Trojan.MSIL.Agent.ASC
Threat Scorecard
EnigmaSoft Threat Scorecard
EnigmaSoft Threat Scorecards are assessment reports for different malware threats which have been collected and analyzed by our research team. EnigmaSoft Threat Scorecards evaluate and rank threats using several metrics including real-world and potential risk factors, trends, frequency, prevalence, and persistence. EnigmaSoft Threat Scorecards are updated regularly based on our research data and metrics and are useful for a wide range of computer users, from end users seeking solutions to remove malware from their systems to security experts analyzing threats.
EnigmaSoft Threat Scorecards display a variety of useful information, including:
Popularity Rank: The ranking of a particular threat in EnigmaSoft’s Threat Database.
Severity Level: The determined severity level of an object, represented numerically, based on our risk modeling process and research, as explained in our Threat Assessment Criteria.
Infected Computers: The number of confirmed and suspected cases of a particular threat detected on infected computers as reported by SpyHunter.
See also Threat Assessment Criteria.
| Popularity Rank: | 2,681 |
| Threat Level: | 80 % (High) |
| Infected Computers: | 686 |
| First Seen: | October 24, 2022 |
| Last Seen: | July 27, 2026 |
| OS(es) Affected: | Windows |
The detection of Trojan.MSIL.Agent.ASC on your system indicates a potential security threat that requires immediate attention. This report aims to provide you with a comprehensive understanding of the threat, its operational methods, symptoms of infection, and most importantly, steps to remove it from your system.
Table of Contents
What Is Trojan.MSIL.Agent.ASC?
Trojan.MSIL.Agent.ASC is identified as a Trojan-type threat. Trojans are malicious programs that can cause significant harm to your computer system. They are designed to allow unauthorized access to your system, steal sensitive information, or disrupt system operations. The name suggests it's written in MSIL (Microsoft Intermediate Language), which is a platform-agnostic intermediate representation of the.NET Common Language Infrastructure (CLI). This allows the Trojan to potentially operate on various systems that support.NET frameworks.
How Trojan.MSIL.Agent.ASC Operates
Trojan.MSIL.Agent.ASC, like other Trojans, operates by disguising itself as a legitimate program or file to deceive users into installing it on their systems. Once installed, it can create backdoors for remote access, allowing attackers to control the infected system. This can lead to a range of malicious activities, including data theft, installation of additional malware, or using the system as part of a botnet for spamming or DDoS attacks. The specific operations of Trojan.MSIL.Agent.ASC can vary, but its primary goal is to compromise system security and user privacy.
Symptoms of Infection
Identifying a Trojan infection can be challenging due to its stealthy nature. However, some common symptoms include unusual system behavior, such as slow performance, frequent crashes, or unfamiliar programs and icons appearing on your desktop. You might also notice increased network activity, even when you're not using your internet connection, or receive notifications from your security software indicating malware activity. Sometimes, Trojans can operate without noticeable symptoms, making regular system scans crucial for detection.
How to Remove Trojan.MSIL.Agent.ASC
- Boot into Safe Mode with Networking: This will limit the Trojan's ability to operate and allow you to perform removal steps without interference. Restart your computer, and as it boots up, press the F8 key repeatedly until you see the Advanced Boot Options menu. Select Safe Mode with Networking.
- Perform a Full Scan with a Reputable Tool: Utilize a reputable anti-malware tool, such as SpyHunter, to scan your system thoroughly. Ensure your antivirus and anti-malware software are updated with the latest definitions before scanning.
- Uninstall Suspicious Programs: Go through your installed programs and uninstall any that you don't recognize or that were installed around the time your system became infected.
- Reset Your Browsers: Trojans can affect your browsers, so resetting them can help remove any malicious settings or extensions. For Chrome, Firefox, and Edge, you can find reset options in their settings or preferences menus.
- Reboot and Re-scan: After completing the above steps, reboot your system in normal mode and perform another full scan to ensure the Trojan has been completely removed.
Conclusion
Removing Trojan.MSIL.Agent.ASC requires careful and systematic steps to ensure your system's security and integrity are restored. It's crucial to stay vigilant and maintain good security practices to prevent future infections, including keeping your operating system and software up to date, using strong antivirus software, and being cautious with emails and downloads from unknown sources. By following the guidance provided, you should be able to remove the Trojan and protect your system from similar threats in the future.
Analysis Report
General information
| Family Name: | Trojan.MSIL.Agent.ASC |
|---|---|
| Signature status: | No Signature |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
512fba0e45bdaff7751e98259b7fc60a
SHA1:
12a3c8467085c6d88cf0b8b2978ddb6de964ec23
SHA256:
A89F0597DC16911AF7F6A65A7873C1B8550167D4F56BA21998DF6896A721F5CF
File Size:
22.02 KB, 22016 bytes
|
|
MD5:
b1b1821e0c0602bc0b105ac1adec9ee5
SHA1:
ecb99f5bda33984335b2104f15492e72bd46db56
SHA256:
F0531D00E82BCFC5751B212F4E95758767F84980E35FD09338122974D62202C5
File Size:
23.04 KB, 23040 bytes
|
|
MD5:
8375f3c68fa79586de08ffb9911cf4cd
SHA1:
b0311d1af17a98518dc5c21c0f5921114e6a5933
SHA256:
AE7CF1B2C3DDAA272B55BD74642983AE80EC85CBEDD75E4AD00C4EE139E1E90D
File Size:
15.36 KB, 15360 bytes
|
|
MD5:
991ffadefc1da0f8880bfc37cae80701
SHA1:
0275792a4641da67f1684ae3bd623fad0588dcd9
SHA256:
B83E59449D17A5A51181669BE0F227951EADF690AF37B567A39D3905E1E931C8
File Size:
57.34 KB, 57344 bytes
|
|
MD5:
061c00d5a89797def413c44de2d352d1
SHA1:
bd68db8f43488a3ee19d13c5bc2508ba9113078f
SHA256:
172742ACA117A40A3C3C03D557372B49A12959053EAEFF3C2CA13A7AFCE6E878
File Size:
61.44 KB, 61440 bytes
|
Show More
|
MD5:
602667f226480679a4f66676dccb1754
SHA1:
31cd67fb5f26468eb0bd9fd15d48e45c66875bfe
SHA256:
571627356B6219D116805974345693B90EF5301917F9681FC4DAA34E2B781B53
File Size:
11.26 KB, 11264 bytes
|
|
MD5:
e756ef8191a753b973ae15217cf17a1b
SHA1:
637fcdbc9ccd833827ef2a9284f71a0884d81739
SHA256:
1061A8B8F308AB59EB120823FEE57D20EE5A2DEDE1D5E7CFAFA104D17A8EFEE2
File Size:
24.06 KB, 24064 bytes
|
|
MD5:
9a73f73f2ab3ce39eb27f64d76153531
SHA1:
00bde344a7def67f0b06a61070daaad7cd181458
SHA256:
59349BD42733B478B402B4F9386583746BFF01960ADA6AF3F88E6E21C0E5279E
File Size:
71.68 KB, 71680 bytes
|
|
MD5:
ca09108b5c119b226a86b97c6d62a893
SHA1:
b87e3f2fdbcd9e00dba5321fc9cd367d92a95ce3
SHA256:
6E32B2D2A1DAA7394E824B2E0D13426095C0200F91C388DB7D0D48FFA7D458AF
File Size:
50.18 KB, 50176 bytes
|
|
MD5:
cb1654f97f6f8ecb620ef25981d4528b
SHA1:
064c9bd804bf9802dfe2eb881d860de3d74cc632
SHA256:
44C102E5D468985C50D1BBC290DB22C9371EC0F7DCF726D0BF3B19390120DB04
File Size:
198.14 KB, 198144 bytes
|
|
MD5:
cd913da9047bb2a2ea48d6a79f57e29d
SHA1:
13a6fd48b4d6d271b9de1b1407f50d10b7ba1218
SHA256:
6A919AD74C14870B1AB5888FA7A96C74ECC2AF1A1BBBB8E7E6E3F267D3B33D3D
File Size:
14.34 KB, 14336 bytes
|
|
MD5:
0ec80c2c82fda27d8cb43906920929be
SHA1:
b31edf236e8e8ffa1ae34a73e7f7b0409cc6337c
SHA256:
D85847904CFEA208EFD890FDE54F940F9186899B374F240394E4F6A0031937F8
File Size:
32.77 KB, 32768 bytes
|
|
MD5:
445ccab5cdb970bbce878bbb989c374f
SHA1:
6c5ceaacf8532b9dfc94a3c8ee946f25f0a47ebc
SHA256:
A67ECDB70C3558435BBDC9B4CAD63DB4024255B3A95A8107E3A66876E16EE8C3
File Size:
391.17 KB, 391168 bytes
|
|
MD5:
98fed55c99ffb9592b673cea9f7ec3c3
SHA1:
b121ac5f7074f12032f90916b073150d6ad7cd03
SHA256:
CF66F2EE294862E127ACEA77F06712599F589B60D6AC547E773067D1A1C3958C
File Size:
8.19 KB, 8192 bytes
|
|
MD5:
f2e71be559cea413a8f9f6bf54807f2d
SHA1:
624bdb2d85499dc07d7393afa06e970ab276983c
SHA256:
2B7C8F9CD42769061A91E0A16C750486A38CAD5D926F23650CD6BF7ACD085D1A
File Size:
7.68 KB, 7680 bytes
|
|
MD5:
5bd59098abda414376b52bcef5c28224
SHA1:
a5e5ce560fe952d7cc65cba4c949891527d5be9d
SHA256:
8D5650A4EC64CAFA70117E1FE3F200695ACEF11C8F1531779C06CDAC14123D54
File Size:
32.77 KB, 32768 bytes
|
|
MD5:
1f7eb6d4d586be7b1b5ec44243b439fb
SHA1:
91dcab02a92a64b411a06e7d2696dc8ee8d63e2f
SHA256:
B84E67877AD1B8A250ABCB50AE18BA98F0719EAB639B3EE034F94A5E1F874D61
File Size:
305.66 KB, 305664 bytes
|
|
MD5:
161dc4f7cf08d1ba96a65f9f7dd7d7ed
SHA1:
050d8e52c950680e0fcf106dbea1104f29187154
SHA256:
81614E805052B79325067A42A1B8E942C80250A196C5EC76A66BD620CCBA814B
File Size:
32.77 KB, 32768 bytes
|
|
MD5:
84e265febad37591ff5882b0a626e827
SHA1:
325153643905cdcf08dd2261316396a0ea375cda
SHA256:
98D8866857C555557B1046361D9998BCB6577A91DB7F4CD5960E2E0609E45061
File Size:
32.77 KB, 32768 bytes
|
|
MD5:
e67f8bbed23ce3decf44644793fe0fdc
SHA1:
2cf25509f747a2900e3e1fe06b2592d0fffe3038
SHA256:
29CAB1A4DCD48D107AF8D7C5E5EE25CB7492AF7D4AF31A70E6D736F85A47B66D
File Size:
14.34 KB, 14336 bytes
|
|
MD5:
3c2205717ab0e6abbb4e919a2a6c07ca
SHA1:
e3f2c55e3e7b09b90366ea62f2e04b4ef7667f8e
SHA256:
DB92FF36BD8F230422E9EA768139E72244812FA09F480A897F98F09825EC79B1
File Size:
7.68 KB, 7680 bytes
|
|
MD5:
c2a1157f627c0b709b3c73e13e3300ec
SHA1:
8f213e6f9e93bf9788342bfb1ef9e02156510553
SHA256:
5CA75724BEF33E9035EC611461F33F7EA597390B7EFCACA5B79AA92958BE70A6
File Size:
7.68 KB, 7680 bytes
|
|
MD5:
c930e7a2f7805c75b7f3527180ff10cc
SHA1:
675bb0ed91429e1d376d80b7cea8568c7f9a74f6
SHA256:
4AC49EA3EA6276DA03F7325FC99673469C29C71E4911619E3022989FA43CEE3B
File Size:
14.34 KB, 14336 bytes
|
|
MD5:
e98dc4ce683d9ce49bb35b87970f496e
SHA1:
363f132bebc682ebe27fcac8b2838bc264a3d714
SHA256:
CA6785BAD5B1CA7605F1901D17296589751FD473D9A3961E8AE89A06C7F88249
File Size:
14.85 KB, 14848 bytes
|
|
MD5:
fec881b7e8150e9aaee96787a94cea39
SHA1:
40332e09fa151647294ed6fdfbc3b39b62fe2ccd
SHA256:
5B752B357A05F38E22F2A68B2F81679D3D4F53D706895FDAB6FFFEF6EDC23DC4
File Size:
14.34 KB, 14336 bytes
|
|
MD5:
c14152b1ced6bf04dac7149fd80307eb
SHA1:
7a50e827d709ce4a6986e2c1285ad1feb435d4a1
SHA256:
9A4479DDFE6E87AB909A20A40FD7E9851EE70BB13DBE704C53563495FE067153
File Size:
14.34 KB, 14336 bytes
|
|
MD5:
c129a244a60a53381307bcbad1f50c69
SHA1:
d2cdd31cbe05d99c87b446cf21d16704b5276da8
SHA256:
3280DF5F635AB738A442426589A7D1390A515211BC92BE86382995A34967BB42
File Size:
7.68 KB, 7680 bytes
|
|
MD5:
ab2383a61fc1e85f37af1b4cc3c6cfb5
SHA1:
b005fa2e85b966194017205d94ac0baf7bbb1dc2
SHA256:
5FBEA952EC83E04454346A5F716E11090583C33234E1AEFC8B69333C05CD44FC
File Size:
32.77 KB, 32768 bytes
|
|
MD5:
e9ebbb90478196c94add175b9b110b2e
SHA1:
37890b7507054b0240ecea5500c899a0c7028d5f
SHA256:
AC7E27CF687DF4186946EF58A9B6B725D31685F17C5916814E711D13EB497E56
File Size:
14.34 KB, 14336 bytes
|
|
MD5:
1ec67be8ca8cd17f5d9d1271541d2803
SHA1:
514aeb80e2a5a1230c862b3aa449e1f452a10dac
SHA256:
C81C4F9C3ABA46047415A8ABA61D8A0B5B299992430F246B684BFEB588F7A31A
File Size:
14.34 KB, 14336 bytes
|
|
MD5:
c749c9c9563224d5d5369ca4582d67ab
SHA1:
a5f87dcba5c7dcf8f5389858ce96b257a57194ea
SHA256:
B924D96CAB7BBC653FA0DF77460D3AA866CEC52F758223D2CE18FDB473A8E6BC
File Size:
6.14 KB, 6144 bytes
|
|
MD5:
eb98d712bf14b144bcb338025553633b
SHA1:
e7be2abc698d806c00a705cfe4fa4743a9747f56
SHA256:
4EE28D4CB3E50B135865CFDE4039B82A46D6195782966BBFFB1F3F76759AC046
File Size:
32.77 KB, 32768 bytes
|
|
MD5:
74d22e4c39736dfccc7327dc2e35a847
SHA1:
119abfdb1e1cbadf068c844f42286cceccb6c978
SHA256:
4916384D5989CAD8CD2CE6749BC23A59E91D93CB83093DE519A2025E9E4C573A
File Size:
312.32 KB, 312320 bytes
|
|
MD5:
e0355cddedb9e5bf67ddc64c5f516ef5
SHA1:
361bd006a958a645d9b093f8fe87be98d0d480b3
SHA256:
025C04396C04A054826EA81745415A6582DE646BDE14614C4F16882D5C272495
File Size:
14.34 KB, 14336 bytes
|
|
MD5:
c1f4f503d82ab923192d287f2a6132bf
SHA1:
666bf79014a04cef9058e2a4d49bc83fc9b5d160
SHA256:
F9B1CD216E6850CC8BBF6BE027949A7F8F01DFA6DCD18ED0E65ACC26AA151D44
File Size:
14.34 KB, 14336 bytes
|
|
MD5:
114a11c6251d4eea843bbb1a43ff9a90
SHA1:
e4ca455883ef523026aca31e95ebc3065dbc9382
SHA256:
8D4BBC58A24B22FE6B634672ECB4C168CEA7B679260133BC5B28AA16F258BFF8
File Size:
331.78 KB, 331776 bytes
|
|
MD5:
3dfed2d21eca7bf2ff12b766f9bbc533
SHA1:
0ff9618f418264c080066ddb6c630fb4c3a7cbc1
SHA256:
0E7412E0CC7047FD025B9CE4683E973A899DFA62B8B26A7D26F775766672EC10
File Size:
14.34 KB, 14336 bytes
|
|
MD5:
55f6143f4d314002e4fd0b3ec8b1e02a
SHA1:
ca2a3dd0b521d9fdcb6dc27fee3f233d5f182037
SHA256:
B2A2D72B655A64C3B1471FB96FD377892400A746095EF55C8BA2D585074539E6
File Size:
329.73 KB, 329728 bytes
|
|
MD5:
66ed800ae15d953cbdeb7e886c3b233f
SHA1:
7c311fd7947bc04dfd9801126f83ccbf0bf921e0
SHA256:
08D13FBE96EBF82A088A54D4EBE0966F8FB3984361EC2EA3CAD6E4B5C81F4C25
File Size:
32.77 KB, 32768 bytes
|
|
MD5:
cae300faaf79fb59a765740073cdb35b
SHA1:
bc2ca0dd76f64a31d2bb4e4d5ba9a765a3a26b42
SHA256:
F84934CEC4DEEDC2FCE85638A3A72F66921F4F107276D507A52CCB824C5327E0
File Size:
394.75 KB, 394752 bytes
|
|
MD5:
834b0996a035c86ed4284ef351c7ebcd
SHA1:
9e92974c5dcf442c733201d4c33a5d8dcc8b8f93
SHA256:
FC36E4515C4B90776B32689558B03BD11AA1162C755DD3CF8E86502FF5631D24
File Size:
14.34 KB, 14336 bytes
|
|
MD5:
e9be5862199fb8e9b02eda052ff85748
SHA1:
b61b6cb96ff657aa1b70bd6b58acf5371b0b076f
SHA256:
0A5EED6EFE6DE16432A9DC36E18C3C359FD9F0529E68B7FD645CB0D87BF44EF3
File Size:
40.45 KB, 40448 bytes
|
|
MD5:
cdc7165a1019a613997e25284a331add
SHA1:
1b581e184c153a2bc9aad11d9c4ec8f112901265
SHA256:
835A4169BECA64404AF73E64F69FCA998007192F89637FE4AEDFE8F22AEE5388
File Size:
14.34 KB, 14336 bytes
|
|
MD5:
0e8a3b43f91d94abee5ff02ea6d77e6c
SHA1:
74b91828120729962c6c3847c1cec0e89254fb1e
SHA256:
018CF6DBCAF5ECBD152232EB47C41FF8FF83757C55F36D6346C7DF28B22A7A9E
File Size:
94.21 KB, 94208 bytes
|
|
MD5:
73950abc6946dc18d5197b62d259a74a
SHA1:
0018b36389742738327b9df3968dcbad5da2a7b7
SHA256:
798B2134703484F7B8E5716A5F63C7130E802EA87C25804546F0332E99F05AA4
File Size:
389.63 KB, 389632 bytes
|
|
MD5:
8101b0396d3a2ca38fd3a37168594c67
SHA1:
5ee3cbc3967543da74af810120c8826bcb513e56
SHA256:
101F166FB67568177844A062CAC5D0242E409089D37B35FB1C6A94821B034D8D
File Size:
14.34 KB, 14336 bytes
|
|
MD5:
eaff1b1ff97b64e0b0d33139d8c2f895
SHA1:
3b21743812a7079a5df1c8a09ae7c1735dfe8562
SHA256:
70F864555408AF144549F2FC230B85A7BB9FEB26F0C4DE9DB65A25C2933BC3AE
File Size:
356.86 KB, 356864 bytes
|
|
MD5:
31e3f4eb405fcaa6ce8c3406aa2d17a8
SHA1:
776a302145a8deb1cb7449b45cfa73118083a728
SHA256:
906955468936392292CBB65ED5B518C3E67E6DACCEF9281BC9DFAE4FC8814CF9
File Size:
32.77 KB, 32768 bytes
|
|
MD5:
650d6438c9cfbc77a8440472493df37e
SHA1:
51923243171273a1aa0cbfe903919ce934aaabb8
SHA256:
4690B5998B371B017C0E1E3B1EE81326A7FD54B87BCF9E9B16703C53163F0D35
File Size:
59.39 KB, 59392 bytes
|
|
MD5:
ae7add0b6e9ff154a9a1dd3fc5a8ad5c
SHA1:
b84e2536d42e70b56196522eedc636150485d48d
SHA256:
6CBBA79A02C09501397E80B32C0AFCA5DCE5C1A7342AB41719735541C06021CD
File Size:
361.98 KB, 361984 bytes
|
|
MD5:
3ad858361837ef886eaf9dfd3f584bd8
SHA1:
ab23354c8585403bd1358a1097c70520031f8bfd
SHA256:
D747F9CFC433BCE8F5DFE80E5433FCC06B32C34F1DA946D49E95216A05F3597D
File Size:
37.89 KB, 37888 bytes
|
|
MD5:
61e4f33eca52d49e90caaa13fd62ab3e
SHA1:
152a6928cf0012b3ad8c86e9ba704e80527902cf
SHA256:
0A35185E7049B5629E7984F9BA268D5A5F93FE2DF0736362B96CC14E2271A526
File Size:
17.92 KB, 17920 bytes
|
|
MD5:
b6f07771a8fa18d1cd805394280856b8
SHA1:
717843c44bfad909fec7bb3f00bb300afa79894e
SHA256:
9021F50C1741BFD922BCD23FCE96E64E45F81E23F91E94B26804A03C9FC758B3
File Size:
32.77 KB, 32768 bytes
|
|
MD5:
782553184602c348dae01d9c73d84049
SHA1:
edf09d16747e7b04f13eec3f5a82433acd9495da
SHA256:
FAEE912A8714153295FDCB0C0B736AA628B8344E11DB6E0DD187C0E9785C1812
File Size:
14.34 KB, 14336 bytes
|
|
MD5:
6fb25240f1ef94e4cefff13262bb0de5
SHA1:
b6962fb5480f376952d4e37de43ed110673781ad
SHA256:
7B9EDCBB568DC8031877F5E4F289BC0666FEA909D55D9056C5C4B8D5675E25FF
File Size:
14.34 KB, 14336 bytes
|
|
MD5:
11ab844d409507ad215ac9e236d839b6
SHA1:
82c859f4104ad379204e9ed1d50f0e3ea5288c3d
SHA256:
2A4137DA9C64ACCC882822E3917F0DF29BE4524331AD83C022E3728B0E370E9C
File Size:
41.98 KB, 41984 bytes
|
|
MD5:
51def4a3662c46b376e52fe68aebea48
SHA1:
28a7ea31b05c2ff115f3c9bfaf359b9922a96f96
SHA256:
97C5B45EFCDDB391B74B8C409584D950D9184AA1643213398BC8283D5FC37A01
File Size:
111.10 KB, 111104 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have exports table
- File doesn't have security information
- File is .NET application
- File is 32-bit executable
- File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
- File is either console or GUI application
- File is not packed
- IMAGE_FILE_DLL is not set inside PE header (Executable)
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
Windows PE Version Information
Windows PE Version Information
This section displays values and attributes that have been set in the Windows file version information data structure for samples within this family. To mislead users, malware actors often add fake version information mimicking legitimate software.| Name | Value |
|---|---|
| Assembly Version | 0.0.0.0 |
| File Version | 0.0.0.0 |
| Internal Name |
Show More
|
| Original Filename |
Show More
|
| Product Version | 0.0.0.0 |
File Traits
- .NET
- dll
- x86
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 147 |
|---|---|
| Potentially Malicious Blocks: | 73 |
| Whitelisted Blocks: | 27 |
| Unknown Blocks: | 47 |
Visual Map
? - Unknown Block
x - Potentially Malicious Block
Similar Families
Similar Families
This section lists other families that share similarities with this family, based on EnigmaSoft’s analysis. Many malware families are created from the same malware toolkits and use the same packing and encryption techniques but uniquely extend functionality. Similar families may also share source code, attributes, icons, subcomponents, compromised and/or invalid digital signatures, and network characteristics. Researchers leverage these similarities to rapidly and effectively triage file samples and extend malware detection rules.- MSIL.Agent.SFC
- MSIL.Webshell.AA
- MSIL.Webshell.BAE
- MSIL.Webshell.BD
- MSIL.Webshell.BT
Show More
- MSIL.Webshell.BV
- MSIL.Webshell.CD
- MSIL.Webshell.D
Registry Modifications
Registry Modifications
This section lists registry keys and values that were created, modified and/or deleted by samples in this family. Windows Registry activity can provide valuable insight into malware functionality. Additionally, malware often creates registry values to allow itself to automatically start and indefinitely persist after an initial infection has compromised the system.| Key::Value | Data | API Name |
|---|---|---|
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | �m �v����(�1�1HO @V� _�zb"hi��k�qrnJ u�~ {b��P� ��� ������m� �� ����$�8წ����o �=�SB1_ T�Vw���%������ �AE�Q] ��D��&��$���L | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | �m " |