Threat Database Trojans Trojan.MSIL.Krypt.MDA

Trojan.MSIL.Krypt.MDA

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 1,102
First Seen: April 20, 2021
Last Seen: July 30, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Krypt.MDA on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the security and integrity of your computer, potentially leading to unauthorized access, data theft, and other malicious activities. It is essential to understand the nature of this threat and take prompt action to remove it and prevent future infections.

What Is Trojan.MSIL.Krypt.MDA?

Trojan.MSIL.Krypt.MDA is a type of Trojan horse malware that can infect your computer through various means, such as downloading malicious software, opening infected email attachments, or visiting compromised websites. Once installed, it can perform a range of malicious activities, including data theft, keystroke logging, and unauthorized access to your system. The name "Trojan.MSIL.Krypt.MDA" suggests that it may be related to the .NET framework and may use encryption to conceal its activities.

How Trojan.MSIL.Krypt.MDA Operates

Trojan.MSIL.Krypt.MDA operates by exploiting vulnerabilities in your system's security, allowing it to install and run malicious code without your knowledge or consent. It may use social engineering tactics, such as fake alerts or warnings, to trick you into installing or executing the malware. Once installed, it can communicate with its command and control servers to receive instructions and transmit stolen data. The malware may also attempt to disable your security software or intercept your internet traffic to steal sensitive information.

Symptoms of Infection

The symptoms of a Trojan.MSIL.Krypt.MDA infection can vary, but common signs include slow system performance, unexpected pop-ups or alerts, and unusual network activity. You may also notice that your antivirus software is disabled or that your browser is redirecting to unfamiliar websites. In some cases, the malware may not exhibit any noticeable symptoms, making it difficult to detect without proper scanning and analysis.

How to Remove Trojan.MSIL.Krypt.MDA

  1. Restart your computer in Safe Mode with Networking to prevent the malware from loading and to allow for a more effective removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect and remove the Trojan.MSIL.Krypt.MDA malware.
  3. Uninstall any suspicious programs or applications that may be related to the malware infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your computer and perform a follow-up scan to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.MSIL.Krypt.MDA from your system requires a combination of technical expertise and caution. By following the steps outlined above and using reputable security software, you can effectively remove the malware and prevent future infections. It is essential to remain vigilant and proactive in maintaining your system's security, including keeping your operating system and software up to date, using strong passwords, and avoiding suspicious downloads and email attachments. By taking these precautions, you can help protect your computer and personal data from the threats posed by Trojan.MSIL.Krypt.MDA and other types of malware.

Analysis Report

General information

Family Name: Trojan.MSIL.Krypt.MDA
Signature status: No Signature

Known Samples

MD5: 1206eadbb98db6c9207d74472076242d
SHA1: bee6f55b70e2aafbea726627ca61eb582ea903c8
File Size: 836.61 KB, 836608 bytes
MD5: 488eb643724256fb3147ecd3464d5e4e
SHA1: 9f77288a96d1aea9e4141750f0f140fdd6f6e8c1
SHA256: 1F16EAA77D63254125057A833BF74F492E0905C2037CF2DF380A3A7DDB43E953
File Size: 4.51 MB, 4514304 bytes
MD5: c28622f52461eb6e1d2629a4394bcc3e
SHA1: e077f3f43ebfa11c1b0f3bf61d3b608bce33b804
SHA256: D5BB458E10E3F639C509CB6E80F3E58579E90F601B3BDFEFAC9747E468E5CA39
File Size: 9.77 MB, 9768448 bytes
MD5: 5ec59bbadf68fde3cd4c7cfe58784eef
SHA1: 82b11bc60d119818f2d5b49cf258315e01e57db8
SHA256: 60D89475441ADCC432F4D69E9B86591E1A6A4E269A99406FA00AB64B21D5DD4B
File Size: 839.17 KB, 839168 bytes
MD5: 7d2c7a97b0164bcaaa74042fe86f7bf4
SHA1: 964ac57598c38c67524a33bdcabc26ded0f5a19b
SHA256: 7B57193575F92CE9E442B7A5D447E70227BEBD8DD86B3CD02D90862BE1A7835A
File Size: 430.59 KB, 430592 bytes
Show More
MD5: a14289c5124d691cf90e5a8beade3a0a
SHA1: db324fa3d2ab624cf52149ab8b579bd6eef50ac5
SHA256: 11827D9FAEAA16FE79D06D45E8A51AC025AC4F38FFEDC03BFAA105C7CC6DD092
File Size: 751.10 KB, 751104 bytes
MD5: ecfad8ff0f273336c22e83900587af64
SHA1: 03b8b2ace9352b4af53ba9445a6696b553a5217d
SHA256: 314445AEFCC85D8CD5F5B60FE87AFB4E28E87CCBEEF4E5C77E70C54BE9149F8E
File Size: 3.91 MB, 3910656 bytes
MD5: beff16c7736d21931562c938f15ccffc
SHA1: 5622d42883732dc94c6345ea87a01d4282558190
SHA256: AF32D7C1E3614979377AFD2F282B329D5804FD59746DADD6424F9F529377098D
File Size: 3.20 MB, 3201024 bytes
MD5: 8f2632520458b583fd5c5903289c27bc
SHA1: 340981725a3d96bafeadfc2c08950e6e627c733c
SHA256: 9E3A4515A046D4726A9092F62A43733DEFD0CB75980AF1BAEC0790A78E4548CE
File Size: 301.32 KB, 301322 bytes
MD5: 142c578c01208d0a31d9834b69a06991
SHA1: 6b2f6fd3e0a3b2910c022cd17e28b46f9fc93fb2
SHA256: 10A48606EEB6E84D8CB03AA8CBBAFBF8EB0D92711B19CC362D5519B773B06CCD
File Size: 1.92 MB, 1915872 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File has exports table
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 8.5.0.0
  • 6.0.0.40
  • 5.21.23.1
  • 1.0.0.1
  • 1.0.0.0
Comments
  • 28/02/2025
  • ProspectMais Whats Sender
Company Name
  • HP Inc.
  • ProspectMais
  • TEP
File Description
  • ADUANA
  • Contactos Zurich
  • DentiOne
  • Expedientes
  • FluentDesignApp
  • Iris
  • PECOM
  • ProspectMais Whats Sender
  • PuntoVenta
File Version
  • 8.5.0.0
  • 6.0.0.40
  • 5.21.23.1
  • 1.0.0.2
  • 1.0.0.0
Internal Name
  • ADUANA.exe
  • Contactos Zurich.exe
  • DashBoardApp.exe
  • DentiOne.exe
  • Iris.exe
  • JBH Expedienta 2022.exe
  • PECOM.exe
  • ProspectMais_Whats_Sender.exe
  • PuntoVenta.exe
Legal Copyright
  • Copyright © 2016
  • Copyright © 2017
  • Copyright © 2018
  • Copyright © 2018 - 2019
  • Copyright © 2020
  • Copyright © 2024
  • Copyright © HP Inc. 2019
  • Copyright © HP Inc. 2020
  • Copyright © TEP 2025
Legal Trademarks
  • ProspectMais Whats Sender
  • TEP
Original Filename
  • ADUANA.exe
  • Contactos Zurich.exe
  • DashBoardApp.exe
  • DentiOne.exe
  • Iris.exe
  • JBH Expedienta 2022.exe
  • PECOM.exe
  • ProspectMais_Whats_Sender.exe
  • PuntoVenta.exe
Product Name
  • ADUANA
  • Contactos Zurich
  • DentiOne
  • Expedientes
  • FluentDesignApp
  • Iris
  • PECOM
  • ProspectMais Whats Sender
  • PuntoVenta
Product Version
  • 8.5.0.0
  • 6.0.0.40
  • 5.21.23.1
  • 1.0.0.2
  • 1.0.0.0

Digital Signatures

Signer Root Status
DESKTOP-4HJ7B15\Jorge DESKTOP-4HJ7B15\Jorge Self Signed

File Traits

  • .NET
  • HighEntropy
  • NewLateBinding
  • RijndaelManaged
  • x86

Block Information

Total Blocks: 220
Potentially Malicious Blocks: 5
Whitelisted Blocks: 159
Unknown Blocks: 56

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 ? 0 0 ? 0 0 0 ? ? ? 0 0 ? 0 0 ? 0 0 0 0 0 0 0 x ? ? 0 ? ? ? ? 0 0 ? 0 0 0 0 ? 0 0 0 0 x x ? x x ? 0 0 ? 0 0 0 0 0 ? ? 0 0 ? 0 0 0 0 0 0 0 ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Agent.XX
  • MSIL.Brute.ME
  • MSIL.Bulz.PPA
  • MSIL.Downloader.Agent.CAL
  • MSIL.Gamehack.BYJ
Show More
  • MSIL.Gamehack.BYZQ
  • MSIL.Gamehack.YR
  • MSIL.Inject.CCA
  • MSIL.Krypt.JOB
  • MSIL.Krypt.MBHVM

Windows API Usage

Category API
User Data Access
  • GetComputerName
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
Keyboard Access
  • GetKeyState
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
Show More
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN