Threat Database Trojans Trojan.MSIL.Webshell.BD

Trojan.MSIL.Webshell.BD

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 3,141
Threat Level: 80 % (High)
Infected Computers: 897
First Seen: February 21, 2023
Last Seen: July 9, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Webshell.BD indicates that a potentially malicious program has been identified on your system. This name suggests a type of Trojan horse malware, which is a broad category of threats that disguise themselves as legitimate software to gain unauthorized access to a computer system. Understanding the nature of this threat and how it operates is crucial for effective removal and prevention of future infections.

What Is Trojan.MSIL.Webshell.BD?

Trojan.MSIL.Webshell.BD, as indicated by its name, falls under the category of Trojan malware. Trojans are malicious programs that can allow unauthorized access to the victim's system, potentially leading to data theft, system compromise, or the installation of additional malware. The term "MSIL" refers to Microsoft Intermediate Language, which is a component of the .NET Framework, suggesting that this malware might be designed to operate within environments that support .NET. "Webshell" implies a connection to web servers or web applications, possibly indicating that the malware could be used to compromise web servers or use them as a conduit for malicious activities.

How Trojan.MSIL.Webshell.BD Operates

While specific details about the operation of Trojan.MSIL.Webshell.BD are not available, Trojans generally operate by deceiving users into installing them, often by disguising themselves as useful software. Once installed, they can create backdoors for remote access, steal sensitive information, disrupt system operation, or install additional malicious software. The webshell component might enable attackers to execute server-side code, potentially leading to server compromise, data breaches, or the distribution of malware to visitors of the compromised website.

Symptoms of Infection

Symptoms of a Trojan infection can be subtle and may not always be immediately apparent. Common indicators include unusual system behavior, such as unexpected pop-ups, slow system performance, or unfamiliar programs running in the background. In cases where the Trojan affects web applications or servers, symptoms might include unauthorized changes to website content, unusual network activity, or alerts from security software. Given the potential for Trojans to install additional malware, any suspicious activity should be thoroughly investigated.

How to Remove Trojan.MSIL.Webshell.BD

  1. Enter Safe Mode with Networking to limit the malware's ability to interfere with the removal process. This mode allows you to use the internet to download necessary tools while limiting the number of running programs.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter. Ensure the tool is updated to the latest version to maximize its effectiveness against the latest threats.
  3. Uninstall suspicious programs that you do not recognize or that were installed around the time the malware was detected. Be cautious and only remove programs you are certain are malicious or unnecessary.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings. This can help remove any malicious extensions or settings changes made by the Trojan.
  5. After completing the above steps, reboot your system and perform another full scan to ensure that the malware has been completely removed. Repeat the scanning process until no threats are detected.

Conclusion

The removal of Trojan.MSIL.Webshell.BD requires careful and systematic steps to ensure that all components of the malware are eliminated from the system. Prevention is also key; avoiding suspicious downloads, keeping software up to date, and using robust security tools can significantly reduce the risk of future infections. By understanding the nature of Trojan threats and taking proactive measures, individuals and organizations can better protect themselves against these and other types of malware.

Analysis Report

General information

Family Name: Trojan.MSIL.Webshell.BD
Signature status: No Signature

Known Samples

MD5: 09899ee637d215865088fb1561d4b5d5
SHA1: 662de5f8c186dc1d8989dfc890993cf2ca9ba64c
SHA256: 63C656342D40321F13AE68B7DEFFA7C4CA46252D63C0AAA284577639BDD93D9B
File Size: 225.79 KB, 225792 bytes
MD5: 71835aba53b22715d40b70ed2f2b8cf7
SHA1: 0d663e995d6c8fb125c88b4d1d5e0ca71017cf76
SHA256: 9CF2B884D572E8887AE8A31B7FF744A47ED7AC886070C0B28899FE3D15B338EC
File Size: 164.35 KB, 164352 bytes
MD5: eac65a3eb61723718779dd4cddbc5456
SHA1: 9ccee7661d50e8ff0f53e4d0dbc2ec54764f09a2
SHA256: 8F7D080F48BDB6120596BEB987131BA82B576261210FB70A606B598988C3EAE1
File Size: 77.31 KB, 77312 bytes
MD5: 9d6030af959599cce0c5ee988a3cc1cb
SHA1: 1536f1b91ae608e2dbe0f7793c03133db84b44b3
SHA256: 92EC5567CF06AA2FD9671B309E2CD6D6AF3876057EF0004A993C0EC10B9DB09F
File Size: 318.98 KB, 318976 bytes
MD5: 4fb3bb837d16a590fc459127a759dede
SHA1: 11ab516f1b7a6996737727896aebe626dba2d01c
SHA256: FCA3D2BA9B769DBE6465C89C94335A9848023C2C9EE63114FCB4750D58F066EA
File Size: 18.94 KB, 18944 bytes
Show More
MD5: da818feae2eb9262eb23079fe3e47a96
SHA1: 9d45f535844a926c4c44290fea04dfa6011ad5ed
SHA256: F921EAADC12CFDF314852EC0257CC9C93028F271AE5B25610B2A694EB50B4A12
File Size: 17.92 KB, 17920 bytes
MD5: 2faeb71cc0838691105259a62c9b78bf
SHA1: aaef62378ec9c16298657686209842ff48701fc3
SHA256: 1C4F8F296CFA7350E429E4AF9E1694966C0E93C3B7AEDE448D8DA6543FF8C408
File Size: 92.67 KB, 92672 bytes
MD5: d37d4c7a8cf75648e16ee8bc6751aad5
SHA1: e4c71dc90788369c5ef974bbacc09e9e4896a660
SHA256: 9DEDC02F518F623364E016CB3928FFF60A6964CB73678124A7B8127066C4604F
File Size: 71.17 KB, 71168 bytes
MD5: 3f89c5a3de8218f8091dedc4912571b5
SHA1: 7f65400ff8f6c690f7d89ac0bd84883795b3b218
SHA256: 6F6DB1F1A645554B567D257F72A82D4BCAA01BD0FE6DE166C78273FB1ABC1DC5
File Size: 24.58 KB, 24576 bytes
MD5: 9d1caa782b598633029ec1cf4079988b
SHA1: 62a219dbfb02e3ac04b46e32f3c9e7ec44777690
SHA256: 7E79A284FF5C68F9BC4F531FBB19C36E2732D6658CE5C2869421531298589A84
File Size: 24.58 KB, 24576 bytes
MD5: f85fe937889a9b3f973c2c9fef99f472
SHA1: 16945f7087925773e9187d0c0e361458ccf0c026
SHA256: 3F6ED1CA3FC76BE1B220BFD8C81E712DECCB67F57D7424845D21F2CD1E3ED7E8
File Size: 139.78 KB, 139776 bytes
MD5: b83cc78e569a54ae623e7217cceacf27
SHA1: 5079c866dbd3728732a87b09cb01b784673055e3
SHA256: DF78AA26F296DC7C6201A54C6B47ACF83571686C711A9CD5188B9B863593D517
File Size: 79.87 KB, 79872 bytes
MD5: 702cde79f4f8e98bd3c8b47904af63ea
SHA1: 7fa5ca3c90c691dbb76722b009fb79ff63a7d3f1
SHA256: 058CD5304E0903D42AA0DBD73B1AF16F4D8A4ABD47A294CC67BD35B282D8C22C
File Size: 282.11 KB, 282112 bytes
MD5: 9d82d2052ac2ed829c286f9ac627549b
SHA1: a6d1117a827a8348262c90502e61573f194891b2
SHA256: 80FEB2D2E699E15E911DED5941E58B67A3D610FE6BB2B21A0C136100F3AD6D77
File Size: 13.31 KB, 13312 bytes
MD5: 9a66eea72ac87862cc4272e0a0053e6b
SHA1: c335a3c97a59c19289757ff20f5c62b63069d354
SHA256: 485446C1A75B475D794385483297BBDB36D8072E45D213506CB2EC22F3768D19
File Size: 258.05 KB, 258048 bytes
MD5: 79944e30c1eab37afd8b7173c230b03e
SHA1: ad11d785ca571f350983f7a6ed3aee8ea378f7ac
SHA256: 3D2A56C916E06B76E2E4701E1166C318C1D28AE60C7A9DD5026C7019D46DF59E
File Size: 13.82 KB, 13824 bytes
MD5: 276bb6704ce0e43a934699bdcf52f948
SHA1: 734a61195fa1053fabff4ef434232daf60b27c5e
SHA256: 659BE9553921F9A91E9E3701AA6536682A9B72EABEC5CCFC0AAADE4689E13F5B
File Size: 27.14 KB, 27136 bytes
MD5: ca3d7120c5e5d717c4f50677e5d4d61d
SHA1: 04dcaac174fbc1aa27bf85f5eeb7fe383d2aa044
SHA256: 0DE96ACAF96160F220DEF1CB4A09B531721CF76812DEBD2EC96CE9803BD1F1D9
File Size: 60.42 KB, 60416 bytes
MD5: 557136d7af6d3735cb3417d96912def3
SHA1: 9779e30a08f62dc71e578a8508709da3f4e25744
SHA256: 7CE2376019ED9E718823C6C39D618A0883AC5370FA706869E9791E52AFAA2C7B
File Size: 163.84 KB, 163840 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 0.0.0.0
File Version 0.0.0.0
Internal Name
  • App_Web_1dw5fmcx.dll
  • App_Web_qi5hbaa0.dll
  • App_Web_xstfujpq.dll
Original Filename
  • App_Web_1dw5fmcx.dll
  • App_Web_qi5hbaa0.dll
  • App_Web_xstfujpq.dll
Product Version 0.0.0.0

File Traits

  • .NET
  • dll
  • x86

Block Information

Total Blocks: 679
Potentially Malicious Blocks: 162
Whitelisted Blocks: 122
Unknown Blocks: 395

Visual Map

x 0 0 x x ? ? ? ? ? ? x ? ? x 0 ? ? 0 ? ? 0 x ? ? x ? ? x x x ? ? x ? ? x x x x ? ? 0 x x ? ? 0 ? 0 ? 0 0 0 x 0 0 x x ? ? ? ? 0 ? 0 0 0 ? ? 0 ? ? 0 x ? ? ? ? ? ? ? ? 0 0 ? ? ? 0 x ? ? x ? ? 0 x ? ? x ? ? 0 x x ? ? 0 x 0 ? ? 0 ? ? x ? x 0 x 0 0 x x ? ? ? 0 ? ? x ? x x x ? ? ? x ? x x x ? ? ? x ? x x x ? ? ? x ? x x x ? ? ? x ? x x x ? x ? ? 0 ? ? 0 ? ? x ? 0 x 0 x 0 0 x x ? ? ? 0 ? ? ? ? ? ? ? ? ? x 0 0 0 ? ? ? 0 ? ? 0 x ? ? ? ? ? ? ? ? ? ? ? ? ? x x ? ? ? 0 ? ? 0 x x ? ? 0 ? 0 ? ? 0 x 0 x 0 0 x x ? ? ? ? ? 0 ? ? ? ? x ? 0 ? ? ? ? ? ? x 0 ? ? ? 0 ? ? 0 x ? ? ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 ? ? 0 x x ? ? 0 ? ? x ? x ? x 0 x 0 0 x x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? 0 ? ? 0 x ? ? x ? ? 0 x ? ? x ? ? 0 x ? ? x ? ? 0 x ? ? x ? ? 0 x x x ? ? 0 x ? ? x ? ? 0 x ? ? x ? ? 0 x ? ? x ? ? 0 x ? ? x ? ? 0 x ? ? x ? ? 0 x x x ? ? 0 x ? ? x ? ? 0 x ? ? x ? ? 0 x ? ? x ? ? 0 ? ? ? x ? x 0 ? ? ? x ? ? ? 0 ? ? ? x ? ? ? 0 ? ? ? x ? x 0 ? ? ? x ? x 0 ? ? ? x ? ? ? 0 ? ? ? x ? x 0 ? ? ? x ? x 0 ? ? ? x ? x 0 ? ? ? x ? x 0 ? ? ? x ? x 0 ? ? ? x ? x 0 ? ? ? x ? x 0 ? ? ? x ? x 0 ? ? ? x ? x 0 ? ? ? x ? x 0 ? ? ? x ? x 0 ? ? ? x ? ? 0 ? ? ? x ? x 0 ? ? ? x ? x 0 ? ? ? x ? x 0 ? ? ? x ? x 0 ? ? ? x ? x 0 ? ? ? x ? ? 0 ? ? ? x ? ? 0 ? ? ? x ? ? 0 ? ? ? x ? ? 0 ? ? ? ? 0 x x ? ? 0 ? x x 0 x 0 ? ? ? 0 x 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Webshell.BC
  • MSIL.Webshell.BV

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �m �v����Bx(�1�1HO@V�H[uN$_�zb"hk�q{b��P���!� ���3�����������m��V����$�8წ���l��~�=�SB1_T�Vw���%���������AE��D��&��$���LA*�"C��| RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
Show More
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN
  • win32u.dll!NtGdiBitBlt
  • win32u.dll!NtGdiCreateBitmap
  • win32u.dll!NtGdiCreateCompatibleDC
  • win32u.dll!NtGdiCreateDIBitmapInternal
  • win32u.dll!NtGdiCreateSolidBrush
  • win32u.dll!NtGdiDeleteObjectApp
  • win32u.dll!NtGdiExtGetObjectW
  • win32u.dll!NtGdiGetDCforBitmap
  • win32u.dll!NtGdiGetDCObject
  • win32u.dll!NtGdiGetDeviceCaps
  • win32u.dll!NtGdiRestoreDC
  • win32u.dll!NtGdiSaveDC
  • win32u.dll!NtGdiSelectBitmap
  • win32u.dll!NtGdiSetDIBitsToDeviceInternal
  • win32u.dll!NtUserBuildHwndList
  • win32u.dll!NtUserCallTwoParam
  • win32u.dll!NtUserCreateEmptyCursorObject
  • win32u.dll!NtUserCreateWindowEx
  • win32u.dll!NtUserDestroyWindow
  • win32u.dll!NtUserFindExistingCursorIcon
  • win32u.dll!NtUserGetAncestor
  • win32u.dll!NtUserGetClassInfoEx
  • win32u.dll!NtUserGetClassName
  • win32u.dll!NtUserGetDC
  • win32u.dll!NtUserGetGUIThreadInfo
  • win32u.dll!NtUserGetIconInfo
  • win32u.dll!NtUserGetIconSize
  • win32u.dll!NtUserGetImeInfoEx
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetObjectInformation
  • win32u.dll!NtUserGetProcessWindowStation
  • win32u.dll!NtUserGetProp
  • win32u.dll!NtUserGetThreadDesktop
  • win32u.dll!NtUserGetThreadState
  • win32u.dll!NtUserGetWindowCompositionAttribute
  • win32u.dll!NtUserIsNonClientDpiScalingEnabled
  • win32u.dll!NtUserIsTopLevelWindow
  • win32u.dll!NtUserMessageCall
  • win32u.dll!NtUserRegisterClassExWOW
  • win32u.dll!NtUserRegisterWindowMessage
  • win32u.dll!NtUserReleaseDC
  • win32u.dll!NtUserRemoveProp
  • win32u.dll!NtUserSelectPalette
  • win32u.dll!NtUserSetCursorIconData
  • win32u.dll!NtUserSetWindowFNID
  • win32u.dll!NtUserSetWindowLongPtr
  • win32u.dll!NtUserSetWindowPos
  • win32u.dll!NtUserUpdateInputContext

Related Posts

Trending

Most Viewed

Loading...