Threat Database Backdoors Backdoor.MSIL.DllInject.TN

Backdoor.MSIL.DllInject.TN

By CagedTech in Backdoors

Threat Scorecard

Threat Level: 60 % (Medium)
Infected Computers: 13
First Seen: April 21, 2023
Last Seen: November 7, 2025
OS(es) Affected: Windows

The detection of Backdoor.MSIL.DllInject.TN indicates that a potentially malicious program has been identified on your system. This detection name suggests a backdoor threat, which is a type of malware that allows unauthorized access to a computer system. Backdoors can be used by attackers to remotely control a system, steal sensitive information, or install additional malware.

What Is Backdoor.MSIL.DllInject.TN?

Backdoor.MSIL.DllInject.TN is a detected threat that implies a malicious program has infiltrated your system, potentially allowing unauthorized access. The term "backdoor" refers to a method by which an attacker can bypass normal security measures to access a system. "MSIL" stands for Microsoft Intermediate Language, which is a component of the .NET Framework, suggesting that this threat may be related to .NET-based applications. "DllInject" implies that the malware may be injecting malicious code into legitimate dynamic link libraries (DLLs) to evade detection.

How Backdoor.MSIL.DllInject.TN Operates

Backdoor threats like Backdoor.MSIL.DllInject.TN typically operate by creating a covert communication channel between the infected system and a command and control (C2) server controlled by the attacker. This allows the attacker to issue commands, steal data, or install additional malware without being detected by traditional security software. The specific operation mechanisms can vary, but the primary goal is to maintain unauthorized access to the compromised system.

Symptoms of Infection

Symptoms of a backdoor infection can be subtle and may not always be immediately apparent. However, signs of infection can include unusual network activity, slow system performance, unexpected changes to system settings, or the appearance of unfamiliar programs or files. In some cases, the system may become unstable, or certain applications may malfunction. It's also possible that the infection may not exhibit any noticeable symptoms, making it difficult to detect without proper security tools.

How to Remove Backdoor.MSIL.DllInject.TN

  1. Boot your system into Safe Mode with Networking to prevent the malware from loading and to allow for internet access to download removal tools.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all components of the malware.
  3. Uninstall any suspicious programs that were installed around the time of the infection. Be cautious and only remove programs that you are certain are malicious or unnecessary.
  4. Reset your web browsers (Chrome, Firefox, Edge) to their default settings to remove any malicious extensions or settings that the malware may have altered.
  5. Reboot your system and perform another full scan with your anti-malware tool to ensure that all malware components have been removed and that your system is clean.

Conclusion

The removal of Backdoor.MSIL.DllInject.TN requires careful steps to ensure that all components of the malware are eliminated from your system. It's crucial to use reputable security tools and follow best practices for malware removal to prevent further infection. After removal, maintaining good security practices, such as keeping your operating system and software up to date, using strong antivirus software, and being cautious with email attachments and downloads, can help protect your system from future threats. Regular system backups and monitoring for suspicious activity can also help in early detection and mitigation of malware infections.

Analysis Report

General information

Family Name: Backdoor.MSIL.DllInject.TN
Signature status: No Signature

Known Samples

MD5: fe2502ac01d4f3e02ab95af057f6ca8e
SHA1: 87e23f8e663c3edd45a295a3f3b4fd11681f27cc
SHA256: D1464240C4FFA4389E2186A9FEC78364AFA657E52D1E12FAD7B74A2447E54CEF
File Size: 1.19 MB, 1194496 bytes
MD5: 83b0f01c46dd4cfe3b463a7d6f1b4e9d
SHA1: 1234a085f56519650359454248f5898979cd1c9d
SHA256: 7C32EF3A95B426FEE5091E8174C0449B4B1DA95D305540A21112EAC88E30104C
File Size: 1.17 MB, 1174528 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is .NET application
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
File Description
  • BKL SENSI BRUTAL
  • modelo - free
File Version 1.0.0.0
Internal Name
  • AnyDesk.exe
  • BKL SENSI BRUTAL.exe
Legal Copyright
  • Copyright © 2024
  • Copyright © 2025
Original Filename
  • AnyDesk.exe
  • BKL SENSI BRUTAL.exe
Product Name
  • BKL SENSI BRUTAL
  • modelo - free
Product Version 1.0.0.0

File Traits

  • .NET
  • Agile.net
  • CreateThread
  • Fody
  • HighEntropy
  • VirtualQueryEx
  • WriteProcessMemory
  • x64

Block Information

Total Blocks: 141
Potentially Malicious Blocks: 32
Whitelisted Blocks: 59
Unknown Blocks: 50

Visual Map

? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? x ? 0 ? x 0 0 0 x x x x x x x x x x x x x x x x x x 0 0 x 0 0 x 0 0 x x x x x x x x x x 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\tracing\rasapi32::enablefiletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::enableautofiletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::enableconsoletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::maxfilesize  RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasapi32::filedirectory %windir%\tracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::enablefiletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::enableautofiletracing RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::enableconsoletracing RegNtPreCreateKey
Show More
HKLM\software\microsoft\tracing\rasmancs::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::maxfilesize  RegNtPreCreateKey
HKLM\software\microsoft\tracing\rasmancs::filedirectory %windir%\tracing RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcCreatePortSection
  • ntdll.dll!NtAlpcCreateSectionView
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClearEvent
Show More
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtGetCompleteWnfStateSubscription
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryEvent
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtQueueApcThread
  • ntdll.dll!NtQueueApcThreadEx2
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSetValueKey
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtUnsubscribeWnfStateChange
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtYieldExecution
  • UNKNOWN
User Data Access
  • GetComputerName
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Other Suspicious
  • AdjustTokenPrivileges
Network Winsock2
  • WSAConnect
  • WSASocket
  • WSAStartup
  • WSAttemptAutodialName
Network Winsock
  • closesocket
  • freeaddrinfo
  • getaddrinfo
  • recv
  • send
  • setsockopt
Network Winhttp
  • WinHttpOpen
Network Info Queried
  • GetAdaptersAddresses
  • GetNetworkParams

Related Posts

Trending

Most Viewed

Loading...