Threat Database Trojans Trojan.MSIL.Downloader.DAABI

Trojan.MSIL.Downloader.DAABI

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 226
First Seen: July 11, 2022
Last Seen: November 16, 2025
OS(es) Affected: Windows

The detection of Trojan.MSIL.Downloader.DAABI on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the security of your computer, allowing unauthorized access and control. It is essential to understand the nature of this threat and take prompt action to remove it and prevent further damage.

What Is Trojan.MSIL.Downloader.DAABI?

Trojan.MSIL.Downloader.DAABI is a type of Trojan horse malware that can be used to download and install additional malicious software on your computer. The name suggests that it is written in MSIL (Microsoft Intermediate Language), which is a platform-independent intermediate representation of the .NET Framework. This type of malware can be particularly dangerous, as it can be used to install a wide range of malicious software, including keyloggers, ransomware, and spyware.

How Trojan.MSIL.Downloader.DAABI Operates

Trojan.MSIL.Downloader.DAABI typically operates by exploiting vulnerabilities in your system or tricking you into installing it. Once installed, it can connect to a command and control server to receive instructions and download additional malware. This malware can also be used to steal sensitive information, such as login credentials, credit card numbers, and personal data. It may also be used to disrupt your system's operation, causing crashes, freezes, and other problems.

Symptoms of Infection

The symptoms of a Trojan.MSIL.Downloader.DAABI infection can vary, but common signs include slow system performance, unexpected pop-ups and ads, and unfamiliar programs or icons on your desktop. You may also notice that your browser homepage has been changed or that you are being redirected to unfamiliar websites. In some cases, you may not notice any symptoms at all, which is why regular scans with a reputable antivirus program are essential.

How to Remove Trojan.MSIL.Downloader.DAABI

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow you to download and install removal tools.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and remove any detected threats.
  3. Uninstall any suspicious programs or applications that you do not recognize or that were installed around the time of the infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your computer and run another scan with your anti-malware tool to ensure that the threat has been completely removed.

Conclusion

Removing Trojan.MSIL.Downloader.DAABI from your system requires careful attention to detail and a thorough understanding of the threat. By following the steps outlined above, you can help to ensure that your system is secure and that your personal data is protected. It is also essential to take preventive measures, such as keeping your operating system and software up to date, using strong passwords, and avoiding suspicious downloads and email attachments. By staying vigilant and taking proactive steps to protect your system, you can help to prevent future infections and keep your computer and personal data safe.

Analysis Report

General information

Family Name: Trojan.MSIL.Downloader.DAABI
Signature status: No Signature

Known Samples

MD5: 14af592946666a7759236b825d944149
SHA1: 3684e4de456a7bf331bedb2a39af3abef7dc36a1
SHA256: CF12DD2CA9B87FB0DAAD740BF577C1B2257D1DF0CB23E443A14121548717F839
File Size: 5.54 MB, 5539328 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is .NET application
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 10.0.17763.1
Company Name Microsoft Corporation
File Version 10.0.17763.1
Internal Name Oxdmnmj-OLD-4.exe
Legal Copyright Copyright (c) Microsoft Corporation. All rights reserved.
Original Filename Oxdmnmj-OLD-4.exe
Product Name Microsoft (R) Windows (R) Operating System
Product Version 10.0.17763.1

File Traits

  • .NET
  • HighEntropy
  • SmartAssembly
  • x64

Block Information

Total Blocks: 24
Potentially Malicious Blocks: 2
Whitelisted Blocks: 16
Unknown Blocks: 6

Visual Map

0 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 x ? x 0 ? 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\users\user\appdata\roaming\viperfolder\fiperw.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows nt\currentversion\winlogon::shell explorer.exe,"C:\Users\Uijkftoi\AppData\Roaming\ViperFolder\FiperW.exe", RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelTimer2
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCompareSigningLevels
Show More
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtGetCachedSigningLevel
  • ntdll.dll!NtGetContextThread
  • ntdll.dll!NtGetWriteWatch
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtPowerInformation
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResetWriteWatch
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtSuspendThread
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtUnsubscribeWnfStateChange
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtYieldExecution
  • UNKNOWN
User Data Access
  • GetComputerName
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserName
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Other Suspicious
  • AdjustTokenPrivileges
Anti Debug
  • CheckRemoteDebuggerPresent
  • IsDebuggerPresent
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • VirtualAllocEx
Process Shell Execute
  • CreateProcess

Shell Command Execution

C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe

Trending

Most Viewed

Loading...