Threat Database Stealers Trojan.MSIL.Stealer.ATB

Trojan.MSIL.Stealer.ATB

By CagedTech in Stealers, Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 39
First Seen: July 1, 2023
Last Seen: September 10, 2025
OS(es) Affected: Windows

The detection of Trojan.MSIL.Stealer.ATB indicates that your system has been compromised by a malicious threat. This type of malware is designed to steal sensitive information from infected computers, posing a significant risk to your personal data and online security. It is essential to take immediate action to remove the threat and prevent further damage.

What Is Trojan.MSIL.Stealer.ATB?

Trojan.MSIL.Stealer.ATB is a type of Trojan horse malware, which is a malicious program that disguises itself as legitimate software. The name "Trojan.MSIL.Stealer.ATB" suggests that it is a stealer-type Trojan, designed to steal sensitive information such as login credentials, credit card numbers, and other personal data. The "MSIL" part of the name may indicate that the malware is written in Microsoft Intermediate Language, which is a programming language used by the .NET framework.

How Trojan.MSIL.Stealer.ATB Operates

Trojan.MSIL.Stealer.ATB operates by infiltrating a victim's computer system, often through exploited vulnerabilities or social engineering tactics. Once inside, the malware can spread to other parts of the system, gathering sensitive information and transmitting it to its command and control servers. The malware may also install additional malicious components, such as keyloggers or screen scrapers, to gather more information. The ultimate goal of the malware is to profit from the stolen data, either by selling it on the black market or using it for malicious activities such as identity theft or financial fraud.

Symptoms of Infection

Systems infected with Trojan.MSIL.Stealer.ATB may exhibit a range of symptoms, including unusual system behavior, slow performance, and unexpected pop-ups or alerts. You may also notice that your browser is redirecting to unfamiliar websites or that your search results are being hijacked. In some cases, the malware may cause system crashes or freezes, or even lead to the loss of sensitive data. If you suspect that your system has been infected, it is crucial to take immediate action to remove the threat and prevent further damage.

How to Remove Trojan.MSIL.Stealer.ATB

  1. Restart your computer in Safe Mode with Networking to prevent the malware from loading and to allow for a more effective removal process.
  2. Download and install a reputable anti-malware tool, such as SpyHunter, and perform a full scan of your system to detect and remove the malware.
  3. Uninstall any suspicious programs or applications that may be related to the malware, and remove any associated files or folders.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform another full scan with your anti-malware tool to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.MSIL.Stealer.ATB from your system requires a combination of technical expertise and caution. By following the steps outlined above, you can help to ensure that the malware is completely removed and that your system is secure. However, prevention is always the best approach, and taking steps to protect your system from malware in the first place, such as keeping your operating system and software up to date, using strong antivirus software, and being cautious when clicking on links or downloading attachments, can help to prevent infections like Trojan.MSIL.Stealer.ATB in the future.

Analysis Report

General information

Family Name: Trojan.MSIL.Stealer.ATB
Signature status: Hash Mismatch

Known Samples

MD5: f677bd0387b9b0d89e51d5550a4e7f83
SHA1: 89cab49cf3b51dc99018e5e246e6c59eb3ebfd39
SHA256: 12069B224AA746E30E52E85D308DD119C14FB8D7C44933682CCAF83AA187E410
File Size: 3.66 MB, 3655232 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File is .NET application
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 2023.9.248.0
Comments Cloudflare WARP
Company Name Cloudflare
File Description Cloudflare WARP
File Version 2023.9.248.0
Internal Name Poanbs.exe
Legal Copyright (c) 2021, Cloudflare Inc.
Original Filename Poanbs.exe
Product Name Cloudflare WARP
Product Version 2023.9.248.0

Digital Signatures

Signer Root Status
Cloudflare, Inc. DigiCert Trusted Root G4 Hash Mismatch

File Traits

  • .NET
  • HighEntropy
  • x64

Block Information

Total Blocks: 3,152
Potentially Malicious Blocks: 298
Whitelisted Blocks: 1,055
Unknown Blocks: 1,799

Visual Map

? ? ? ? ? ? x 0 0 0 0 0 0 0 0 0 0 0 x x ? x x ? 0 0 0 ? ? ? 0 ? 0 ? 0 ? ? 0 ? ? 0 ? ? 0 ? ? 0 ? ? 0 ? ? 0 ? ? 0 ? ? 0 ? ? 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 x ? ? ? ? ? 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 ? ? x 0 0 0 0 0 0 0 0 0 ? 0 0 ? ? 0 0 0 ? 0 ? 0 0 ? ? 0 0 ? ? 0 x 0 ? ? 0 0 0 0 0 ? ? 0 ? ? x 0 0 ? 0 x 0 0 ? ? ? ? 0 ? x 0 0 0 0 x 0 0 ? 0 0 0 0 0 0 ? ? ? x ? ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 ? ? ? 0 ? x ? ? x 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x 0 ? ? ? ? ? x ? 0 ? ? ? ? ? ? ? ? 0 0 0 ? 0 0 ? 0 0 0 ? 0 0 ? ? 0 ? ? ? x 0 0 ? ? ? ? ? ? ? ? ? ? ? 0 x 0 0 0 ? 0 ? 0 0 0 0 x 0 x 0 ? 0 ? ? ? ? ? x 0 ? 0 0 0 0 ? ? ? x x ? x ? ? 0 0 ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x ? 0 0 ? x 0 0 ? 0 x 0 ? 0 0 ? 0 ? 0 0 0 0 x 0 0 ? 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? x ? ? ? ? x ? x ? x ? x ? x ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? x ? ? 0 0 0 ? ? ? 0 ? ? ? ? 0 0 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x 0 ? ? 0 ? ? ? ? ? ? ? 0 ? 0 ? 0 ? ? ? 0 x ? x 0 x ? x ? x x ? ? ? ? x 0 x 0 x 0 ? ? ? ? 0 0 x ? ? x ? x ? ? x ? ? x ? ? ? ? x x ? 0 x ? x x ? ? ? ? 0 ? ? x ? ? ? ? ? x ? x 0 x ? ? 0 ? ? 0 ? x ? x ? ? x ? ? x ? 0 ? x ? ? ? x ? x ? ? x ? x ? x x ? ? x ? ? ? ? x ? ? x ? ? ? ? x ? ? ? ? ? ? ? ? 0 ? 0 0 ? ? ? ? ? ? ? ? ? ? x x 0 ? ? ? ? ? ? x ? ? ? x ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? x ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? x 0 ? ? ? 0 x 0 ? ? ? ? x x ? x x ? ? x x ? ? x x ? x x x x ? ? x ? ? x ? ? ? ? ? ? x ? x ? ? x ? ? ? ? ? ? ? ? x 0 0 ? ? ? ? ? ? ? ? ? 0 x 0 ? ? ? x ? 0 0 ? 0 ? x 0 0 0 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? 0 x 0 0 x x x 0 0 0 0 0 0 x 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? 0 ? 0 x ? x ? ? ? ? ? ? 0 0 0 x 0 x x ? 0 ? 0 ? x ? x 0 ? ? ? ? ? ? ? 0 ? 0 ? x ? ? 0 0 0 0 0 ? x ? 0 0 0 0 0 0 0 0 ? ? ? ? ? ? 0 ? 0 ? x 0 0 ? x ? ? ? ? ? 0 ? ? ? ? ? ? ? 0 0 ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 x 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? 0 0 ? 0 0 ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? x ? ? ? ? ? ? 0 ? ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? ? ? ? x ? ? 0 0 ? ? 0 ? ? ? ? ? ? 0 ? 0 0 0 0 0 ? x 0 ? 0 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 ? ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 ? x ? ? ? ? ? ? ? ? 0 0 ? ? 0 0 0 0 0 x 0 ? 0 0 ? ? ? ? 0 ? ? ? ? ? ? ? x ? ? 0 ? 0 ? ? ? ? ? ? x ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? 0 0 x ? ? ? ? ? 0 0 0 ? 0 ? ? ? 0 0 0 0 ? ? 0 ? 0 ? ? ? ? ? ? 0 ? ? ? ? 0 ? 0 ? x x ? x ? ? x 0 0 0 0 0 0 0 ? x ? ? ? ? x x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? x 0 x ? ? 0 0 ? 0 x ? x ? ? ? 0 0 x ? ? ? 0 ? ? 0 ? ? ? ? ? ? 0 0 0 0 ? ? 0 0 0 ? ? ? 0 0 0 0 ? ? ? ? ? ? 0 0 0 0 ? 0 0 ? ? ? ? 0 0 0 ? ? ? ? 0 ? ? 0 ? x 0 0 0 0 ? 0 0 0 0 x 0 ? ? ? 0 ? x 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? x 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x ? ? x ? ? ? ? ? ? ? ? 0 0 ? ? ? x x 0 0 0 ? ? ? x x x 0 ? ? ? 0 0 0 ? x ? x 0 ? x 0 0 x ? ? 0 0 0 0 x ? 0 0 0 0 0 0 0 0 0 x 0 0 ? ? ? ? ? ? ? ? x ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? 0 ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 ? 0 ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? x 0 0 0 ? 0 x 0 ? ? 0 0 0 ? ? ? ? ? x 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? 0 0 0 ? ? 0 0 0 ? ? ? ? ? ? ? ? ? 0 0 0 0 ? 0 0 0 0 0 0 0 ? 0 ? 0 x 0 x ? ? ? ? ? ? ? 0 ? ? ? 0 x 0 0 ? 0 ? ? ? 0 0 ? 0 x ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 ? ? x ? ? 0 ? ? ? 0 ? ? ? ? ? 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? x 0 0 0 0 ? ? 0 0 ? x 0 ? 0 ? ? ? ? ? ? 0 x ? x ? 0 ? ? ? ? ? 0 x 0 ? ? ? ? ? ? ? ? x 0 ? ? ? ? ? ? ? ? ? ? 0 x ? x x ? ? ? ? ? ? 0 0 0 ? x 0 ? ? ? ? 0 ? ? x ? ? 0 x x ? 0 ? x ? ? 0 ? ? 0 ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? x ? ? ? x x 0 ? ? 0 x
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelTimer2
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClearEvent
Show More
  • ntdll.dll!NtClose
  • ntdll.dll!NtCompareObjects
  • ntdll.dll!NtCompareSigningLevels
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateUserProcess
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtGetCachedSigningLevel
  • ntdll.dll!NtGetContextThread
  • ntdll.dll!NtGetWriteWatch
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtResetWriteWatch
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetContextThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtSuspendThread
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtUnsubscribeWnfStateChange
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • ntdll.dll!NtYieldExecution
  • UNKNOWN
User Data Access
  • GetUserDefaultLocaleName
  • GetUserName
  • GetUserObjectInformation
Other Suspicious
  • AdjustTokenPrivileges
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Process Terminate
  • TerminateProcess
Anti Debug
  • IsDebuggerPresent

Related Posts

Trending

Most Viewed

Loading...