Threat Database Backdoors Backdoor.MSIL.DiscordStealer.P

Backdoor.MSIL.DiscordStealer.P

By CagedTech in Backdoors, Stealers

Threat Scorecard

Threat Level: 60 % (Medium)
Infected Computers: 44
First Seen: March 18, 2022
Last Seen: July 20, 2026
OS(es) Affected: Windows

The detection of Backdoor.MSIL.DiscordStealer.P indicates that your system has been compromised by a potentially malicious threat. This backdoor threat is designed to allow unauthorized access to your system, which can lead to a range of serious consequences, including data theft and further malware infections. It is essential to take immediate action to remove this threat and prevent any potential damage.

What Is Backdoor.MSIL.DiscordStealer.P?

Backdoor.MSIL.DiscordStealer.P is a type of backdoor malware that is designed to provide unauthorized access to a compromised system. The name suggests that it may be related to Discord, a popular online communication platform, and may be used to steal sensitive information such as login credentials or other personal data. However, without further information, it is difficult to determine the exact nature and purpose of this threat.

How Backdoor.MSIL.DiscordStealer.P Operates

Backdoor malware like Backdoor.MSIL.DiscordStealer.P typically operates by creating a covert channel of communication between the compromised system and a command and control (C2) server. This allows the attackers to remotely access and control the system, steal sensitive information, and install additional malware. The malware may also use various techniques to evade detection, such as encrypting its communication or using legitimate system processes to hide its activities.

Symptoms of Infection

The symptoms of a Backdoor.MSIL.DiscordStealer.P infection can be subtle and may not be immediately apparent. However, some common signs of a backdoor infection include unusual system behavior, such as slow performance, unexpected crashes, or unfamiliar programs running in the background. You may also notice that your system is connecting to unfamiliar servers or transmitting data to unknown locations. If you suspect that your system has been infected, it is essential to take immediate action to remove the threat.

How to Remove Backdoor.MSIL.DiscordStealer.P

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow you to download and install removal tools.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect and remove any malware infections.
  3. Uninstall any suspicious programs or applications that may be related to the malware infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform another full scan with your anti-malware tool to ensure that the threat has been completely removed.

Conclusion

Removing Backdoor.MSIL.DiscordStealer.P requires careful attention to detail and a thorough understanding of the malware removal process. By following the steps outlined above and using reputable anti-malware tools, you can help to ensure that your system is completely clean and free from infection. It is also essential to take steps to prevent future infections, such as keeping your operating system and software up to date, using strong passwords, and avoiding suspicious downloads and links. By staying vigilant and taking proactive measures, you can help to protect your system and your personal data from the risks associated with backdoor malware like Backdoor.MSIL.DiscordStealer.P.

Analysis Report

General information

Family Name: Backdoor.MSIL.DiscordStealer.P
Signature status: No Signature

Known Samples

MD5: 02b6b672924584792d9969f116b1a26e
SHA1: d748e18b1fd427afb872b2ed1148ab097809775e
SHA256: 850E3D18450E772E7786FCB9AC19D5B26DFF5ACCC953EA126981AFE67347255E
File Size: 544.26 KB, 544256 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
Company Name Microsoft
File Description WhereIsMyVersion
File Version 1.0.0.0
Internal Name PromobVersion.exe
Legal Copyright Copyright © Microsoft 2014
Original Filename PromobVersion.exe
Product Name WhereIsMyVersion
Product Version 1.0.0.0

File Traits

  • .NET
  • .sdata
  • Reactor
  • RijndaelManaged
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 416
Potentially Malicious Blocks: 77
Whitelisted Blocks: 326
Unknown Blocks: 13

Visual Map

0 ? 0 ? 0 ? ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 x ? 0 0 0 0 x x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 x 0 x 0 0 x 0 0 x ? x x 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 x x 0 0 x 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 x 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 x 0 x 0 x 0 x x x 0 0 0 x 0 0 x 0 0 x 0 0 0 x 0 x 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x 0 0 x x x x x 0 0 x x x x x x x x x x x 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 x 0 ? x 0 ? 0 0 x x x 0 0 x x 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.DiscordStealer.AO
  • MSIL.DiscordStealer.AU
  • MSIL.DiscordStealer.MA
  • MSIL.DiscordStealer.P

Files Modified

File Attributes
c:\programdata\isolated storage\{53007400-3600-7500-6d00-680038004b00} Generic Read,Write Data,Write Attributes,Write extended,Append data

Registry Modifications

Key::Value Data API Name
HKCU\cid\{53007400-3600-7500-6d00-680038004b00}::1 pIuOQdvqdTsoH0VT8kLYvWbMi8x18bXf5pkKP0HHirAt4KnEppDZVYbEH69IgiVKZ/sXPJ5o56KAEbgZ0514hC3BgS93gt2Haj0iiARQDbIcZCSNjGgb5EdfASHVHufK RegNtPreCreateKey

Windows API Usage

Category API
User Data Access
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
Network Info Queried
  • GetAdaptersInfo
Other Suspicious
  • AdjustTokenPrivileges
Process Terminate
  • TerminateProcess

Related Posts

Trending

Most Viewed

Loading...