Threat Database Trojans Trojan.MSIL.Perseus.I

Trojan.MSIL.Perseus.I

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 68
First Seen: September 8, 2021
Last Seen: January 5, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Perseus.I on your system indicates a potential security threat that requires immediate attention. This report aims to provide you with an understanding of the nature of this threat, its operational methods, symptoms of infection, and most importantly, steps to remove it from your computer.

What Is Trojan.MSIL.Perseus.I?

Trojan.MSIL.Perseus.I is identified as a Trojan-type threat, which is a broad category of malware designed to allow unauthorized access to a computer system. Trojans can be used for a variety of malicious purposes, including data theft, espionage, and the distribution of additional malware. The name Trojan.MSIL.Perseus.I itself does not directly indicate a specific malware family but suggests it is written in MSIL (Microsoft Intermediate Language), which is a platform-agnostic intermediate representation of the .NET Framework.

How Trojan.MSIL.Perseus.I Operates

Trojan.MSIL.Perseus.I, like other Trojans, operates by disguising itself as a legitimate program or file to deceive users into installing it on their systems. Once installed, it can open a backdoor for remote access, allowing attackers to execute commands, steal sensitive information, or install additional malware. The specifics of how Trojan.MSIL.Perseus.I operates can vary, but its primary goal is to compromise the security and integrity of the infected system.

Symptoms of Infection

Symptoms of a Trojan.MSIL.Perseus.I infection can be subtle and may include unusual system behavior, such as unexpected pop-ups, slow system performance, or programs launching without user input. In some cases, there may be no noticeable symptoms at all, making regular system scans crucial for detection. If you suspect your system is infected, it's essential to take immediate action to mitigate potential damage.

How to Remove Trojan.MSIL.Perseus.I

  1. Boot into Safe Mode with Networking: This will help prevent the malware from loading and give you a cleaner environment to work in.
  2. Conduct a Full Scan with a Reputable Tool: Use a trusted anti-malware tool, such as SpyHunter, to scan your system for the Trojan.MSIL.Perseus.I and other potential threats. Ensure your antivirus and anti-malware software is updated before scanning.
  3. Uninstall Suspicious Programs: Review your installed programs and remove any that you do not recognize or that were installed around the time of the suspected infection.
  4. Reset Your Browsers: Resetting browsers like Chrome, Firefox, and Edge can help remove any malicious extensions or settings changes made by the malware.
  5. Reboot and Re-scan: After removal, reboot your system and run another full scan to ensure that all components of the malware have been successfully removed.

Conclusion

The removal of Trojan.MSIL.Perseus.I requires careful and immediate action to prevent further damage to your system and potential data theft. By understanding the nature of this threat and following the steps outlined above, you can effectively remove the malware and protect your system from similar threats in the future. Regular system scans, keeping your software updated, and practicing safe browsing habits are key to maintaining a secure computing environment.

Analysis Report

General information

Family Name: Trojan.MSIL.Perseus.I
Signature status: No Signature

Known Samples

MD5: 290d85892398549368c571d132913b7e
SHA1: 75cd702852534e347120dc3a817d0376e86b9b15
SHA256: 9AD9736DFCFFA12A595125DA5A2593784366B65E0C9F2972DBFBC309651C790E
File Size: 1.57 MB, 1574400 bytes
MD5: 4600485887a90d72a7dbcb8a22169c78
SHA1: a1d704977001bcbc40c992fe95fcfa9ba68d93cd
SHA256: 5D5B14E12AFBCF84B43197A45C86AE0A759A35ADA9625A19FD043405C15A4448
File Size: 1.57 MB, 1571840 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version
  • 2.2.5.0
  • 1.7.4.0
File Version
  • 2.2.5
  • 1.7.4
Internal Name Client.exe
Original Filename Client.exe
Product Version
  • 2.2.5
  • 1.7.4

File Traits

  • .NET
  • dll
  • x86

Block Information

Total Blocks: 892
Potentially Malicious Blocks: 283
Whitelisted Blocks: 232
Unknown Blocks: 377

Visual Map

x x ? x x x ? ? 0 ? ? 0 0 ? ? ? ? ? ? 0 ? x x 0 0 ? ? x ? ? 0 ? ? x ? ? 0 ? 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 0 0 0 0 x 0 x 0 x ? ? x x x ? ? ? 0 ? ? ? x ? ? ? ? ? ? ? 0 ? ? ? ? ? x x x 0 x 0 0 0 0 0 ? ? 0 0 0 x ? x ? x ? x x x ? ? ? ? ? ? ? ? ? ? ? ? x 0 x x x x 0 x x x 0 x x ? 0 x ? 0 ? 0 x x ? ? ? ? ? ? ? ? 0 ? ? ? ? x 0 ? ? x 0 x x x x x x x x x x x x x x 0 0 x x x x x x x 0 0 0 0 0 ? x x x x x ? x x 0 x x x x x x x x x x ? ? ? ? x 0 x ? ? ? x x x 0 x ? 0 0 0 0 0 0 0 x 0 0 0 0 ? ? ? ? ? ? ? ? x ? ? ? 0 0 0 0 ? 0 0 x ? ? ? ? ? 0 0 x ? ? ? ? 0 ? 0 x ? ? ? ? 0 ? ? 0 0 x x x 0 0 x x ? ? 0 ? ? 0 ? ? x x x x ? x x x x ? ? x x x 0 x 0 x 0 0 0 x ? ? ? ? ? ? ? 0 0 x x ? x ? ? ? 0 ? 0 x ? 0 0 0 x 0 0 x x 0 0 ? 0 0 0 0 x ? 0 0 0 0 ? ? 0 x ? ? ? ? ? x x x x x x x x x x 0 ? ? ? ? ? 0 ? 0 0 x ? x x x ? x ? ? ? ? ? 0 ? x x x ? ? ? 0 ? ? 0 0 0 ? 0 0 x ? 0 x 0 0 x 0 0 0 x x ? ? ? ? ? 0 ? 0 ? 0 0 0 0 x 0 x x 0 0 x 0 x x x x 0 x 0 0 ? x x 0 x ? ? ? ? ? ? x ? ? 0 x ? ? 0 x x x x 0 0 ? 0 0 x 0 x ? ? ? ? 0 0 x 0 0 ? ? x x ? 0 ? 0 0 0 0 x x x x x x x x ? ? ? x 0 0 0 0 x x x x ? ? x x 0 x x x x x x x x 0 x x ? x x 0 x x x ? x 0 x x x x x x x x x x 0 x x ? ? ? ? x 0 0 0 x 0 x 0 ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? x x ? ? x ? ? x ? ? ? 0 ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? 0 ? 0 0 ? ? ? ? x ? 0 0 ? ? ? ? ? ? ? ? 0 ? 0 ? 0 0 x ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 x 0 ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 ? ? 0 0 x ? ? ? ? ? ? ? ? ? 0 x 0 0 ? 0 ? 0 ? ? ? ? ? ? ? 0 0 0 ? 0 0 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? ? ? ? x ? ? x 0 x 0 x x 0 x x x x 0 x x x x x 0 x x 0 0 0 x 0 0 0 0 x 0 0 x ? x ? ? ? ? ? ? ? ? ? ? ? 0 x x x x ? ? x ? x ? ? ? ? ? x x x x x ? x ? ? x 0 ? x x x x x ? x x x ? ? x x x ? 0 ? ? x x x x 0 0 x x 0 0 ? x x 0 x x 0 x x x x x ? ? ? ? x ? x x x x 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelTimer2
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
Show More
  • ntdll.dll!NtCompareSigningLevels
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtGetCachedSigningLevel
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtUnsubscribeWnfStateChange
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Other Suspicious
  • AdjustTokenPrivileges
Anti Debug
  • IsDebuggerPresent
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext

Related Posts

Trending

Most Viewed

Loading...