Threat Database Trojans Trojan.MSIL.Webshell.DG

Trojan.MSIL.Webshell.DG

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 14,882
Threat Level: 80 % (High)
Infected Computers: 24
First Seen: October 7, 2024
Last Seen: June 20, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Webshell.DG indicates that your system has been compromised by a potentially malicious threat. This type of threat is generally associated with Trojan-type malware, which can have various effects on an infected system. It's essential to understand the nature of this threat and take appropriate steps to remove it and prevent future infections.

What Is Trojan.MSIL.Webshell.DG?

Trojan.MSIL.Webshell.DG is a type of malware that can be used to gain unauthorized access to a system or network. The name suggests that it may be related to webshell malware, which is designed to provide remote access to an infected system. However, without more specific information, it's difficult to determine the exact nature and capabilities of this particular threat.

How Trojan.MSIL.Webshell.DG Operates

Malware like Trojan.MSIL.Webshell.DG typically operates by exploiting vulnerabilities in software or using social engineering tactics to trick users into installing it. Once installed, the malware can communicate with its creators or other infected systems, potentially allowing for the theft of sensitive information, installation of additional malware, or other malicious activities. The exact mechanisms used by Trojan.MSIL.Webshell.DG are not known, but it's likely that it uses common malware techniques to achieve its goals.

Symptoms of Infection

Systems infected with Trojan.MSIL.Webshell.DG may exhibit a range of symptoms, including unusual network activity, slower system performance, or unexpected changes to system settings. Users may also notice that their system is behaving erratically or that they are being redirected to unfamiliar websites. However, some malware can operate without producing noticeable symptoms, making it essential to use antivirus software and other security tools to detect and remove threats.

  • Unexplained changes to system settings or files
  • Increased network activity or unusual traffic patterns
  • Slow system performance or crashes
  • Appearance of unexpected or unfamiliar programs

How to Remove Trojan.MSIL.Webshell.DG

  1. Boot your system into Safe Mode with Networking to prevent the malware from loading and to allow for internet access.
  2. Use a reputable antivirus tool, such as SpyHunter, to perform a full scan of your system and remove any detected threats.
  3. Uninstall any suspicious programs that may be related to the malware infection.
  4. Reset your web browsers (e.g., Chrome, Firefox, Edge) to their default settings to remove any potentially malicious extensions or settings.
  5. Reboot your system and perform another scan with your antivirus software to ensure that the threat has been fully removed.

Conclusion

Removing Trojan.MSIL.Webshell.DG from an infected system requires careful attention to detail and the use of reputable security software. By following the steps outlined above and maintaining good security practices, such as regularly updating software and avoiding suspicious downloads, you can help protect your system from future malware infections. It's also essential to stay informed about potential threats and to use a combination of security tools and best practices to safeguard your digital assets.

Analysis Report

General information

Family Name: Trojan.MSIL.Webshell.DG
Signature status: No Signature

Known Samples

MD5: 163c19ce144d18b74dcd1b81c5cd82f9
SHA1: 275de706164c54175bd0f2758c7434d30fe5acf0
SHA256: 0745AFEB2ED410334D0DE49EDEA400437FB49ECD69807395B4C5B46CD23CAAAF
File Size: 307.20 KB, 307200 bytes
MD5: 8483cf65d6a103e851a6b3c05552a2c0
SHA1: fbf9f210a49b47003603d5e74fb645966eb1b57d
SHA256: CDBEF376EA39F07961C03117FB3F32F3F760E0EC59AECC577681049712C48DDF
File Size: 284.16 KB, 284160 bytes
MD5: a19ca1ccace7a7fc76e2e435c41d89e1
SHA1: 64b17d2fa779c34bd81d14f8cb6c00f9df60d977
SHA256: 716DB9DD28D5ADBEA025BAB6FBD2D5F0D6B557D2FEF1D42A2321023AF94A570E
File Size: 171.01 KB, 171008 bytes
MD5: 2607419778b19fe7d162feefa616c42f
SHA1: a3f9cd24859fae2d156b279d5b03a64e509562d7
SHA256: 7EE604265A79ED3A74CAD8219827BBBBFBB6CA5F520FB93D8B54EFBDBE1213D6
File Size: 247.81 KB, 247808 bytes
MD5: 3ab111a3aea0cb1b5d8b7e6722883435
SHA1: a4fa2db42a99bf2210dd20911670f10ef8fa9663
SHA256: 545BDB3068CB87AC9F71C120A47FAFD8B45C2F1E48E7A20CDA2C6D9B9CAD7579
File Size: 302.59 KB, 302592 bytes
Show More
MD5: abd68537a67cab965f1447758f39f1f4
SHA1: 18634f3111904a019c8a3179fbd74cd450c9b814
SHA256: F37FC6D93DEB2809CC35692DBA7158632C390ADD111F3C2C632C409376F4951A
File Size: 208.38 KB, 208384 bytes
MD5: 634d76b10bbe607f3efe180ab5b658eb
SHA1: 9b904fd819c5c80a7c766c45863bb68a0b230a89
SHA256: 454135E82C8135CBB21547D4404E6A3E3D9E8E8A9D51BC076958982B966CFF50
File Size: 190.98 KB, 190976 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • .NET
  • dll
  • x86

Block Information

Total Blocks: 547
Potentially Malicious Blocks: 152
Whitelisted Blocks: 61
Unknown Blocks: 334

Visual Map

x 0 0 x x x ? ? 0 ? 0 x 0 0 ? 0 x 0 ? x ? ? ? ? x ? ? x ? x ? ? ? x ? x ? ? ? x ? x ? ? ? ? ? ? ? ? 0 0 ? ? x ? ? ? x x ? ? ? ? x ? ? ? ? ? x 0 ? 0 x 0 0 x x x ? x ? x x x x x x x x x x x ? x x ? ? ? x ? x ? ? ? ? ? ? ? x 0 x 0 0 0 0 0 x x x 0 x 0 0 ? 0 0 ? x 0 x ? x ? ? ? x ? ? ? x x ? ? ? x ? ? ? ? x ? ? ? ? ? x x x ? ? ? x x x ? ? ? ? ? ? x ? x x x x x x ? ? ? ? ? ? ? ? ? ? ? x x ? x ? x ? ? ? ? ? ? ? ? x ? ? x ? ? ? ? x ? x ? ? ? ? x ? x ? ? ? ? x ? x ? ? ? ? ? x ? x ? ? ? ? ? x x ? ? ? x x ? ? ? x ? ? ? ? ? ? ? x ? x ? ? ? x ? x ? ? ? x ? x ? ? ? x x ? ? ? ? ? ? ? ? ? x 0 ? 0 x 0 0 ? 0 ? x x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 x ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 x ? ? ? ? ? ? ? ? ? ? ? ? ? x ? 0 x ? ? ? ? ? x 0 ? 0 0 0 0 0 0 x x 0 x 0 0 ? 0 x 0 x 0 ? ? ? x ? ? x ? x ? ? ? ? ? ? x ? ? ? x ? ? ? ? x ? ? x ? x ? ? x ? x ? ? ? ? x ? x ? ? x ? x ? ? x ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? x ? x ? ? ? x ? x ? ? ? ? ? ? ? ? ? x 0 ? 0 x 0 0 ? 0 x 0 ? ? x ? x ? ? ? ? 0 x 0 ? 0 x 0 0 x 0 ? x x x x x x x x ? x x ? x x ? ? ? ? x ? x ? ? ? ? ? ? ? ? ? ? ? x 0 ? 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
Show More
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN
  • win32u.dll!NtGdiBitBlt
  • win32u.dll!NtGdiCreateBitmap
  • win32u.dll!NtGdiCreateCompatibleDC
  • win32u.dll!NtGdiCreateDIBitmapInternal
  • win32u.dll!NtGdiCreateSolidBrush
  • win32u.dll!NtGdiDeleteObjectApp
  • win32u.dll!NtGdiExtGetObjectW
  • win32u.dll!NtGdiGetDCforBitmap
  • win32u.dll!NtGdiGetDCObject
  • win32u.dll!NtGdiGetDeviceCaps
  • win32u.dll!NtGdiRestoreDC
  • win32u.dll!NtGdiSaveDC
  • win32u.dll!NtGdiSelectBitmap
  • win32u.dll!NtGdiSetDIBitsToDeviceInternal
  • win32u.dll!NtUserBuildHwndList
  • win32u.dll!NtUserCallTwoParam
  • win32u.dll!NtUserCreateEmptyCursorObject
  • win32u.dll!NtUserCreateWindowEx
  • win32u.dll!NtUserDestroyWindow
  • win32u.dll!NtUserFindExistingCursorIcon
  • win32u.dll!NtUserGetAncestor
  • win32u.dll!NtUserGetClassInfoEx
  • win32u.dll!NtUserGetClassName
  • win32u.dll!NtUserGetDC
  • win32u.dll!NtUserGetGUIThreadInfo
  • win32u.dll!NtUserGetIconInfo
  • win32u.dll!NtUserGetIconSize
  • win32u.dll!NtUserGetImeInfoEx
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetObjectInformation
  • win32u.dll!NtUserGetProcessWindowStation
  • win32u.dll!NtUserGetProp
  • win32u.dll!NtUserGetThreadDesktop
  • win32u.dll!NtUserGetThreadState
  • win32u.dll!NtUserGetWindowCompositionAttribute
  • win32u.dll!NtUserIsNonClientDpiScalingEnabled
  • win32u.dll!NtUserIsTopLevelWindow
  • win32u.dll!NtUserMessageCall
  • win32u.dll!NtUserRegisterClassExWOW
  • win32u.dll!NtUserRegisterWindowMessage
  • win32u.dll!NtUserReleaseDC
  • win32u.dll!NtUserRemoveProp
  • win32u.dll!NtUserSelectPalette
  • win32u.dll!NtUserSetCursorIconData
  • win32u.dll!NtUserSetWindowFNID
  • win32u.dll!NtUserSetWindowLongPtr
  • win32u.dll!NtUserSetWindowPos
  • win32u.dll!NtUserUpdateInputContext

Related Posts

Trending

Most Viewed

Loading...