Threat Database Trojans Trojan.MSIL.Downloader.CP

Trojan.MSIL.Downloader.CP

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 3,679
Threat Level: 80 % (High)
Infected Computers: 300
First Seen: November 14, 2021
Last Seen: July 18, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Downloader.CP indicates that a potentially malicious program has been identified on your system. This detection name suggests that the threat is related to a Trojan-type malware, which is designed to allow unauthorized access to a computer system. Trojans can be used to download and install additional malware, steal sensitive information, or provide remote access to the infected system. It is essential to take immediate action to remove the threat and prevent further damage.

What Is Trojan.MSIL.Downloader.CP?

Trojan.MSIL.Downloader.CP is a type of malware that is likely designed to download and install additional malicious programs on an infected system. The name "Trojan" refers to the fact that this type of malware disguises itself as a legitimate program, allowing it to evade detection and gain access to the system. The "MSIL" part of the name suggests that the malware is written in Microsoft Intermediate Language, which is a programming language used by the .NET Framework. The "Downloader" part of the name indicates that the malware is capable of downloading additional files or programs from the internet.

How Trojan.MSIL.Downloader.CP Operates

Trojan.MSIL.Downloader.CP operates by exploiting vulnerabilities in the system or by tricking the user into installing it. Once installed, the malware can connect to a remote server to download and install additional malicious programs. This can include other types of malware, such as viruses, spyware, or ransomware. The malware can also be used to steal sensitive information, such as login credentials, credit card numbers, or personal data. In some cases, the malware can provide remote access to the infected system, allowing the attacker to control the system and use it for malicious purposes.

Symptoms of Infection

The symptoms of a Trojan.MSIL.Downloader.CP infection can vary, but common signs include slow system performance, unexpected pop-ups or ads, and unusual network activity. The system may also become unstable, crashing or freezing frequently. In some cases, the malware can cause the system to become unresponsive or prevent certain programs from running. If you suspect that your system is infected with Trojan.MSIL.Downloader.CP, it is essential to take immediate action to remove the threat.

How to Remove Trojan.MSIL.Downloader.CP

  1. Restart your system in Safe Mode with Networking to prevent the malware from loading and to allow for easier removal.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malicious files or programs.
  3. Uninstall any suspicious programs or applications that may be related to the malware.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform another scan with the anti-malware tool to ensure that the threat has been completely removed.

Conclusion

In conclusion, the detection of Trojan.MSIL.Downloader.CP is a serious issue that requires immediate attention. By understanding how the malware operates and taking the necessary steps to remove it, you can help protect your system and prevent further damage. It is essential to use reputable anti-malware tools and to follow safe computing practices to prevent future infections. Remember to always be cautious when downloading and installing programs, and never click on suspicious links or attachments. By taking these precautions, you can help keep your system safe and secure.

Analysis Report

General information

Family Name: Trojan.MSIL.Downloader.CP
Signature status: No Signature

Known Samples

MD5: ab0d897691783d07a513aa22eaac6aa8
SHA1: aea4b86f53a770515abddc917f242e1a967ac1ea
SHA256: 853131634A63D68198F11C8DB916DA91CFE9DF20455F3A0B99205BFE5160E089
File Size: 16.38 KB, 16384 bytes
MD5: 4dad677750f341f5eef92d98b681b561
SHA1: 757b67ae0d9b3f538b4adbaef0912243993f8bb1
SHA256: 0C22770397CA39B5969D8BE7EAAA7A4B19478D9669BBA9E49CF76CBE3A7128AC
File Size: 15.87 KB, 15872 bytes
MD5: 887e398f130b56fa43fc64530ba2a190
SHA1: db8903d4ab12e9919dc2bd5e81201eb6befc8203
SHA256: 73D369DCDDBEDAED4A3ADE171BF4F3186B07401B17ADCD77A8C9E0555F8B6ACD
File Size: 105.98 KB, 105984 bytes
MD5: 466975d605b519162d3017322cbfbc5e
SHA1: 028eb124eaa17c4080f7020b54201777add739b4
SHA256: 0BF556D79DA232785B01BC921A0CC3D44B96C1E9A95110B7E13013CD77E10DE5
File Size: 53.25 KB, 53248 bytes
MD5: c39896d4c064c1c7a77bc13321250942
SHA1: bd567ed77de26330955609fe3d889d8f5b1cf4ab
SHA256: 28A6EB57B0459AE0C2E5364926B2FFAF474584FD27B4D780A67817F87539E647
File Size: 20.99 KB, 20992 bytes
Show More
MD5: cac292d4531151a77b75b9c26735f3ae
SHA1: bd08e1ef20e633fa39b820221ae115026ad2d4cf
SHA256: 37A5EC4AF3B8E532D00246EC6BAD6DF659EFC3602C1B5EDED3F16910B292E04C
File Size: 27.07 KB, 27072 bytes
MD5: 0438d40148cf6a66358d1f3243a71d8c
SHA1: 9be9516eb87c95154352b2d3855d57ea61899fd4
SHA256: 7B493CC4EDF15E00C6F176338086D2CD327126818FE36C41E1E19E37D7CE27A7
File Size: 18.43 KB, 18432 bytes
MD5: 431214364badea653fdec4fdb02cc9f3
SHA1: 9cf32db78c5124c13799df8fcb84eeed0ab74d07
SHA256: B8424291529A7B7D6A74DEBDC8DB839981BF4BE4254ED76BCDCCB509FF450DF8
File Size: 16.90 KB, 16896 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
Company Name
  • F. Hoffmann La Roche Ltd
  • HP
  • Microsoft
File Description
  • cleansync
  • email_3
  • IKEYKioskforKeystroke
  • NAVCFG
  • VCTX750Draw
  • WindowsApplication1
File Version 1.0.0.0
Internal Name
  • CleanSync.exe
  • dasn10.exe
  • Del.exe
  • DLLCFG.exe
  • email_3.exe
  • IKEYKioskforKeystroke.exe
  • RunCommand.exe
  • VCTX750Draw.exe
Legal Copyright
  • Copyright © 2010
  • Copyright © 2014
  • Copyright © 2019
  • Copyright © 2023
  • Copyright © F. Hoffmann La Roche Ltd 2013
  • Copyright © HP 2013
  • Copyright © Microsoft 2011
  • Copyright © Microsoft 2015
Original Filename
  • CleanSync.exe
  • dasn10.exe
  • Del.exe
  • DLLCFG.exe
  • email_3.exe
  • IKEYKioskforKeystroke.exe
  • RunCommand.exe
  • VCTX750Draw.exe
Product Name
  • cleansync
  • email_3
  • IKEYKioskforKeystroke
  • NAVCFG
  • VCTX750Draw
  • WindowsApplication1
Product Version 1.0.0.0

Digital Signatures

Signer Root Status
BlackBox2\Admin BlackBox2\Admin Self Signed

File Traits

  • .NET
  • .sdata
  • x86

Block Information

Total Blocks: 22
Potentially Malicious Blocks: 1
Whitelisted Blocks: 19
Unknown Blocks: 2

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x ? ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Banload.AG
  • MSIL.Agent.FQ
  • MSIL.Agent.XGA
  • MSIL.BadJoke.XF
  • MSIL.BadJoke.XI
Show More
  • MSIL.BadJoke.XJ
  • MSIL.Downloader.CP
  • MSIL.Downloader.CPB
  • MSIL.Downloader.XL
  • MSIL.Dropper.CS
  • MSIL.Dropper.X
  • MSIL.Flooder.X
  • MSIL.HackAgent.TH
  • MSIL.PSW.Agent.GB
  • MSIL.PSW.Agent.XB
  • MSIL.Spy.Agent.XG

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.0.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.1.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\usrclass.dat{dba6b5ef-640a-11ed-9bcb-f677369d361c}.txr.2.regtrans-ms Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\appcompat\programs\amcache.hve Read Data,Read Control,Write Data
c:\windows\appcompat\programs\amcache.hve Write Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �j�8��81��B �6 �v y� �Z xy �� �a ۀT�B������1�����5����eeBx�<�����R �7 �!wz"M)"Wc#�#��$kF$��%"�%:�%�&� &�x'�(�(X�)�`*J*9*�^+�[+��,=�,��/9�/��1`1� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 k8��81��B�8 �6 �v y� �Z xy �� �a ۀT�B������1�����5����eeBx�<�����R �7 �!wz"M)"Wc#�#��$kF$��%"�%:�%�&� &�-&�x'�(�(X�)�`*J*9*�^+�[+��,=�,��/9�/�� RegNtPreCreateKey
HKLM\system\software\microsoft\tip\aggregateresults::data 隞̃耀꧌ШŊ RegNtPreCreateKey
HKLM\system\software\microsoft\tip\aggregateresults::data 隞̃쨁耀꧌ф RegNtPreCreateKey
HKCU\software\microsoft\ctf\msutb::left RegNtPreCreateKey
HKCU\software\microsoft\ctf\msutb::top RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �m|v8��8tXz�jg�B�8 �� �6 �v z �Z xy �� �a��T�B�����������5���� +Bx�<��5�R �!wz"Wc#�#��$kF$��%:�%`�%�&� &�-(�(X�)E)�`*J*9*�"+�[,=�,��-!R/9�/�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 .m�8�1�jg �� �6 �v xy ����T������1��dc�%������3bBx���R �7#�#��$kF%`�&� &�-'�(�(X�(�)A)�`*J*9*�"+��,��-!R0P%1`1�1HO1�D5,]9ߔ=�@V�A��B��F?G�IH[uH�� RegNtPreCreateKey

Windows API Usage

Category API
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAdjustPrivilegesToken
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
Show More
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateKey
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeleteValueKey
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtFsControlFile
  • ntdll.dll!NtLoadKeyEx
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenSymbolicLinkObject
  • ntdll.dll!NtOpenThread
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySymbolicLinkObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReadVirtualMemory
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
Process Shell Execute
  • CreateProcess
Encryption Used
  • BCryptOpenAlgorithmProvider

Shell Command Execution

C:\Windows\Microsoft.NET\Framework64\v2.0.50727\\dw20.exe dw20.exe -x -s 800
C:\Windows\Microsoft.NET\Framework64\v2.0.50727\\dw20.exe dw20.exe -x -s 876

Related Posts

Trending

Most Viewed

Loading...