Threat Database Trojans Trojan.MSIL.Webshell.BL

Trojan.MSIL.Webshell.BL

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 13,339
Threat Level: 80 % (High)
Infected Computers: 89
First Seen: January 2, 2024
Last Seen: July 28, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Webshell.BL on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the security of your computer, allowing unauthorized access and potentially leading to further malicious activities. It is essential to understand the nature of this threat and take prompt action to remove it and secure your system.

What Is Trojan.MSIL.Webshell.BL?

Trojan.MSIL.Webshell.BL is a type of Trojan horse malware that can infect a computer system, providing a backdoor for remote access by an attacker. The name suggests it may be related to webshell exploits, which are malicious scripts used to compromise web applications. Understanding the specifics of this malware is crucial for effective removal and prevention of future infections.

How Trojan.MSIL.Webshell.BL Operates

Trojan.MSIL.Webshell.BL, like other Trojan horses, operates by disguising itself as legitimate software or embedding itself within legitimate programs. Once installed, it can create a backdoor that allows hackers to access the infected system remotely. This access can be used for a variety of malicious purposes, including data theft, installation of additional malware, or using the compromised system as part of a botnet for distributed denial-of-service (DDoS) attacks or spamming.

Symptoms of Infection

Symptoms of a Trojan.MSIL.Webshell.BL infection can vary widely, depending on the specific goals of the malware and the actions taken by the attackers. Common signs include unexpected changes to system settings, unusual network activity, slow system performance, and the appearance of unfamiliar programs or files. In some cases, the infection may not exhibit obvious symptoms, making regular system monitoring and antivirus scans crucial for detection.

How to Remove Trojan.MSIL.Webshell.BL

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for easier removal. This mode starts Windows with a minimal set of drivers and services, reducing the chance of the malware interfering with the removal process.
  2. Perform a full scan of your system using a reputable antivirus tool, such as SpyHunter, to detect and remove all components of the Trojan.MSIL.Webshell.BL malware. Ensure your antivirus software is updated with the latest definitions before scanning.
  3. Uninstall any suspicious programs or applications that were installed around the time of the infection. Be cautious and only remove programs you are certain are malicious or unnecessary.
  4. Reset your web browsers (Google Chrome, Mozilla Firefox, Microsoft Edge, etc.) to their default settings. This can help remove any malicious extensions or settings changes made by the malware.
  5. After completing the above steps, reboot your computer and perform another full scan with your antivirus software to ensure all components of the malware have been removed.

Conclusion

Removing Trojan.MSIL.Webshell.BL requires a thorough approach to ensure all components of the malware are eliminated from your system. By following the steps outlined above and maintaining good cybersecurity practices, such as regularly updating your operating system and software, using strong antivirus protection, and being cautious with emails and downloads, you can help protect your system from future infections. Remember, prevention and vigilance are key to securing your digital environment.

Analysis Report

General information

Family Name: Trojan.MSIL.Webshell.BL
Signature status: No Signature

Known Samples

MD5: f76412ffe1bbeeeb775ec1139cf29e94
SHA1: 0b45cc831f41c876483346bf72582d286d5062f5
SHA256: 8E4B8D133A9A5A6A8951A8A64B2E01ABA3473FAEA876980458972FA3F154A492
File Size: 19.97 KB, 19968 bytes
MD5: 0437cd335feb6843444b1438e25f852e
SHA1: c707e1c06612ca86371d8e5c79a36c0d701cd303
SHA256: 742D74D87BFE1B9EAACC748EB30FD415BCF6B0150650C74DC3767C734E677102
File Size: 19.97 KB, 19968 bytes
MD5: 1fdb075326bb0fdec64f8e91938b24d3
SHA1: cf8a916dfe01f5e6b9ccbcb592232be2c0f67fec
SHA256: 5C57F6BB1B2645805632E0E83E040E605F61B871B7DE7A25B74309163FE44054
File Size: 59.90 KB, 59904 bytes
MD5: 20edd6a46ecda1155e2897aa410dd78e
SHA1: 2777c01e024bbf2e414a053355f1cdb3d58620f2
SHA256: 6D90B6481F73B6BE7AC1FBDBF10B4F51BD4BEA46DF6FCBFCAA1EA8D64CDE3305
File Size: 19.97 KB, 19968 bytes
MD5: 46c4b38c8a3c0eb167dd07ab11af049e
SHA1: c3c54cf7b3134894a2a8d95f516016843fac55ee
SHA256: 42D00C54647EDC03AF4D047B769AF85732EB86FD8BB81BF132CF3F27544D06C5
File Size: 19.97 KB, 19968 bytes
Show More
MD5: 5411b2cff204522ece8b62ef3974f42f
SHA1: 12eaad8b248149f6307bb8da68805fa0f879c021
SHA256: 6FB0A80B5B3F3600B05613DB8657F7A4438054FF747C89384B07B4329D4F23AF
File Size: 19.97 KB, 19968 bytes
MD5: 33bb6db5458245b3f41c488a5ea13f10
SHA1: f29119eafa93f415b36385c4a6dcb09ee8588c74
SHA256: AEC67E91AB46070A20F16A6851AE120988F043345110CA848FFF1DCB6C1C62A1
File Size: 20.48 KB, 20480 bytes
MD5: a8c834f4094425abac324ed4a8bde893
SHA1: 79266415e1f4310e304cf915ecdf32043a5309ed
SHA256: 9465B4A5538BF6D1BC9158CED861EEB9BA32CCC3FD2840FC18E06E5800DB2F19
File Size: 19.97 KB, 19968 bytes
MD5: 4d06510bb231b5ea0e63b3442970d8d1
SHA1: 4f706700f636ee8963699993cc7c40e24a469c97
SHA256: 562E98B4C97DB840FE36468A83B61BF3D0F3B4160FC76D5E627188EF6A4D5C62
File Size: 29.18 KB, 29184 bytes
MD5: ee9c57dfdf55c4c96d405090eab917f8
SHA1: e44a28d40444f91bff270a1adafc3e150888a30f
SHA256: 69A75BE90A216945EACFA9590F929F67F6F22F5C9C3E2E06012BF4845C98231C
File Size: 133.63 KB, 133632 bytes
MD5: 23225c48f8befc9dc464951f758adb15
SHA1: 63fcfa9e9e269ed651fa45d860fc08343bc10954
SHA256: C1F6B1ADAC04D634FB28F9AF242B3E545B230C7FEA18E85A6E0A3C44FE4DE164
File Size: 8.19 KB, 8192 bytes
MD5: 8c3ca4cd3797652aa36f50b688d2e268
SHA1: a12b13eabe445fa0ce91324c7551c70975e3a2d9
SHA256: D17B1843352DC9E07F81C7F12C5BB6E474D700A9B47FA004F8B1A53D77AEFED0
File Size: 19.97 KB, 19968 bytes
MD5: 4d14b0d39b73e5dbc620cd170cd1a2ef
SHA1: 1b1caf02945291f2931766df57d453453611d74a
SHA256: DFF530CD4C8BA84883BCA20F93FC4DC9ECD0B32A4AB4C680E4C48A5F6870FF17
File Size: 20.48 KB, 20480 bytes
MD5: d4beb355c632108768a6307b62a9a682
SHA1: c4c2900d920309bea9ddaf5362ce196e52ca22b3
SHA256: 83C6150D06141CB613969005A7DF686D9441FD2B178163504204A2AB4530C309
File Size: 19.97 KB, 19968 bytes
MD5: 2d58a04ba7a565abe523d03da03c17bc
SHA1: 49bbffac3e703bf38f85f9b315cddcdff5a5be19
SHA256: 850821E3A226E10B239702448684685FA3DC7918CE01F5C0D211728D5F70C3D1
File Size: 19.97 KB, 19968 bytes
MD5: 1f845393a2b7c6304ab38d036a4752b4
SHA1: f8cc34229d5936ce043b60cb7d28c9ba345ce454
SHA256: 48708C34661DC4E4936E67F0259800AC08FFB339671B73338EAE85384793CD6A
File Size: 19.97 KB, 19968 bytes
MD5: 7a365d153152bccd984c295a37eb8402
SHA1: fe7dbcfac5bad3ca03fc3580201c6eba421168ac
SHA256: 93A47C8269A428FE30D6591693ABFE150CEAD915773652ACDA7EA39E836AC88E
File Size: 70.66 KB, 70656 bytes
MD5: 22a564ad93e2eca7bd47a3bb2d7ba1f8
SHA1: 2e6d546f06dce68e7159d5492bd0b55c9f9856af
SHA256: 3F7929B4D731A052C799E6A0CDC0892F594C789D0A30F2F169CC3320FCA856D2
File Size: 19.97 KB, 19968 bytes
MD5: 7a25662ee5570fd982b7698ee495e8c2
SHA1: a8460f59e15d5b06f58bb9299672f62ef8d7d5d9
SHA256: 67130958F9AA555122628400AF8AF8F1B426ADC9B735A09565F8463E08797D53
File Size: 118.78 KB, 118784 bytes
MD5: 8b97bd5edc17376f37f16fe6c1cfadda
SHA1: d479e5595a8734e6e5f034e00bcf6b793de0db2b
SHA256: 84CF25161630D6D98438BC94482F446B75E45809777E329A2E397A29A7AF3E74
File Size: 78.85 KB, 78848 bytes
MD5: 00386e9d249e742fe5d683da38336e14
SHA1: 3dd2f7519661bcb162eb6c02caf353af6f83486b
SHA256: 1309612BDC101A22E6517E2A56EB16E9EBB696CF91929F018715F3B6F3B093E6
File Size: 19.97 KB, 19968 bytes
MD5: e584479145720be4f7e119502f2b0073
SHA1: 2c767f1aca907e34632d04f8621f556d554936de
SHA256: 8B931D16CDD807E95CB1E50361EE280C5088308771D6C305718208F8F39D4C36
File Size: 22.53 KB, 22528 bytes
MD5: 9d42998ca6c793be60d1e7cc664c4763
SHA1: ba38d5a70ec5460e5e8d32fffb0f9026cefafa72
SHA256: 5456388DC5684C60FECDD3C26F1025C61FEC0B36818CF9164EC2A7322EBCCDCC
File Size: 20.48 KB, 20480 bytes
MD5: da88927f78a5aca18469850a9a159d55
SHA1: 1b097c0d5336fdfe63569c8a8176fceb5f165502
SHA256: C9C2B047AE32F4BECD0EBC3C8A99E726D34E678EC82D5E8317AFA59BC8F72671
File Size: 19.97 KB, 19968 bytes
MD5: d3a58e958c875c064a3350ac16f1b93d
SHA1: af0dc07763a59630d655374a2c9c72c3f25f8bb9
SHA256: 1842D91283D72A3A9D97D8CE7A155DA3D6D6C01DDAA6C4A29C6ED76F1B9248B6
File Size: 8.70 KB, 8704 bytes
MD5: d38fc15b449166beafe8994254b5a9ce
SHA1: 7a8df7401775937ec26b53424820b97efa7103fd
SHA256: 7DE91366C8BDB06CD25E844B4B5F0210ED81DF312484E4F75A4A38B59DB2F292
File Size: 129.54 KB, 129536 bytes
MD5: dfeb31a15cfa3398c71cc85296953784
SHA1: 417c6f09d032620ae4a32c7d3e1140965472aa6b
SHA256: A9A77871D4B0A2ACC269A35503EF529B6B01743B86B450A3E6A078FC11910616
File Size: 123.39 KB, 123392 bytes
MD5: 6457a9975d34c908f6a1d34cef4e9486
SHA1: 9d528cf1e9c37ef59876a45c1b9b784272d84fe3
SHA256: 190726551A2CBC2D6794994D92D9E47727A4AC2E7F682F4079924009F5851E35
File Size: 8.19 KB, 8192 bytes
MD5: 7b50ffbda4306d00f24d54a4a6d3e5c7
SHA1: 593b71501c274fe556aad8a349690e956ab0a329
SHA256: 3D411CAE165E18670F080D3086BDE2D1DEE91124CE60458C4157DD8313ACAE17
File Size: 24.58 KB, 24576 bytes
MD5: f1314d565a6b0af940d2a1b002ee23f2
SHA1: 6b792b07cd699dc7084d5a9125afe802594cb036
SHA256: 57A1D60C873F18B86F278202812102A332FF00ED15136B22A25DA39D663FDAEC
File Size: 129.54 KB, 129536 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 0.0.0.0
File Version 0.0.0.0
Internal Name
  • App_Web_1kghofws.dll
  • App_Web_33nhplyz.dll
  • App_Web_g1d3cdad.dll
  • App_Web_rn3nzyzc.dll
Original Filename
  • App_Web_1kghofws.dll
  • App_Web_33nhplyz.dll
  • App_Web_g1d3cdad.dll
  • App_Web_rn3nzyzc.dll
Product Version 0.0.0.0

File Traits

  • .NET
  • dll
  • x86

Block Information

Total Blocks: 343
Potentially Malicious Blocks: 144
Whitelisted Blocks: 83
Unknown Blocks: 116

Visual Map

0 0 0 0 0 x 0 x ? ? x x ? x x x ? ? 0 0 0 0 x x ? 0 ? 0 0 0 0 0 x x x x ? ? ? x ? ? ? 0 x 0 0 x x 0 0 0 0 x x 0 0 0 0 0 ? ? x 0 0 0 0 0 0 x 0 x ? ? x x ? ? 0 0 0 0 x x ? x x x x x ? ? ? x x x x x ? x x 0 x x 0 x x x x 0 x x x x 0 x x x x 0 x x x x x x ? ? 0 x x ? 0 x x ? ? ? 0 x ? ? ? ? ? ? x x x x x ? x ? x ? ? ? ? ? ? 0 x x 0 x x x x 0 x x x x 0 x x ? 0 x ? x ? ? ? 0 x ? ? ? ? 0 x x 0 x x x x 0 x x x x x x ? ? 0 x x 0 ? ? ? 0 x ? ? ? x ? x ? x ? x ? x x ? ? ? ? ? ? ? 0 x x x x 0 x x x x 0 x x x x 0 x x x x 0 x x ? 0 x x x ? ? ? 0 x ? ? ? 0 0 0 0 ? x 0 x ? 0 0 0 0 x x x x ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? 0 x 0 0 0 0 0 x 0 x ? ? x x ? x x x ? ? 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Agent.JKA
  • MSIL.Webshell.BB
  • MSIL.Webshell.BE
  • MSIL.Webshell.BL
  • MSIL.Webshell.BW
Show More
  • MSIL.Webshell.DD

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 Hk!tX �v����(�*J1�1HO@V�A��G�IH[u_�zk�qq�Xw�n{b��P��jI���������������*�m�Ù�����$�8წ���&M�=�S/�.SLB1_T�Vw�`�V��%�������AE�Q]��D��&��$���L��@K� RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
Show More
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN
  • win32u.dll!NtGdiBitBlt
  • win32u.dll!NtGdiCreateBitmap
  • win32u.dll!NtGdiCreateCompatibleDC
  • win32u.dll!NtGdiCreateDIBitmapInternal
  • win32u.dll!NtGdiCreateSolidBrush
  • win32u.dll!NtGdiDeleteObjectApp
  • win32u.dll!NtGdiExtGetObjectW
  • win32u.dll!NtGdiGetDCforBitmap
  • win32u.dll!NtGdiGetDCObject
  • win32u.dll!NtGdiGetDeviceCaps
  • win32u.dll!NtGdiRestoreDC
  • win32u.dll!NtGdiSaveDC
  • win32u.dll!NtGdiSelectBitmap
  • win32u.dll!NtGdiSetDIBitsToDeviceInternal
  • win32u.dll!NtUserBuildHwndList
  • win32u.dll!NtUserCallTwoParam
  • win32u.dll!NtUserCreateEmptyCursorObject
  • win32u.dll!NtUserCreateWindowEx
  • win32u.dll!NtUserDestroyWindow
  • win32u.dll!NtUserFindExistingCursorIcon
  • win32u.dll!NtUserGetAncestor
  • win32u.dll!NtUserGetClassInfoEx
  • win32u.dll!NtUserGetClassName
  • win32u.dll!NtUserGetDC
  • win32u.dll!NtUserGetGUIThreadInfo
  • win32u.dll!NtUserGetIconInfo
  • win32u.dll!NtUserGetIconSize
  • win32u.dll!NtUserGetImeInfoEx
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetObjectInformation
  • win32u.dll!NtUserGetProcessWindowStation
  • win32u.dll!NtUserGetProp
  • win32u.dll!NtUserGetThreadDesktop
  • win32u.dll!NtUserGetThreadState
  • win32u.dll!NtUserGetWindowCompositionAttribute
  • win32u.dll!NtUserIsNonClientDpiScalingEnabled
  • win32u.dll!NtUserIsTopLevelWindow
  • win32u.dll!NtUserMessageCall
  • win32u.dll!NtUserRegisterClassExWOW
  • win32u.dll!NtUserRegisterWindowMessage
  • win32u.dll!NtUserReleaseDC
  • win32u.dll!NtUserRemoveProp
  • win32u.dll!NtUserSelectPalette
  • win32u.dll!NtUserSetCursorIconData
  • win32u.dll!NtUserSetWindowFNID
  • win32u.dll!NtUserSetWindowLongPtr
  • win32u.dll!NtUserSetWindowPos
  • win32u.dll!NtUserUpdateInputContext