Backdoor

Backdoor.MSIL.NanoBot.aetl information

Malware Removal

The Backdoor.MSIL.NanoBot.aetl is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.MSIL.NanoBot.aetl virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • A process created a hidden window
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Attempts to remove evidence of file being downloaded from the Internet
  • Installs itself for autorun at Windows startup
  • Exhibits behavior characteristic of Nanocore RAT
  • Creates a hidden or system file
  • Collects information to fingerprint the system

Related domains:

himeraaa.ddns.net
edgedl.me.gvt1.com

How to determine Backdoor.MSIL.NanoBot.aetl?


File Info:

crc32: 30AE33C9
md5: c175b20d60972f1b6e9708964c18903e
name: C175B20D60972F1B6E9708964C18903E.mlw
sha1: 591d6c1ab1c85a86a6ad153c22153dc8599ff456
sha256: c49759a73f5c1515d6fd07de402561171a49a9890eaab888681c44ff2b7da362
sha512: c1754a49fb482e306088df65b7ec3401434555bfbd8e8d3f04bcc3b5ffa9cc9ff6767e01e623998e687144156576058edffc5837481b9df4641bd5c8198788cf
ssdeep: 12288:uUomEFRu3xEPE1MEEAw3hxZt6Pf23qDhiKXvm1rMnpX2:amOMSPE1M3AYhztUYAXvm1I92
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor.MSIL.NanoBot.aetl also known as:

LionicTrojan.MSIL.NanoBot.m!c
ALYacZum.Rastarby.3
MalwarebytesGeneric.Malware/Suspicious
CrowdStrikewin/malicious_confidence_80% (D)
Cybereasonmalicious.ab1c85
SymantecML.Attribute.HighConfidence
ESET-NOD32MSIL/NanoCore.E
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 99)
KasperskyBackdoor.MSIL.NanoBot.aetl
NANO-AntivirusTrojan.Win32.NanoBot.fhuqdj
TencentMsil.Backdoor.Nanobot.Swkj
SophosMal/Generic-S
ComodoMalware@#2kfa31argl37i
DrWebTrojan.Nanocore.24
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Ransomware.gc
FireEyeGeneric.mg.c175b20d60972f1b
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1130941
MicrosoftTrojan:Win32/Skeeyah.A!rfn
ZoneAlarmBackdoor.MSIL.NanoBot.aetl
TACHYONBackdoor/W32.NanoBot.480839
AhnLab-V3Malware/Win32.Generic.C2559022
McAfeeArtemis!C175B20D6097
YandexBackdoor.NanoBot!HzPvY+inSgk
IkarusTrojan.MSIL.NanoCore
FortinetMSIL/NanoCore.E!tr
PandaTrj/CI.A
Qihoo-360Win32/Backdoor.Nanocore.HgIASOgA

How to remove Backdoor.MSIL.NanoBot.aetl?

Backdoor.MSIL.NanoBot.aetl removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment