Trojan.MSIL.Stealer.L
Threat Scorecard
EnigmaSoft Threat Scorecard
EnigmaSoft Threat Scorecards are assessment reports for different malware threats which have been collected and analyzed by our research team. EnigmaSoft Threat Scorecards evaluate and rank threats using several metrics including real-world and potential risk factors, trends, frequency, prevalence, and persistence. EnigmaSoft Threat Scorecards are updated regularly based on our research data and metrics and are useful for a wide range of computer users, from end users seeking solutions to remove malware from their systems to security experts analyzing threats.
EnigmaSoft Threat Scorecards display a variety of useful information, including:
Popularity Rank: The ranking of a particular threat in EnigmaSoft’s Threat Database.
Severity Level: The determined severity level of an object, represented numerically, based on our risk modeling process and research, as explained in our Threat Assessment Criteria.
Infected Computers: The number of confirmed and suspected cases of a particular threat detected on infected computers as reported by SpyHunter.
See also Threat Assessment Criteria.
| Popularity Rank: | 11,793 |
| Threat Level: | 80 % (High) |
| Infected Computers: | 9,207 |
| First Seen: | December 21, 2021 |
| Last Seen: | March 18, 2026 |
| OS(es) Affected: | Windows |
Table of Contents
Analysis Report
General information
| Family Name: | Trojan.MSIL.Stealer.L |
|---|---|
| Signature status: | Hash Mismatch |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
84a7213a0907ff10d3fc06429637c39b
SHA1:
7deb0984d18603173b82ec2913b78aa5eb582974
File Size:
1.79 MB, 1789248 bytes
|
|
MD5:
4a4f6edf3b4b321353a97c7627a9c36a
SHA1:
ea9174a95b1812f6f8f452f39e75c914b566749e
SHA256:
81AA69CCA2D48908D212944402A6CF6BA202B47FF855ED7B6ABEB15B5CE099DE
File Size:
569.34 KB, 569344 bytes
|
|
MD5:
bb753fdfe74f35814d51093d47fe2bc7
SHA1:
24a2a1fdb95fb0c705e5cde7d9e3cb12a0a06c84
SHA256:
484D46EFDC250C5CC1C4BCBAEBE39E2F3A3AB35225DE38E54C420E0A5A580C0C
File Size:
906.56 KB, 906560 bytes
|
|
MD5:
9ef66628c3c952ce92e8ddeeb1d7eaa3
SHA1:
f215fc9cde636e4fa3fa9e17e479e6b8b8cadff1
SHA256:
9D0C9AA7A404232EE2AA3840A8C7D10925D3C56E794FB1FC663FCBE3B7A82CC1
File Size:
1.54 MB, 1535480 bytes
|
|
MD5:
c0ff5df3aba4b3ff7de1ba8f2ca6e889
SHA1:
939c80b546f5913a72192a132c61a98349b98d97
SHA256:
F3959EA809FAB649143DCAC043C29883949581EB346AD971A5860D166DCE8016
File Size:
1.31 MB, 1313792 bytes
|
Show More
|
MD5:
af9e941533661388d6753acd4b01835e
SHA1:
a7a3cc3c777a1e7072468eeed066e2fa579fa8bf
SHA256:
649B3A14F8EE509E9FE9D5FA9005C54B097EACD4D1DB6DD5CF5AA5EFDA139286
File Size:
414.02 KB, 414016 bytes
|
|
MD5:
b3b0d320da6beed2b920d482aa22ff70
SHA1:
21a08244f0566029b440a164a0bccdb118b5d849
SHA256:
1ABEC3EA75FA09082C5F5B2E1FB83E6FF8BB1E1D6DFEAACCAA1EAA8F94482BBA
File Size:
487.94 KB, 487936 bytes
|
|
MD5:
c38fb3d549afdfd4c9979cf97fbda2b5
SHA1:
d7cdc99e83c1470907b14b49764bd36ed2387642
SHA256:
90AD3FB7B8D1C426EDF2E713C07E383229511493754324C6F926AD2088B608E5
File Size:
415.86 KB, 415856 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have debug information
- File doesn't have exports table
- File doesn't have relocations information
- File doesn't have security information
- File is .NET application
- File is 32-bit executable
- File is 64-bit executable
- File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
- File is either console or GUI application
Show More
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is not packed
- IMAGE_FILE_DLL is not set inside PE header (Executable)
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
File Icons
File Icons
This section displays icon resources found within family samples. Malware often replicates icons commonly associated with legitimate software to mislead users into believing the malware is safe.Windows PE Version Information
Windows PE Version Information
This section displays values and attributes that have been set in the Windows file version information data structure for samples within this family. To mislead users, malware actors often add fake version information mimicking legitimate software.| Name | Value |
|---|---|
| Assembly Version |
|
| Comments |
|
| Company Name |
|
| File Description |
|
| File Version |
|
| Internal Name |
|
| Legal Copyright |
|
| Legal Trademarks |
|
| Original Filename |
|
| Product Name |
|
| Product Version |
|
Digital Signatures
Digital Signatures
This section lists digital signatures that are attached to samples within this family. When analyzing and verifying digital signatures, it is important to confirm that the signature’s root authority is a well-known and trustworthy entity and that the status of the signature is good. Malware is often signed with non-trustworthy “Self Signed” digital signatures (which can be easily created by a malware author with no verification). Malware may also be signed by legitimate signatures that have an invalid status, and by signatures from questionable root authorities with fake or misleading “Signer” names.| Signer | Root | Status |
|---|---|---|
| NetEase (Hangzhou) Network Co., Ltd | DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 | Hash Mismatch |
| Microsoft Corporation | Microsoft Code Signing PCA 2010 | Hash Mismatch |
| Microsoft Corporation | Microsoft Code Signing PCA 2011 | Hash Mismatch |
File Traits
- .NET
- CreateThread
- GenKrypt
- HighEntropy
- Installer Version
- No Version Info
- Reactor
- Reflective
- RijndaelManaged
- x64
Show More
- x86
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 58 |
|---|---|
| Potentially Malicious Blocks: | 4 |
| Whitelisted Blocks: | 54 |
| Unknown Blocks: | 0 |
Visual Map
? - Unknown Block
x - Potentially Malicious Block
Similar Families
Similar Families
This section lists other families that share similarities with this family, based on EnigmaSoft’s analysis. Many malware families are created from the same malware toolkits and use the same packing and encryption techniques but uniquely extend functionality. Similar families may also share source code, attributes, icons, subcomponents, compromised and/or invalid digital signatures, and network characteristics. Researchers leverage these similarities to rapidly and effectively triage file samples and extend malware detection rules.- MSIL.Agent.LOD
- MSIL.Agent.ONR
- MSIL.Agent.XFB
- MSIL.Agent.XY
- MSIL.AgentTesla.DH
Show More
- MSIL.AgentTesla.LP
- MSIL.AgentTesla.PH
- MSIL.Bladabindi.LB
- MSIL.Bladabindi.LE
- MSIL.Coinminer.AH
- MSIL.DllInject.Z
- MSIL.Downloader.PFA
- MSIL.Downloader.PFB
- MSIL.Dropper.XC
- MSIL.Krypt.D
- MSIL.Krypt.GJLD
- MSIL.Krypt.MJC
- MSIL.Krypt.MJG
- MSIL.Krypt.OFB
- MSIL.Krypt.POB
- MSIL.Kryptik.SA
- MSIL.Mardom.AJ
- MSIL.Mardom.JG
- MSIL.Mardom.TJA
- MSIL.Mardom.TK
- MSIL.Quasar.I
- MSIL.Redline.AR
- MSIL.Stealer.KU
- MSIL.Ursu.TJG
Files Modified
Files Modified
This section lists files that were created, modified, moved and/or deleted by samples in this family. File system activity can provide valuable insight into how malware functions on the operating system.| File | Attributes |
|---|---|
| c:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\3acf660917f73e764d4410bf1eaa48f5 | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\fee33ce020c970ea56929081c2d05808 | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\3acf660917f73e764d4410bf1eaa48f5 | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\fee33ce020c970ea56929081c2d05808 | Generic Read,Write Data,Write Attributes,Write extended,Append data |
Registry Modifications
Registry Modifications
This section lists registry keys and values that were created, modified and/or deleted by samples in this family. Windows Registry activity can provide valuable insight into malware functionality. Additionally, malware often creates registry values to allow itself to automatically start and indefinitely persist after an initial infection has compromised the system.| Key::Value | Data | API Name |
|---|---|---|
| HKCU\software\microsoft\systemcertificates\ca\certificates\be68d0adaa2345b48e507320b695d386080e5b25::blob | RegNtPreCreateKey | |
| HKCU\software\microsoft\systemcertificates\ca\certificates\31600991ed5fec63d355a5484a6dcc787ead89bc::blob | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\content::cacheprefix | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\cookies::cacheprefix | Cookie: | RegNtPreCreateKey |
| HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\history::cacheprefix | Visited: | RegNtPreCreateKey |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect | RegNtPreCreateKey |
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API usage analysis is a valuable tool that can help identify malicious activity, such as keylogging, security privilege escalation, data encryption, data exfiltration, interference with antivirus software, and network request manipulation.| Category | API |
|---|---|
| User Data Access |
|
| Anti Debug |
|
| Process Terminate |
|
| Other Suspicious |
|
| Process Manipulation Evasion |
|
| Encryption Used |
|
| Syscall Use |
Show More
|