Threat Database Worms WORM_MSIL.BR

WORM_MSIL.BR

By Domesticus in Worms

Threat Scorecard

Popularity Rank: 12,832
Threat Level: 80 % (High)
Infected Computers: 27,071
First Seen: October 11, 2012
Last Seen: August 7, 2026
OS(es) Affected: Windows

WORM_MSIL.BR is a worm that is distributed via removable drives, downloaded from the web or spread by other computer infections. WORM_MSIL.BR comes by connecting infected removable drives to a machine. WORM_MSIL.BR spreads as a malevolent file downloaded by other PC infections or dropped unknowingly by computer users when visiting insecure websites. While being executed, WORM_MSIL.BR checks the operating system version of the vixtimized computer. If it is Windows Vista or Windows 7, it downloads the particular copies of itself in the form of the infectious files on the targeted computer. If the operating system version is not Windows Vista or Windows 7, WORM_MSIL.BR downloads the specific copies of itself on the compromised PC.

File System Details

WORM_MSIL.BR may create the following file(s):
# File Name Detections
1. %Desktop%\suchost..exe
2. %Windows%\system\svchost..exe
3. %User Startup%\svchost..exe
4. movies.exe

Analysis Report

General information

Family Name: Trojan.MSIL.Spy
Signature status: No Signature

Known Samples

MD5: 148ee6bc7028182efe69d87047f0a7e9
SHA1: 27b13cfb5b8dfe3266258bf74c3f14761093311b
SHA256: 5155D941FC16D359553F446FC150A95BCF2CA4700E4AAF3CEBA975D3B2162D76
File Size: 434.69 KB, 434688 bytes
MD5: 39dd3648fb0176277a8ab210bbc9de02
SHA1: 0670f26520e13bec795514f6d8a97952c250f905
SHA256: 14D4E33DE088DBC8A1948371D494B7604BA5895E6483AFEDB07E4269001FDCC2
File Size: 799.74 KB, 799744 bytes
MD5: 346683f11a08e7157a1fa6f8438559bb
SHA1: 6aad10b4a859a5f34178f57945393c36ec0a915d
SHA256: C04F6E38E7E49C0404F87693ABD8A73EBD4A0ADF3974905159C2DF0322F24364
File Size: 877.57 KB, 877568 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 2.2.3.9
  • 2.1.3.9
  • 1.1.3.9
Comments
  • Dvdx Toolkit
  • Gvgx Toolkit
  • IMP Server Toolkit
Company Name
  • Dvdx Corporation
  • Gvgx Corporation
  • IMP Server Inc
File Description
  • Dvdx Toolkit
  • Gvgx Toolkit
  • IMP Server Toolkit
File Version
  • 2.2.2.9
  • 2.1.2.9
  • 1.1.2.9
Internal Name server1.exe
Legal Copyright
  • Dvdx Copyright © 2026
  • Gvgx Copyright © 2026
  • Server Copyright © 2026
Legal Trademarks
  • Dvdx Server Corporation
  • Gvgx Toolkit Server Corporation
  • IM Server Incorporation
Original Filename server1.exe
Product Name
  • Dvdx Toolkit
  • Gvgx Toolkit Star
  • IMP Server Toolkit
Product Version
  • 2.2.2.9
  • 2.1.2.9
  • 1.1.2.9

File Traits

  • .NET
  • HighEntropy
  • RijndaelManaged
  • x86

Block Information

Total Blocks: 107
Potentially Malicious Blocks: 0
Whitelisted Blocks: 35
Unknown Blocks: 72

Visual Map

? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 ? ? 0 ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? 0 ? 0 0 0 0 0 ? 0 ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Encryption Used
  • BCryptOpenAlgorithmProvider