Threat Database Backdoors Backdoor.MSIL.Spy.Agent.JD

Backdoor.MSIL.Spy.Agent.JD

By CagedTech in Backdoors

Threat Scorecard

Threat Level: 60 % (Medium)
Infected Computers: 31
First Seen: June 14, 2023
Last Seen: March 15, 2026
OS(es) Affected: Windows

The detection of Backdoor.MSIL.Spy.Agent.JD indicates that your system has been compromised by a malicious threat. This type of malware is designed to secretly allow unauthorized access to your computer, potentially leading to serious security breaches and data theft. It is essential to understand the nature of this threat and take immediate action to remove it from your system to prevent further damage.

What Is Backdoor.MSIL.Spy.Agent.JD?

Backdoor.MSIL.Spy.Agent.JD is a type of backdoor malware that uses the Microsoft Intermediate Language (MSIL) to operate. This means it is designed to run on the .NET Common Language Runtime (CLR), allowing it to blend in with legitimate system processes and avoid detection. The "Spy" and "Agent" components of its name suggest that it is capable of spying on the user's activities and possibly communicating with a command and control server to receive instructions or send stolen data.

How Backdoor.MSIL.Spy.Agent.JD Operates

Backdoor malware like Backdoor.MSIL.Spy.Agent.JD typically operates by creating a covert communication channel between the infected computer and a remote server controlled by the attackers. This channel can be used to steal sensitive information, install additional malware, or provide the attackers with remote access to the infected system. The malware may also have the ability to hide its presence by disguising itself as a legitimate system process or by exploiting vulnerabilities in the system's security.

The exact mechanisms used by Backdoor.MSIL.Spy.Agent.JD to infect systems and maintain its presence are not specified, but common methods include exploiting software vulnerabilities, phishing attacks, and drive-by downloads from compromised websites. Once installed, the malware can potentially monitor and log keystrokes, capture screenshots, and steal personal data such as passwords and credit card numbers.

Symptoms of Infection

Identifying a backdoor infection can be challenging due to its stealthy nature. However, some symptoms may indicate the presence of malware like Backdoor.MSIL.Spy.Agent.JD. These include unusual system behavior such as slow performance, unexpected crashes, or unfamiliar programs running in the!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!background. Additionally, if you notice unauthorized access to your personal data, such as login credentials being used from unfamiliar locations, it could be a sign of a backdoor infection.

How to Remove Backdoor.MSIL.Spy.Agent.JD

  1. Enter Safe Mode with Networking: Restart your computer and enter Safe Mode with Networking. This will limit the malware's ability to interfere with the removal process.
  2. Full Scan with a Reputable Tool: Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. Ensure the tool is updated with the latest definitions to improve the chances of detecting and removing the malware.
  3. Uninstall Suspicious Programs: Check your installed programs for any that you do not recognize or that were installed around the time the malware was detected. Uninstall these programs to prevent them from potentially reinstalling the malware.
  4. Reset Browsers: Reset your web browsers (Chrome, Firefox, Edge) to their default settings. This can help remove any malicious extensions or settings that the malware may have installed.
  5. Reboot and Re-scan: After completing the above steps, reboot your computer and perform another full scan with your anti-malware tool to ensure that the malware has been completely removed.

Conclusion

Removing Backdoor.MSIL.Spy.Agent.JD requires careful and immediate action to prevent further damage to your system and protect your personal data. By following the steps outlined above and maintaining good security practices, such as keeping your software up to date and being cautious with emails and downloads, you can significantly reduce the risk of future malware infections. Remember, vigilance and proactive security measures are key to safeguarding your digital security in today's evolving threat landscape.

Analysis Report

General information

Family Name: Backdoor.MSIL.Spy.Agent.JD
Signature status: No Signature

Known Samples

MD5: e1475048cdd374945f10fd84ae6276cf
SHA1: 6ace5b90cdd0317789d955539409c616fa33ecb2
SHA256: A8877BB8A4C398186E6AE41B7F64DEBD3C1907522AD6570BF6B2028DCB01561C
File Size: 1.01 MB, 1007616 bytes
MD5: 41917f6c778b127afce0b7c440df73f6
SHA1: 4198acb65e7d25d179b04e833aed0f0f164a1173
SHA256: 5017B3F939C248FDE7CA0AC6B75B8D3B6B21FDB5B1DB23A42A79F10247E13A07
File Size: 190.46 KB, 190464 bytes
MD5: 530e17c2c7eb40581b5b62a318db4278
SHA1: 242670bd274b29f75ceedc6ae0265e974669e39a
SHA256: 5DB8E9CFFC51446F3BC023DEE859C8F267FE1CC9FD4909B18E551B1B81482CD6
File Size: 514.05 KB, 514048 bytes
MD5: 7e59ac7e771c6670b1881e0ae2f3aebb
SHA1: 001e8dd1c2b87fb6fc5679fd72f4f8027ad95600
SHA256: 18082CB397A450FC50C3674C34E3A85520E12DF4A108795D7DE354C4C560EF56
File Size: 78.34 KB, 78336 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version
  • 1.4.0.0
  • 1.0.0.0
Comments
  • iKeyMonitor Uninstaller
  • Payload for Divulge Stealer
File Description
  • Divulge Stealer Payload
  • iKeyMonitor Uninstaller
  • Quasar Client
  • Systems
File Version
  • 1.4.0
  • 1.0.0.0
Internal Name
  • Client.exe
  • Divulge.payload.exe
  • Systemss.exe
  • Uninstaller.exe
Legal Copyright
  • Copyright © 2023
  • Copyright © 2025
  • Copyright © MaxXor 2020
  • Copyright © PyDevOG 2023
Original Filename
  • Client.exe
  • Divulge.payload.exe
  • Systemss.exe
  • Uninstaller.exe
Product Name
  • Divulge.payload
  • iKeyMonitor Uninstaller
  • Quasar
  • Systems
Product Version
  • 1.4.0
  • 1.0.0.0

File Traits

  • .NET
  • CryptUnprotectData
  • Installer Version
  • No CryptProtectData
  • RijndaelManaged
  • Run
  • Stealer
  • x86

Block Information

Total Blocks: 231
Potentially Malicious Blocks: 190
Whitelisted Blocks: 38
Unknown Blocks: 3

Visual Map

? x x x 0 x x x x x x x x x x x x x x x x 0 0 0 x x x x x x 0 x x 0 x x x x x x x x x x x 0 x 0 x x 0 x x x x x x x x x x x x x x x x x x x x x 0 0 0 0 0 0 0 x x x x x x 0 x x x x 0 x x x x x x x x x 0 x x x x x x x x x x x ? x x x x x x 0 x x x x x x x x x x x x x x x x 0 0 0 x x x x x x 0 x x 0 x x x x x x x x x x x 0 x 0 x x 0 x x x x x x x x x x x x x x x x x x x x x 0 0 0 0 0 0 0 x x x x x x 0 x x x x 0 x x x x x x x x x 0 x x x x x x x x x x x ? x x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Spy.HB
  • MSIL.Stealer.AVB

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows nt\currentversion\windows::appinit_dlls RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\windows::loadappinit_dlls RegNtPreCreateKey
HKLM\software\microsoft\windows\currentversion\policies\explorer\run::es32 RegNtPreCreateKey
HKLM\software\microsoft\windows\currentversion\policies\explorer\run::es64 RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateKey
Show More
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtDeleteValueKey
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtPowerInformation
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateNameInformation
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetSystemInformation
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtTraceEvent
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtUpdateWnfStateData
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtYieldExecution
  • UNKNOWN
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
Encryption Used
  • BCryptOpenAlgorithmProvider
Other Suspicious
  • AdjustTokenPrivileges

Related Posts

Trending

Most Viewed

Loading...