Threat Database Stealers Trojan.MSIL.Stealer.CO

Trojan.MSIL.Stealer.CO

By CagedTech in Stealers, Trojans

Threat Scorecard

Popularity Rank: 18,960
Threat Level: 80 % (High)
Infected Computers: 5
First Seen: June 23, 2023
Last Seen: June 5, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Stealer.CO on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise your computer's security and steal sensitive information. It is essential to understand the nature of this threat and take prompt action to remove it and prevent further damage.

What Is Trojan.MSIL.Stealer.CO?

Trojan.MSIL.Stealer.CO is a type of Trojan horse malware that can infect your computer without your knowledge or consent. The name suggests that it is a malicious program designed to steal sensitive information from your system. Trojans are known for their ability to disguise themselves as legitimate programs, making them difficult to detect. They can be spread through various means, including infected software downloads, phishing emails, or exploited vulnerabilities in your system.

How Trojan.MSIL.Stealer.CO Operates

Once installed on your system, Trojan.MSIL.Stealer.CO can operate in the background, collecting sensitive information such as login credentials, credit card numbers, and other personal data. It can also create backdoors, allowing hackers to access your system remotely and steal more information or install additional malware. This type of malware can be particularly dangerous, as it can lead to identity theft, financial loss, and compromised system security.

Symptoms of Infection

Identifying the symptoms of a Trojan.MSIL.Stealer.CO infection can be challenging, as it can operate stealthily. However, some common signs of infection include slow system performance, unexpected pop-ups or ads, and unfamiliar programs or icons on your desktop. You may also notice that your browser is being redirected to unfamiliar websites or that your system is crashing frequently. If you suspect that your system is infected, it is crucial to take immediate action to remove the malware.

How to Remove Trojan.MSIL.Stealer.CO

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for a more effective removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malicious programs or files.
  3. Uninstall any suspicious programs or applications that you do not recognize or that were installed without your consent.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform another scan with your anti-malware tool to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.MSIL.Stealer.CO from your system requires careful attention to detail and a thorough understanding of the malware removal process. By following the steps outlined above and using reputable anti-malware tools, you can effectively remove this threat and prevent further damage to your system. It is essential to remain vigilant and take proactive measures to protect your system from future malware infections, including keeping your operating system and software up to date, using strong antivirus software, and avoiding suspicious downloads or email attachments.

Analysis Report

General information

Family Name: Trojan.MSIL.Stealer.CO
Signature status: No Signature

Known Samples

MD5: f3ea1a5babb98de208b70612230561a1
SHA1: 472d8eb46748ff709ae37f722d04acd6b1382321
SHA256: 26893A4D8B0ED50DEE01C861BAEE0903E8D63F3E34AAA890E34456076D408DC2
File Size: 1.64 MB, 1642496 bytes
MD5: 3abd07bef3e6731a4c8031de2c363437
SHA1: 05535072ca984eaf1f909f29e061d96b3a4ba8b5
SHA256: 01641A22219AF864546CB0449FAFE652EFE0FE6E8F1732652979A90175F353AA
File Size: 1.65 MB, 1649664 bytes
MD5: bb0b9f56a77f5a649870cfc39631c43c
SHA1: 58a098b57d8c3e4b467db3f7f1480c59cf8e18ce
SHA256: 044F68772B73C42954438D8466FBF69A476BECADCF6106272071DAF2AB23F122
File Size: 1.56 MB, 1564672 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 1.29.1.70
  • 1.25.4.59
  • 1.0.1.0
Comments EBLICT Product's Installer application. Automatically updates your EBLICT installed applications with latest versions and Sync with EBLICT Server. In One Place Manage Your All EBLICT Applications !
Company Name
  • Enhanced in Bangla language through research and development (EBLICT)
  • Ingeteam
File Description
  • Bangla_Word_Plugin
  • iedFactory
File Version
  • 1.29.1.70
  • 1.25.4.59
  • 1.0.1
Internal Name
  • Bangla_Word_Plugin.dll
  • iedFactory.exe
Legal Copyright
  • Copyright © 2003-2019 Ingeteam
  • Copyright © 2003-2021 Ingeteam
  • Copyright © 2025 EBLICT. All rights reserved.
Legal Trademarks INGESYS™ - INGESAS™
Original Filename
  • Bangla_Word_Plugin.dll
  • iedFactory.exe
Product Name
  • EBLICT Product's Installer
  • ZY8102IJD01AC
  • ZY8102IJD01Z
Product Version
  • 1.29.1.70
  • 1.25.4.59
  • 1.0.0

File Traits

  • .NET
  • Installer Version
  • x64
  • x86

Block Information

Total Blocks: 136
Potentially Malicious Blocks: 2
Whitelisted Blocks: 61
Unknown Blocks: 73

Visual Map

0 0 0 0 0 ? ? ? ? ? ? ? ? ? 0 0 0 0 ? ? 0 0 ? 0 ? ? ? ? ? ? ? ? 0 ? ? 0 0 0 0 ? 0 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 x x 0 ? ? ? 0 ? 0 0 0 0 0 ? ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? 0 0 0 0 ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 ? ? ? 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\windows\appcompat\programs\amcache.hve Read Data,Read Control,Write Data
c:\windows\appcompat\programs\amcache.hve Write Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 Bk� �v����#��&�-(�1�1HO@V�H[uH�pX�k`l(��P��/�����b:����X����h �a �m�ͪ�gi�$����j��oAB1_B��`�V������zH��@K� RegNtPreCreateKey
HKLM\system\software\microsoft\tip\aggregateresults::data 鐄ȴ 鲱莏洎ʫጉ嵑祧픋˹耀뫹躧隞̃昁耀꧌ì< RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �lm�B �� �v �� 7� �� ���T�B������%Bx�!#��$��%�&� &�-'�!(�(X�(�) ;*J*9*�",=�1�1HO5,]5�G>��@V�@�*B F Fy�G�IH[uM�lN$N�P@jR��X �b"hc�we0Te�hh�rj�bk`k�ql(�q(q�XrnJ RegNtPreCreateKey
HKLM\system\software\microsoft\tip\aggregateresults::data 鐄ȴ 鲱漺픋˹耀뫹躧隞̃㜁耀꧌Ôʚ RegNtPreCreateKey

Windows API Usage

Category API
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
Process Shell Execute
  • CreateProcess
Encryption Used
  • BCryptOpenAlgorithmProvider
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtDuplicateObject
Show More
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Shell Command Execution

C:\Windows\Microsoft.NET\Framework\v2.0.50727\\dw20.exe dw20.exe -x -s 788
C:\Windows\Microsoft.NET\Framework\v2.0.50727\\dw20.exe dw20.exe -x -s 848

Related Posts

Trending

Most Viewed

Loading...