Threat Database Backdoors Backdoor.MSIL.DiscordStealer.AV

Backdoor.MSIL.DiscordStealer.AV

By CagedTech in Backdoors, Stealers

Threat Scorecard

Popularity Rank: 5,706
Threat Level: 60 % (Medium)
Infected Computers: 163
First Seen: February 19, 2025
Last Seen: July 19, 2026
OS(es) Affected: Windows

The detection of Backdoor.MSIL.DiscordStealer.AV indicates that a potentially malicious program has been identified on your system. This name suggests a backdoor threat, which is a type of malware that allows unauthorized access to a computer system. It is essential to understand the nature of this threat and take immediate action to remove it and prevent further damage.

What Is Backdoor.MSIL.DiscordStealer.AV?

Backdoor.MSIL.DiscordStealer.AV appears to be a backdoor threat, which is a type of malware designed to bypass security mechanisms and allow unauthorized access to a computer system. The name itself does not provide specific information about the malware family or its origin. However, it is crucial to recognize that backdoor threats can be particularly dangerous, as they can lead to a range of malicious activities, including data theft, system compromise, and further malware infections.

How Backdoor.MSIL.DiscordStealer.AV Operates

Backdoor threats like Backdoor.MSIL.DiscordStealer.AV typically operate by creating a covert communication channel between the infected system and a command and control server controlled by the attacker. This allows the attacker to remotely access the system, steal sensitive information, and install additional malware. The specific mechanisms used by Backdoor.MSIL.DiscordStealer.AV are not publicly known, but it is likely that it uses common backdoor tactics, such as exploiting system vulnerabilities or disguising itself as a legitimate program.

Symptoms of Infection

Systems infected with Backdoor.MSIL.DiscordStealer.AV may exhibit a range of symptoms, including unusual network activity, slow system performance, and unexplained changes to system settings. In some cases, the infection may not produce any noticeable symptoms, making it difficult to detect without the use of specialized security software. It is essential to be vigilant and monitor system activity regularly to identify potential security threats.

  • Unusual network activity, such as unexpected outgoing connections
  • Slow system performance or crashes
  • Unexplained changes to system settings or files
  • Appearance of unknown or suspicious programs

How to Remove Backdoor.MSIL.DiscordStealer.AV

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for internet access.
  2. Use a reputable security tool, such as SpyHunter, to perform a full scan of your system and identify all malicious components.
  3. Uninstall any suspicious programs or applications that may be related to the infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or settings.
  5. Reboot your system and perform another full scan to ensure that all malicious components have been removed.

Conclusion

The detection of Backdoor.MSIL.DiscordStealer.AV is a serious security issue that requires immediate attention. By understanding the nature of this threat and taking prompt action to remove it, you can help prevent further damage and protect your system from potential harm. It is essential to remain vigilant and continue to monitor system activity regularly to identify potential security threats and prevent future infections.

Analysis Report

General information

Family Name: Backdoor.MSIL.DiscordStealer.AV
Signature status: No Signature

Known Samples

MD5: 391938cc272cd4822b39b01ece9b4898
SHA1: 42ed0192ff9caad8972e6b189ab4c1af7b2eb68b
SHA256: 264B238D10B842399084EEA4F715ED638F06FEE2D0DF22817C27F36A735283E0
File Size: 58.37 KB, 58368 bytes
MD5: 9bfe06b6d19f1ab32ce9cea7c38f455e
SHA1: 39a32c1be053dda7a8e2bb38d9f4cf601a213d74
SHA256: 3E2C7630BC24CE949233704478E4E49B8EE48416AAA29EE2F9F16137F1FD837C
File Size: 4.14 MB, 4135589 bytes
MD5: fc37ad74a5cfb048b576a3f843435d58
SHA1: 368408ef7f03ce4eac0170f7f5317fdbb1cc8941
SHA256: 7C8D210AD56C030F372C589178DFE2A65E3DBC1C1DA90FB5E27B4B093382CE4E
File Size: 2.00 MB, 1998848 bytes
MD5: 5d48f9a5c86659ac76667166fedbc580
SHA1: c6a53c0f90da77945bb7b80df6c2a6e90575357b
SHA256: 4375E5ACA6BA2D17FAF88D69D7D427F1C64F78573BBECDEDA4009ABEA9DB48CC
File Size: 1.95 MB, 1953280 bytes
MD5: a7252ff9631d4b421dcb4f54753b0e52
SHA1: 6bb0517b274f872a663ad0e1e3c180de53dd1ec7
SHA256: 34052939C7D1A674F62932F937299DEF14BD4B3C36EEE4421B9A4E4C370DA64B
File Size: 259.58 KB, 259584 bytes
Show More
MD5: 67993739a77ae750496f910edefed863
SHA1: c7906871f95f0fb7de33aed983ca371ae1ec8561
SHA256: 43BFB45A0017FF4DBF4751688A231517C23E7BA35527177E4F9648B7C6DC5DF3
File Size: 1.86 MB, 1859072 bytes
MD5: 0d263157cc322fb5ab9c3b65c114a258
SHA1: 68cae707ef6a083a9e3a5329765f2fc64a2beb9e
SHA256: 162F16134C3AC80FF3322D2DCE13D8FD4F0476108CB96415927EBEA055ABC241
File Size: 1.95 MB, 1951232 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is .NET application
  • File is 32-bit executable
  • File is 64-bit executable
Show More
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 2.2.0.0
  • 2.1.0.0
  • 1.6.0.5
  • 1.3.4.0
  • 1.0.0.0
Comments
  • PLCore
  • ThinkPad LEDs Control
  • This installation was built with Inno Setup.
Company Name
  • ProgramLab
  • telegramgroupscraper.com
  • ValiNet (Valentin-Gabriel Radu)
File Description
  • FileConverter
  • PLCore
  • telegramgroupscraper.com Setup
  • ThinkPad LEDs Control
  • UnlockPico4
  • XiaoMiFlash
File Version
  • 2.2.0.0
  • 2.1.0.0
  • 1.6.0.5
  • 1.3.4.0
  • 1.0.0.0
Internal Name
  • FileConverter.exe
  • LEDControl.exe
  • PLCore.exe
  • UnlockPico4.exe
  • XiaoMiFlash.exe
Legal Copyright
  • Copyright © 2006-2016 ValiNet (Valentin-Gabriel Radu)
  • Copyright © 2015
  • Copyright © 2023
  • Copyright © 2025
  • Copyright © 2026
  • ProgramLab© 2021
Legal Trademarks
  • ProgramLab© 2021
  • ThinkPad LEDs Control
Original Filename
  • FileConverter.exe
  • LEDControl.exe
  • PLCore.exe
  • UnlockPico4.exe
  • XiaoMiFlash.exe
Product Name
  • FileConverter
  • PLCore
  • telegramgroupscraper.com
  • ThinkPad LEDs Control
  • UnlockPico4
  • XiaoMiFlash
Product Version
  • telegramgroupscraper.com
  • 2.2.0.0
  • 2.1.0.0
  • 1.6.0.5
  • 1.3.4.0
  • 1.0.0.0

File Traits

  • .NET
  • HighEntropy
  • x64
  • x86

Block Information

Total Blocks: 728
Potentially Malicious Blocks: 13
Whitelisted Blocks: 408
Unknown Blocks: 307

Visual Map

0 0 0 0 0 x x ? 0 0 ? 0 ? ? ? ? ? ? ? ? 0 0 ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? 0 0 ? ? ? ? 0 0 ? ? ? ? 0 ? 0 ? 0 0 ? ? 0 0 0 ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? 0 ? x 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? ? x 0 x x x x ? 0 0 ? ? ? 0 0 0 ? 0 ? ? 0 ? ? ? ? ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? ? ? ? ? ? ? 0 ? x x ? 0 ? 0 ? 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? 0 0 0 0 0 ? 0 0 0 ? ? 0 0 0 0 ? ? 0 0 ? 0 0 0 0 ? 0 0 0 ? ? ? ? 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? 0 ? 0 0 ? ? ? ? 0 ? ? 0 0 0 ? ? ? ? 0 ? x x 0 ? ? ? ? ? 0 0 0 ? ? 0 0 0 ? ? ? ? x 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? 0 ? 0 0 0 ? ? ? ? 0 ? ? ? ? ? ? ? 0 ? 0 0 ? ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 ? 0 0 0 ? ? 0 ? 0 ? 0 0 ? ? ? ? ? ? ? 0 0 0 ? 0 0 ? ? ? ? ? ? 0 ? 0 0 0 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 ? ? 0 0 ? ? 0 ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? 0 0 ? ? 0 0 0 0 ? 0 0 0 ? ? ? ? 0 ? ? ? 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? ? ? 0 0 ? 0 0 ? 0 ? 0 0 ? 0 0 0 ? 0 ? 0 0 0 ? 0 0 0 0 0 0 ? 0 ? ? ? ? 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 ? ? ? ? ? ? ? 0 ? ? ? ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\appdata\local\temp\is-gjuc0.tmp\39a32c1be053dda7a8e2bb38d9f4cf601a213d74_0004135589.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\valinet_(valentin-gabriel\6bb0517b274f872a663ad0e1e_url_dyqwrbqr5fas3maicwyqu3cfhwgr0sdx\1.6.0.5\0xfbjhbu.newcfg Generic Write,Read Attributes
c:\users\user\appdata\local\valinet_(valentin-gabriel\6bb0517b274f872a663ad0e1e_url_dyqwrbqr5fas3maicwyqu3cfhwgr0sdx\1.6.0.5\0xfbjhbu.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\valinet_(valentin-gabriel\6bb0517b274f872a663ad0e1e_url_dyqwrbqr5fas3maicwyqu3cfhwgr0sdx\1.6.0.5\user.config Synchronize,Write Data

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
Show More
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Process Shell Execute
  • CreateProcess
Encryption Used
  • BCryptOpenAlgorithmProvider

Shell Command Execution

"C:\Users\Njjsygeg\AppData\Local\Temp\is-GJUC0.tmp\39a32c1be053dda7a8e2bb38d9f4cf601a213d74_0004135589.tmp" /SL5="$30230,3328045,780800,c:\users\user\downloads\39a32c1be053dda7a8e2bb38d9f4cf601a213d74_0004135589"

Related Posts

Trending

Most Viewed

Loading...