es) Affected: Windows

The detection of Trojan.MSIL.Krypt.MBAXL on your system indicates a potential security threat. This type of malware is designed to compromise the integrity of your computer, allowing unauthorized access and control. It is essential to understand the nature of this threat and take immediate action to remove it and prevent further damage.

What Is Trojan.MSIL.Krypt.MBAXL?

Trojan.MSIL.Krypt.MBAXL is a type of Trojan horse malware, which is a broad category of malicious software that disguises itself as legitimate programs. The name suggests it may be related to MSIL (Microsoft Intermediate Language), which is a programming language used by the .NET Framework, but without more specific information, it's difficult to determine its exact origin or purpose. Trojans are known for their ability to sneak past security defenses, often by posing as useful applications or attachments.

How Trojan.MSIL.Krypt.MBAXL Operates

Once installed on a system, Trojan.MSIL.Krypt.MBAXL can operate in various ways, depending on its intended purpose. Trojans can create backdoors, allowing remote access to the infected computer. They can also steal sensitive information, such as passwords, credit card numbers, and personal data. Additionally, Trojans can install additional malware, hijack system resources for malicious activities like cryptocurrency mining, or disrupt system operation to demand ransom.

Symptoms of Infection

Symptoms of a Trojan infection can vary widely. You might notice your computer running slower than usual, experiencing frequent crashes, or displaying unusual error messages. There could be unfamiliar programs or icons on your desktop, or you might receive alerts from your security software indicating suspicious activity. Sometimes, the presence of a Trojan can be almost invisible, making it crucial to have robust security measures in place.

  • Unexplained changes in system settings or files.
  • New, unfamiliar icons or programs.
  • Frequent system crashes or freezes.
  • Increased network activity without apparent cause.
  • Pop-ups or spam messages.

How to Remove Trojan.MSIL.Krypt.MBAXL

  1. Boot your computer in Safe Mode with Networking to limit the malware's ability to interfere with the removal process.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all instances of the malware.
  3. Uninstall any suspicious programs or applications that you do not recognize or that were installed around the time the malware was detected.
  4. Reset your web browsers (Chrome, Firefox, Edge, etc.) to their default settings to remove any malicious extensions or settings changes made by the Trojan.
  5. Reboot your computer and run another full scan with your anti-malware tool to ensure that all remnants of the malware have been removed.

Conclusion

Removing Trojan.MSIL.Krypt.MBAXL from your system requires careful and immediate action. By following the steps outlined and maintaining vigilance with robust security software and practices, you can protect your computer and personal data from this and other malware threats. Regular system updates, cautious internet browsing habits, and a reliable security suite are key to preventing future infections and ensuring the integrity of your digital environment.

Analysis Report

General information

Family Name: Trojan.MSIL.Krypt.MBAXL
Signature status: No Signature

Known Samples

MD5: 0bbfdee50cba8a6be73d884e15d19215
SHA1: 176751a52c3f3237267855aa6dacb8fd561aa90d
SHA256: 50CFB392E547BCA134EF558C05425093FAB7BEE2D062E5A28AE876B50FE14A78
File Size: 170.50 KB, 170496 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
File Description updater
File Version 1.0.0.0
Internal Name updater.exe
Legal Copyright Copyright © 2017
Original Filename updater.exe
Product Name updater
Product Version 1.0.0.0

File Traits

  • .NET
  • .sdata
  • Reactor
  • RijndaelManaged
  • x86

Block Information

Total Blocks: 943
Potentially Malicious Blocks: 140
Whitelisted Blocks: 721
Unknown Blocks: 82

Visual Map

? 0 0 0 0 0 x ? 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 x x x x x 0 0 0 0 0 0 0 0 x 0 x 0 x 0 x 0 x x 0 x x 0 x x x 0 0 x x 0 0 x 0 0 0 0 x 0 0 0 0 x 0 0 0 0 x x x 0 x x 0 0 x 0 x 0 x 0 x 0 0 x 0 x 0 0 x 0 0 0 x 0 x 0 x x x x 0 0 0 x 0 x x 0 0 x 0 x x x x 0 x 0 0 0 x 0 x 0 x 0 x x 0 0 0 0 0 0 0 x 0 x 0 x x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x 0 x x x 0 x 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 x x ? ? ? x ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x ? x 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 ? 0 0 0 0 0 0 0 0 x x ? ? 0 0 0 0 0 0 0 ? x ? ? 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? ? ? x 0 0 0 0 0 0 0 0 0 0 0 ? x ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? x ? 0 0 0 0 0 0 0 0 0 0 0 ? ? ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? x 0 0 0 0 0 0 0 0 0 0 0 0 ? x ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? x ? 0 0 0 0 0 0 0 ? x ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 x 0 x 0 0 x 0 x 0 0 x 0 x 0 0 x 0 x 0 0 0 0 ? x ? 0 0 0 0 0 0 0 0 x x ? 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Coinminer.AEA
  • MSIL.Krypt.MBAXL

Files Modified

File Attributes
c:\windows\appcompat\programs\amcache.hve Read Data,Read Control,Write Data
c:\windows\appcompat\programs\amcache.hve.log1 Read Data,Write Data
c:\windows\appcompat\programs\amcache.hve.log2 Read Data,Write Data

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAdjustPrivilegesToken
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcDeleteSecurityContext
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClose
Show More
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeleteValueKey
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtLoadKeyEx
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetObjectInformation
  • win32u.dll!NtUserGetProcessWindowStation
  • win32u.dll!NtUserGetThreadDesktop
  • win32u.dll!NtUserGetThreadState
User Data Access
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
Process Shell Execute
  • CreateProcess
Encryption Used
  • BCryptOpenAlgorithmProvider
Process Manipulation Evasion
  • ReadProcessMemory

Shell Command Execution

C:\Windows\Microsoft.NET\Framework64\v2.0.50727\\dw20.exe dw20.exe -x -s 772

Related Posts

Trending

Most Viewed

Loading...