Threat Database Backdoors Backdoor.MSIL.AgentTesla.PH

Backdoor.MSIL.AgentTesla.PH

By CagedTech in Backdoors

Threat Scorecard

Popularity Rank: 9,634
Threat Level: 60 % (Medium)
Infected Computers: 65
First Seen: August 28, 2024
Last Seen: July 13, 2026
OS(es) Affected: Windows

The detection of Backdoor.MSIL.AgentTesla.PH on your system indicates a potential security threat that requires immediate attention. This detection name suggests a backdoor threat, which is a type of malware designed to allow unauthorized access to a compromised system. It is essential to understand the nature of this threat and take prompt action to remove it and prevent further damage.

What Is Backdoor.MSIL.AgentTesla.PH?

Backdoor.MSIL.AgentTesla.PH is identified as a backdoor threat, which means it is designed to create a covert communication channel between the compromised system and a command and control (C2) server controlled by the attacker. This allows the attacker to remotely access the system, steal sensitive information, install additional malware, or use the system for malicious activities. The name itself does not directly indicate a specific malware family, but its characteristics align with backdoor malware behavior.

How Backdoor.MSIL.AgentTesla.PH Operates

Backdoor malware like Backdoor.MSIL.AgentTesla.PH typically operates by establishing a connection with its C2 server, awaiting commands to execute on the compromised system. These commands can range from data exfiltration to downloading and installing additional malware. The backdoor can be installed through various means, including exploited vulnerabilities, phishing attacks, or drive-by downloads. Once installed, it can hide its presence by using rootkit techniques or disguising itself as a legitimate process.

Symptoms of Infection

Symptoms of a backdoor infection can be subtle and may not always be immediately apparent. However, signs may include unusual network activity, slow system performance, unexpected changes in system settings, or the appearance of unfamiliar programs. In some cases, the system may become unstable, or certain applications may not function correctly. Given the stealthy nature of backdoors, some infections may only be discovered through the use of security software.

How to Remove Backdoor.MSIL.AgentTesla.PH

  1. Boot your system into Safe Mode with Networking to prevent the malware from loading and to allow for a more effective removal process.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all components of the malware.
  3. Uninstall any suspicious programs or applications that were installed around the time of the infection. Be cautious and only remove programs you are certain are malicious or unnecessary.
  4. Reset your web browsers (Chrome, Firefox, Edge) to their default settings to remove any malicious extensions or settings changes made by the malware.
  5. Reboot your system and perform another full scan with your anti-malware tool to ensure that all malware components have been removed.

Conclusion

The removal of Backdoor.MSIL.AgentTesla.PH requires a thorough approach to ensure that all components of the malware are eliminated from the system. It is crucial to act quickly to prevent further damage or unauthorized access. After removal, consider enhancing your system's security by keeping your operating system and software up to date, using strong antivirus software, and practicing safe computing habits, such as avoiding suspicious links and attachments. Regular backups of important data can also protect against data loss in case of future infections or system failures.

Analysis Report

General information

Family Name: Backdoor.MSIL.AgentTesla.PH
Signature status: No Signature

Known Samples

MD5: 1367070e83b95143106feba12485eb58
SHA1: 14b311b68a1f0a7b7beb91622edc88bb7d7a7ade
SHA256: F10B6C4DB40AD84F88F9F4591D68B3DE2B3F19E46751D4A8869A346647FC6443
File Size: 865.79 KB, 865792 bytes
MD5: 6eb464923ac1f94dc8d9563f1afc4bbb
SHA1: 94c038eb19623856a5b500564838fec2446eac0c
SHA256: 342AC1F8CB57D8745155D4DD1C8395131CB0C8FB11F2B8D031B92EAD0F4556B6
File Size: 841.22 KB, 841216 bytes
MD5: 2b5882623a545a457ae157812e6163fc
SHA1: 8abdfb8638943fb02fd8a213df62b2d3f3f4ee68
SHA256: 7FE162B84E6D99ECAFE3DCD7418848246A7B3FACF9EACD03A0B6F54EFFC925C2
File Size: 418.82 KB, 418816 bytes
MD5: 7dbb8b87a7bc6ce2d0c44a36685d88e3
SHA1: cccb92152459d31b9c48c9c4ca0a24bab02d9905
SHA256: FCE4F1C8C5AC29A62EBB007AB3EAE83D24E4FBFD833319DDC4BF62C2ABAAC73A
File Size: 435.71 KB, 435712 bytes
MD5: 8c265a26ffeafa347a9607f36d353250
SHA1: 29f53d09473d0f32dc5e0ed22a41a2ab46d9fa8b
SHA256: B305079D40311C34F42BEFFA8668E17EDDBEBDE00EC0DA04CE43CA25E12B60F2
File Size: 434.18 KB, 434176 bytes
Show More
MD5: fe67f0a9a31716d9c7e67af6a5a2df0e
SHA1: e4dfc0763e86f9d295c8e10947363577b4c14f7e
SHA256: E4355C6FC5F24CD6584A525C12AF5B6378D776738CB6192A0D4BAC3584FB1732
File Size: 356.35 KB, 356352 bytes
MD5: 78669fd74bb82a1f51a2d1c0e4fb559d
SHA1: 17c7791074bc4d4bc029c68a9c2e31d6f2bdbd88
SHA256: C16C14909E7C32F5B9997C79F985D310475732E5BBA28A5151008FDC72479C13
File Size: 693.25 KB, 693248 bytes
MD5: e6cd02ded4128b72d2913229b3f3d720
SHA1: 23561dbad509dca39ac014241c1ee58a3bedde87
SHA256: 6DF97E5CC8FD351306954FCA5216D6BB094BEB9094D2112038587C6624E86BEA
File Size: 8.92 MB, 8919552 bytes
MD5: 31e3ff656c560c349a9b825dc48bbe2d
SHA1: 92e1bbb069440fc30775fdd75d78981cca35cbb6
SHA256: 1B8D2DB9AACD73F1F65EA72CA0C7ACEF5A83F38ED928F8B05515FCDF83C01B7A
File Size: 1.81 MB, 1808384 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File has exports table
  • File is .NET application
  • File is 32-bit executable
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
Show More
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 6.3.3.3
  • 5.5.4.2
  • 3.3.3.3
  • 2.2.2.2
  • 1.0.0.0
Comments
  • DOUTSPDWPRLATS
  • ENGREGUNANS
  • KROMASTICOSPRONATIVOS
  • TIMESCANASTRAONFIRES
  • Xoay text trong layout/model Autocad
Company Name
  • 0987606292
  • DOUTSPDWPRLATS
  • ENGREGUNANS
  • KROMASTICOSPRONATIVOS
  • TIMESCANASTRAONFIRES
File Description
  • Alpaca
  • DOUTSPDWPRLATS
  • ENGREGUNANS
  • KROMASTICOSPRONATIVOS
  • Rotate text in Layout/model Autocad
  • TIMESCANASTRAONFIRES
File Version
  • 6.3.3.2
  • 5.5.4.6
  • 3.3.3.3
  • 2.7.2.2
  • 1.0.0.0
  • 1.0
Internal Name
  • AlpacaCheats.exe
  • Bfnibxg.exe
  • Plex.dll
  • Rljaopbdsp.exe
  • Rmkbtgg.exe
  • RotateTextInViewport (RTV).dll
  • Virtual Piano.dll
  • WindowsHDRCalibration.dll
Legal Copyright
  • Copyright © 2026
  • DOUTSPDWPRLATS
  • ENGREGUNANS
  • KROMASTICOSPRONATIVOS
  • TIMESCANASTRAONFIRES
  • ©2023 Hieuntvn@wru.vn 0987606292
Legal Trademarks
  • DOUTSPDWPRLATS
  • ENGREGUNANS
  • KROMASTICOSPRONATIVOS
  • TIMESCANASTRAONFIRES
Original Filename
  • AlpacaCheats.exe
  • Bfnibxg.exe
  • Plex.dll
  • Rljaopbdsp.exe
  • Rmkbtgg.exe
  • RotateTextInViewport (RTV).dll
  • Virtual Piano.dll
  • WindowsHDRCalibration.dll
Product Name
  • Alpaca
  • DOUTSPDWPRLATS
  • ENGREGUNANS
  • Hieuntvn
  • KROMASTICOSPRONATIVOS
  • TIMESCANASTRAONFIRES
Product Version
  • 6.3.3.2
  • 5.5.4.6
  • 3.3.3.3
  • 2.7.2.2
  • 1.0.0.0
  • 1.0

File Traits

  • .NET
  • dll
  • GenKrypt
  • HighEntropy
  • Reactor
  • Reflective
  • RijndaelManaged
  • x64
  • x86

Block Information

Total Blocks: 108
Potentially Malicious Blocks: 40
Whitelisted Blocks: 63
Unknown Blocks: 5

Visual Map

0 x 0 x 0 x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x 0 0 0 x x ? ? x ? 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x x 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Agent.GOE
  • MSIL.Agent.ONH
  • MSIL.AgentTesla.DH
  • MSIL.AgentTesla.PH
  • MSIL.Bulz.KA
Show More
  • MSIL.Downloader.JPB
  • MSIL.Downloader.PFA
  • MSIL.Downloader.PFB
  • MSIL.Downloader.XN
  • MSIL.Heracles.XC
  • MSIL.Krypt.GEFT
  • MSIL.Krypt.GJLD
  • MSIL.Krypt.MBAZO
  • MSIL.Kryptik.SC
  • MSIL.Mardom.AJ
  • MSIL.Mardom.AY
  • MSIL.Mardom.TJA
  • MSIL.Quasar.BV
  • MSIL.Quasar.I
  • MSIL.ShellcodeRunner.XB
  • MSIL.Stealer.PAE
  • MSIL.Stealer.PHE
  • MSIL.XWorm.G

Files Modified

File Attributes
\device\namedpipe\dav rpc service Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\pshost.134185330248234952.7968.defaultappdomain.powershell Generic Read,Write Data,Write Attributes,Write extended,Append data,LEFT 524288
\device\namedpipe\wkssvc Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\__psscriptpolicytest_tnd5mpnd.ir3.ps1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\__psscriptpolicytest_uvfuwcop.sfm.psm1 Generic Write,Read Attributes
c:\users\user\appdata\local\temp\alpaca.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\bebasneue-regular.ttf Generic Write,Read Attributes
c:\users\user\appdata\roaming\e4dfc0763e86f9d295c8e10947363577b4c14f7e_0000356352 Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ॰쾍룘ǜ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �m.tX �v �Z�����5#��&� (�*J1`1�1HO@V�A��G�IH[uH�pb"hk`k�ql(�q�XtǤ{b��P��/������7�������X�����.�m�Ù��IV�gi����$�8წ���Κ�>��&MA�=�SB1_B��T�Vw�`�V��%�������A RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelTimer2
  • ntdll.dll!NtCancelWaitCompletionPacket
Show More
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCompareSigningLevels
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtGetCachedSigningLevel
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtUnsubscribeWnfStateChange
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • ntdll.dll!NtYieldExecution
  • UNKNOWN
  • win32u.dll!NtGdiBitBlt
  • win32u.dll!NtGdiCreateBitmap

46 additional items are not displayed above.

User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserName
  • GetUserNameEx
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Other Suspicious
  • AdjustTokenPrivileges
Network Winsock2
  • WSAConnect
  • WSASocket
  • WSAStartup
  • WSAttemptAutodialName
Network Winsock
  • closesocket
  • freeaddrinfo
  • getaddrinfo
  • gethostname
  • setsockopt
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess

Shell Command Execution

"powershell.exe" Remove-ItemProperty -Path 'HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run' -Name 'e4dfc0763e86f9d295c8e10947363577b4c14f7e_0000356352'

Related Posts

Trending

Most Viewed

Loading...