Threat Database Backdoors Backdoor.MSIL.Agent.FBK

Backdoor.MSIL.Agent.FBK

By CagedTech in Backdoors

Threat Scorecard

Threat Level: 60 % (Medium)
Infected Computers: 3
First Seen: July 28, 2025
Last Seen: November 30, 2025
OS(es) Affected: Windows

The detection of Backdoor.MSIL.Agent.FBK on your system indicates a potential security threat that requires immediate attention. This backdoor threat can compromise the security and integrity of your computer, allowing unauthorized access and potentially leading to further malicious activities. It is essential to understand the nature of this threat and take prompt action to remove it and secure your system.

What Is Backdoor.MSIL.Agent.FBK?

Backdoor.MSIL.Agent.FBK is a type of backdoor threat that can create a covert communication channel between your computer and a remote server controlled by an attacker. This allows the attacker to access your system without your knowledge or consent, potentially leading to data theft, system compromise, or the installation of additional malware. The name suggests it is written in MSIL (Microsoft Intermediate Language), which is a platform-agnostic intermediate representation of the .NET Common Intermediate Language (CIL).

How Backdoor.MSIL.Agent.FBK Operates

Backdoor threats like Backdoor.MSIL.Agent.FBK typically operate by exploiting vulnerabilities in software or using social engineering tactics to trick users into installing them. Once installed, they can communicate with their command and control (C2) servers to receive instructions, which can include downloading and installing additional malware, stealing sensitive information, or using the compromised system for malicious activities such as spamming or participating in botnet attacks.

Symptoms of Infection

Symptoms of a Backdoor.MSIL.Agent.FBK infection can be subtle and may not always be immediately apparent. However, signs of infection can include unusual network activity, slow system performance, unexpected changes to system settings, or the appearance of unfamiliar programs or icons. If you suspect your system has been infected, it is crucial to take immediate action to mitigate the threat.

How to Remove Backdoor.MSIL.Agent.FBK

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for a cleaner environment to perform removal steps.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. This can help identify and remove the backdoor threat and any associated malware.
  3. Uninstall any suspicious programs or applications that you do not recognize or that were installed around the time of the suspected infection.
  4. Reset your web browsers (Chrome, Firefox, Edge, etc.) to their default settings to remove any malicious extensions or settings changes made by the malware.
  5. Reboot your system and perform another full scan with your anti-malware tool to ensure that the threat has been fully removed.

Conclusion

Removing Backdoor.MSIL.Agent.FBK requires careful and immediate action to prevent further system compromise and potential data loss. By following the steps outlined above and maintaining good security practices, such as keeping your operating system and software up to date, using strong antivirus software, and being cautious with emails and downloads, you can help protect your system from similar threats in the future. Regularly scanning your system for malware and being vigilant for signs of infection are key components of a robust security strategy.

Analysis Report

General information

Family Name: Backdoor.MSIL.Agent.FBK
Signature status: No Signature

Known Samples

MD5: 7e16aeab737c35d72fd2c75294ee40d9
SHA1: fcfa480d9821d158a3d1e5b7ad9f8789129d372d
SHA256: 35A6FD0302BD10FE151825FF87BFA237D3015E71FE3BD9D51F1E2ECB362B925C
File Size: 88.06 KB, 88064 bytes
MD5: 81a51be1d2ecaa472d76393477b7d12c
SHA1: 35c3681ba36363ff849468c00ca0b4833e4c7bf1
SHA256: 75C34963CC931355215F4E5D8FAA9984DB14793306C250017A5138EC58F28532
File Size: 125.95 KB, 125952 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
Company Name Microsoft Corporation
File Description
  • version
  • Windows Explorer
File Version
  • 10.0.19041.1503 (WinBuild.160101.0800)
  • 1.0.0.0
Internal Name
  • explorer
  • version.exe
Legal Copyright
  • Copyright © 2025
  • © Microsoft Corporation. All rights reserved.
Original Filename
  • EXPLORER.EXE
  • version.exe
Product Name
  • Microsoft® Windows® Operating System
  • version
Product Version
  • 10.0.19041.1503
  • 1.0.0.0

File Traits

  • .NET
  • RijndaelManaged
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 92
Potentially Malicious Blocks: 3
Whitelisted Blocks: 70
Unknown Blocks: 19

Visual Map

0 0 0 0 0 0 ? 0 0 0 0 0 0 0 x 0 0 0 ? 0 0 0 0 0 0 0 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Agent.DFDF
  • MSIL.Agent.FBK
  • MSIL.Agent.PI
  • MSIL.Bladabindi.R
  • MSIL.Gamehack.BOWB
Show More
  • MSIL.Gamehack.BOWD
  • MSIL.Krypt.FHH
  • MSIL.Krypt.YEK
  • MSIL.Kryptik.FHE
  • MSIL.Kryptik.FHM
  • MSIL.Njrat.J
  • MSIL.Spy.Agent.GAE

Files Modified

File Attributes
c:\windows\appcompat\programs\amcache.hve Read Data,Read Control,Write Data
c:\windows\appcompat\programs\amcache.hve Write Attributes

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAdjustPrivilegesToken
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreateSecurityContext
  • ntdll.dll!NtAlpcDeleteSecurityContext
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
Show More
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeleteValueKey
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtLoadKeyEx
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
Anti Debug
  • IsDebuggerPresent
Process Shell Execute
  • CreateProcess
Encryption Used
  • BCryptOpenAlgorithmProvider

Shell Command Execution

C:\Windows\Microsoft.NET\Framework64\v2.0.50727\\dw20.exe dw20.exe -x -s 696

Related Posts

Trending

Most Viewed

Loading...