Threat Database Trojans Trojan.MSIL.Webshell.BG

Trojan.MSIL.Webshell.BG

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 18,813
Threat Level: 80 % (High)
Infected Computers: 51
First Seen: March 8, 2023
Last Seen: May 22, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Webshell.BG on your system indicates a potential security threat that requires immediate attention. This report aims to provide you with a comprehensive understanding of the threat, its operational mechanisms, symptoms of infection, and most importantly, steps to remove it from your system. Understanding the nature of the threat is crucial in taking the right steps towards securing your computer and protecting your personal data.

What Is Trojan.MSIL.Webshell.BG?

Trojan.MSIL.Webshell.BG refers to a type of malicious software (malware) that has been detected on your system. The term "Trojan" suggests that it operates by disguising itself as legitimate software, allowing it to bypass security defenses and gain unauthorized access to a computer system. The "MSIL" part of the name indicates that the malware is written in Microsoft Intermediate Language, which is a platform-agnostic intermediate representation of the .NET Framework and .NET Core. "Webshell" implies that the malware might be related to web-based attacks, potentially allowing attackers to access and control the infected system remotely through web interfaces. The ".BG" suffix could indicate the origin or a specific variant of the malware, but without more context, its significance remains speculative.

How Trojan.MSIL.Webshell.BG Operates

Malware like Trojan.MSIL.Webshell.BG typically operates by exploiting vulnerabilities in software or tricking users into installing it. Once installed, it can perform a variety of malicious activities, including but not limited to, stealing sensitive information, installing additional malware, or providing backdoor access to the attackers. The webshell component suggests it might be used to manage and control infected systems remotely, potentially turning them into bots for further malicious activities like DDoS attacks or spam distribution. Understanding how such malware operates is key to preventing future infections and mitigating the damage from current ones.

Symptoms of Infection

Symptoms of infection can vary widely depending on the specific goals of the malware and the extent of the infection. Common indicators include unexpected changes to system settings, appearance of unknown programs or toolbars in your browser, slow system performance, and frequent crashes or freezes. Sometimes, the presence of malware like Trojan.MSIL.Webshell.BG might not be immediately apparent, as it may be designed to operate stealthily in the background. Therefore, regular system checks and the use of reputable antivirus software are crucial for early detection.

How to Remove Trojan.MSIL.Webshell.BG

  1. Enter Safe Mode with Networking to limit the malware's ability to interfere with the removal process. This mode allows you to use the internet to download necessary tools while minimizing system processes.
  2. Perform a full scan of your system using a reputable antivirus tool such as SpyHunter. Ensure your antivirus software is updated to the latest version to increase the chances of detecting and removing the malware.
  3. Uninstall suspicious programs that you do not recognize or that were installed around the time the malware was detected. Be cautious and only remove programs you are certain are malicious or unnecessary.
  4. Reset your browsers (Chrome, Firefox, Edge, etc.) to their default settings. This can help remove any malicious extensions or settings changes made by the malware.
  5. After completing the above steps, reboot your system and perform another full scan to ensure the malware has been completely removed.

Conclusion

Removing Trojan.MSIL.Webshell.BG requires a combination of technical knowledge and the right tools. By following the steps outlined above and maintaining good cybersecurity practices, such as regularly updating your operating system and software, using strong passwords, and being cautious with emails and downloads, you can significantly reduce the risk of future infections. Remember, prevention is key, and vigilance is your best defense against malware and other cyber threats.

Analysis Report

General information

Family Name: Trojan.MSIL.Webshell.BG
Signature status: No Signature

Known Samples

MD5: 6ca6d909b7c8d9b914ace2fc7d80be24
SHA1: f6317f2bb8ec7e967c67fd82cc0f4761b4dcf593
SHA256: F33CD57653BD108FAED47E3EF9DD5D0D4B036F08B8413ED98F5600377240F84C
File Size: 17.92 KB, 17920 bytes
MD5: 60f1990558d1bb9b6708149bd708fed2
SHA1: f3a7e1aa62b23f8227d6caa583609acae99696d4
SHA256: 25E2D77E224181E9C8D7BEB9F25435877739D3B590D0179276412F8C65CF61EF
File Size: 63.49 KB, 63488 bytes
MD5: c73e0bfc536a5a654ce9ca92b6e44d72
SHA1: 7eabb0cbf1ce9b0d2c88e1655c249fece0579af2
SHA256: 88F10B28BA472C5AA7F7EC429A57060518B03EBC1C750E6721337ADCAB4C2EED
File Size: 63.49 KB, 63488 bytes
MD5: 8b95ecc94772a5ccc323d68e267fe8e5
SHA1: 40f1e2cc0ea452d55d9d5c7c4c838173d74261c1
SHA256: D9DBAFE36D375342C3145CD5460363882C6AA19D77E117450FD528DA2722B311
File Size: 188.93 KB, 188928 bytes
MD5: bb9eaf2c255eb355cdc9afc504277381
SHA1: d00edae6030c2807d57c3928de8fcdbaf50a06db
SHA256: 3BC04737190FB952D5820CD04B663F3A5B10579E220E2A07480BA0E9FCDF0E8E
File Size: 39.94 KB, 39936 bytes
Show More
MD5: d1173fc30d16b96d5c17a77fd6813037
SHA1: b1d7a992cfa6f6d6f2285e68aa922eb712c373fd
SHA256: D6B5FEF12089BC2484BE7E6E8A036EA9D41F754D95A64F1D323B5D6B44CA5566
File Size: 40.45 KB, 40448 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • .NET
  • dll
  • x86

Block Information

Total Blocks: 6
Potentially Malicious Blocks: 0
Whitelisted Blocks: 4
Unknown Blocks: 2

Visual Map

0 0 0 ? ? 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Webshell.BG
  • MSIL.Webshell.BJ

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
Show More
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Related Posts

Trending

Most Viewed

Loading...