Threat Database Stealers Trojan.MSIL.Stealer.L

Trojan.MSIL.Stealer.L

By CagedTech in Stealers, Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 9,207
First Seen: December 21, 2021
Last Seen: March 18, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Stealer.L indicates that your system has been compromised by a potentially malicious program. This type of threat is designed to infiltrate and gather sensitive information from your computer, posing a significant risk to your personal data and online security. It is essential to understand the nature of this threat and take immediate action to remove it from your system.

What Is Trojan.MSIL.Stealer.L?

Trojan.MSIL.Stealer.L is a type of Trojan horse malware that is designed to steal sensitive information from infected computers. The name suggests that it is a malicious program written in MSIL (Microsoft Intermediate Language), which is a platform-agnostic intermediate representation of.NET code. This type of malware can be particularly dangerous, as it can be used to steal a wide range of sensitive information, including login credentials, financial data, and personal identifiable information.

How Trojan.MSIL.Stealer.L Operates

Trojan.MSIL.Stealer.L operates by infiltrating a computer system and establishing a connection with its command and control server. Once connected, the malware can receive instructions from its creators, allowing them to steal sensitive information, install additional malware, or take control of the infected system. The malware may also use various techniques to evade detection, such as encrypting its communications or disguising itself as a legitimate program.

Symptoms of Infection

Systems infected with Trojan.MSIL.Stealer.L may exhibit a range of symptoms, including unusual network activity, slow system performance, and unexplained changes to system settings. You may also notice that your browser is being redirected to unfamiliar websites, or that your login credentials are being stolen. In some cases, the malware may also cause your system to crash or become unresponsive.

  • Unexplained changes to system settings or browser configurations
  • Unusual network activity, such as unexpected outgoing connections
  • Slow system performance or frequent crashes
  • Unfamiliar programs or icons appearing on your system

How to Remove Trojan.MSIL.Stealer.L

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow you to download and install removal tools
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove the malware
  3. Uninstall any suspicious programs or applications that may be related to the malware
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons
  5. Reboot your system and perform a follow-up scan to ensure that the malware has been completely removed

Conclusion

Removing Trojan.MSIL.Stealer.L from your system requires immediate attention and a comprehensive approach. By following the steps outlined above, you can help to ensure that your system is thoroughly cleaned and that your sensitive information is protected. It is also essential to take proactive measures to prevent future infections, such as keeping your operating system and software up to date, using strong antivirus software, and being cautious when opening email attachments or downloading files from the internet. By taking these steps, you can help to protect your system and your personal data from the risks associated with Trojan.MSIL.Stealer.L and other types of malware.

Analysis Report

General information

Family Name: Trojan.MSIL.Stealer.L
Signature status: Hash Mismatch

Known Samples

MD5: 84a7213a0907ff10d3fc06429637c39b
SHA1: 7deb0984d18603173b82ec2913b78aa5eb582974
File Size: 1.79 MB, 1789248 bytes
MD5: 4a4f6edf3b4b321353a97c7627a9c36a
SHA1: ea9174a95b1812f6f8f452f39e75c914b566749e
SHA256: 81AA69CCA2D48908D212944402A6CF6BA202B47FF855ED7B6ABEB15B5CE099DE
File Size: 569.34 KB, 569344 bytes
MD5: bb753fdfe74f35814d51093d47fe2bc7
SHA1: 24a2a1fdb95fb0c705e5cde7d9e3cb12a0a06c84
SHA256: 484D46EFDC250C5CC1C4BCBAEBE39E2F3A3AB35225DE38E54C420E0A5A580C0C
File Size: 906.56 KB, 906560 bytes
MD5: 9ef66628c3c952ce92e8ddeeb1d7eaa3
SHA1: f215fc9cde636e4fa3fa9e17e479e6b8b8cadff1
SHA256: 9D0C9AA7A404232EE2AA3840A8C7D10925D3C56E794FB1FC663FCBE3B7A82CC1
File Size: 1.54 MB, 1535480 bytes
MD5: c0ff5df3aba4b3ff7de1ba8f2ca6e889
SHA1: 939c80b546f5913a72192a132c61a98349b98d97
SHA256: F3959EA809FAB649143DCAC043C29883949581EB346AD971A5860D166DCE8016
File Size: 1.31 MB, 1313792 bytes
Show More
MD5: af9e941533661388d6753acd4b01835e
SHA1: a7a3cc3c777a1e7072468eeed066e2fa579fa8bf
SHA256: 649B3A14F8EE509E9FE9D5FA9005C54B097EACD4D1DB6DD5CF5AA5EFDA139286
File Size: 414.02 KB, 414016 bytes
MD5: b3b0d320da6beed2b920d482aa22ff70
SHA1: 21a08244f0566029b440a164a0bccdb118b5d849
SHA256: 1ABEC3EA75FA09082C5F5B2E1FB83E6FF8BB1E1D6DFEAACCAA1EAA8F94482BBA
File Size: 487.94 KB, 487936 bytes
MD5: c38fb3d549afdfd4c9979cf97fbda2b5
SHA1: d7cdc99e83c1470907b14b49764bd36ed2387642
SHA256: 90AD3FB7B8D1C426EDF2E713C07E383229511493754324C6F926AD2088B608E5
File Size: 415.86 KB, 415856 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
Show More
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 9.2.1.2
  • 3.5.6.0
  • 1.0.0.3
  • 1.0.0.0
Comments
  • eFootball No Crowd & FPS unlocking
  • Install
Company Name
  • Ahmed Suror
  • Install
File Description
  • Chicken
  • Corbie
  • Digital
  • eFootball No Crowd & FPS unlocking
  • Install
  • Purpose
File Version
  • 4.0.1.2
  • 3.6.0.0
  • 1.0.0.3
  • 1.0.0.0
Internal Name
  • Chicken.exe
  • Digital.exe
  • eFootballPatcher.exe
  • Install.exe
  • Paradise.exe
  • Purpose.exe
Legal Copyright
  • Copyright © 2023
  • Copyright © 2025
  • Copyright © 2029
  • Copyright © Ahmed Suror 2009 - 2024
Legal Trademarks
  • AS
  • Install
Original Filename
  • Chicken.exe
  • Digital.exe
  • eFootballPatcher.exe
  • Install.exe
  • Paradise.exe
  • Purpose.exe
Product Name
  • Chicken
  • Corbie
  • Digital
  • eFootball Patcher
  • Install
  • Purpose
Product Version
  • 4.0.1.2
  • 3.6-build20
  • 1.0.0.3
  • 1.0.0.0

Digital Signatures

Signer Root Status
NetEase (Hangzhou) Network Co., Ltd DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Hash Mismatch
Microsoft Corporation Microsoft Code Signing PCA 2010 Hash Mismatch
Microsoft Corporation Microsoft Code Signing PCA 2011 Hash Mismatch

File Traits

  • .NET
  • CreateThread
  • GenKrypt
  • HighEntropy
  • Installer Version
  • No Version Info
  • Reactor
  • Reflective
  • RijndaelManaged
  • x64
Show More
  • x86

Block Information

Total Blocks: 58
Potentially Malicious Blocks: 4
Whitelisted Blocks: 54
Unknown Blocks: 0

Visual Map

0 x 0 0 x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Agent.LOD
  • MSIL.Agent.ONR
  • MSIL.Agent.XFB
  • MSIL.Agent.XY
  • MSIL.AgentTesla.DH
Show More
  • MSIL.AgentTesla.LP
  • MSIL.AgentTesla.PH
  • MSIL.Bladabindi.LB
  • MSIL.Bladabindi.LE
  • MSIL.Coinminer.AH
  • MSIL.DllInject.Z
  • MSIL.Downloader.PFA
  • MSIL.Downloader.PFB
  • MSIL.Dropper.XC
  • MSIL.Krypt.D
  • MSIL.Krypt.GJLD
  • MSIL.Krypt.MJC
  • MSIL.Krypt.MJG
  • MSIL.Krypt.OFB
  • MSIL.Krypt.POB
  • MSIL.Kryptik.SA
  • MSIL.Mardom.AJ
  • MSIL.Mardom.JG
  • MSIL.Mardom.TJA
  • MSIL.Mardom.TK
  • MSIL.Quasar.I
  • MSIL.Redline.AR
  • MSIL.Stealer.KU
  • MSIL.Ursu.TJG

Files Modified

File Attributes
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\3acf660917f73e764d4410bf1eaa48f5 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\fee33ce020c970ea56929081c2d05808 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\3acf660917f73e764d4410bf1eaa48f5 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\fee33ce020c970ea56929081c2d05808 Generic Read,Write Data,Write Attributes,Write extended,Append data

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\systemcertificates\ca\certificates\be68d0adaa2345b48e507320b695d386080e5b25::blob �hЭ�#E��Ps ��ӆ[%;p�S�v%�`��fƛ�oTj�ӂA�G g\`f��0b��ܣ��m;�r&m D̟[�]� 7��qd���b�I[ �] n\;W ˋY�WP��'��V\ý5I�"Z��74���� �0��0��� �n• RegNtPreCreateKey
HKCU\software\microsoft\systemcertificates\ca\certificates\31600991ed5fec63d355a5484a6dcc787ead89bc::blob 1` ��_�c�U�HJm�x~����~/���J�p[�ߚ���a��P����1p�X_h[0��%�O�;5D�Ԩ�h�Z�Ͻ�'L��{���wI>�x0+�n�٬�k��V_�o��%�m��\ý5I�"Z��74���� �0��0����~T~ RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\content::cacheprefix RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\cookies::cacheprefix Cookie: RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\history::cacheprefix Visited: RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey

Windows API Usage

Category API
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Process Terminate
  • TerminateProcess
Other Suspicious
  • AdjustTokenPrivileges
Process Manipulation Evasion
  • NtUnmapViewOfSection
Encryption Used
  • BCryptOpenAlgorithmProvider
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateThreadEx
Show More
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFlushProcessWriteBuffers
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForMultipleObjects
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtYieldExecution
  • UNKNOWN

Related Posts

Trending

Most Viewed

Loading...