Backdoor

Backdoor:MSIL/WebShell.AI!MTB malicious file

Malware Removal

The Backdoor:MSIL/WebShell.AI!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:MSIL/WebShell.AI!MTB virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Backdoor:MSIL/WebShell.AI!MTB?


File Info:

name: BA70966B9890AE7E6DB4.mlw
path: /opt/CAPEv2/storage/binaries/82a0809b145457da204ad2932a9a13be5f8fc3ff2b7fd5553ad8ac6df780eab6
crc32: BEB18025
md5: ba70966b9890ae7e6db4ae8273f6381d
sha1: d95fdfa917815d8c0a671bdc960a741854e3ea90
sha256: 82a0809b145457da204ad2932a9a13be5f8fc3ff2b7fd5553ad8ac6df780eab6
sha512: 0f77345a8fd022cf7525bad5a98df20188a508f4bf167190d2ae815ee801335e65a69408ae030c3239fef51b893f1037747012865b29546e28deb65d6ca3537b
ssdeep: 192:LUpU1U0D0lqjhxHbggSzcfVasYtbmY5XwbM9bU8b:GU1KQ9x7gdzcfVasYtN7
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1FF32F81BB7D9CA23DA7E477C297186140337D603A023FB276FC850A89FD37518452B96
sha3_384: 13695a2d036680a108f564ce8dc6bf3d8a8bee363814116d4493134078b9ce25f306fa31c57d8c7c5ca31188831fbb55
ep_bytes: ff250020001000000000000000000000
timestamp: 2024-02-29 00:34:43

Version Info:

0: [No Data]

Backdoor:MSIL/WebShell.AI!MTB also known as:

BkavW32.AIDetectMalware.CS
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.104945
SkyhighBehavesLike.Win32.Infected.lm
McAfeeArtemis!BA70966B9890
MalwarebytesTrojan.WebShell.MSIL
ZillyaTrojan.Agent.Win32.3763008
CrowdStrikewin/malicious_confidence_60% (W)
BitDefenderTrojan.GenericKDZ.104945
ArcabitTrojan.Generic.D199F1
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/Agent.EJA
APEXMalicious
ClamAVWin.Packed.Webshell-10014509-0
KasperskyHEUR:Backdoor.MSIL.WebShell.gen
AvastWin32:BackdoorX-gen [Trj]
TACHYONBackdoor/W32.DN-WebShell.11264.L
EmsisoftTrojan.GenericKDZ.104945 (B)
F-SecureTrojan.TR/Agent.edize
DrWebBackDoor.WebshellNET.5
VIPRETrojan.GenericKDZ.104945
FireEyeTrojan.GenericKDZ.104945
IkarusTrojan.MSIL.Agent
VaristW32/MSIL_Agent1.GWE.gen!Eldorado
AviraTR/Agent.edize
Antiy-AVLTrojan[Backdoor]/MSIL.WebShell
MicrosoftBackdoor:MSIL/WebShell.AI!MTB
ZoneAlarmHEUR:Backdoor.MSIL.WebShell.gen
GDataMSIL.Trojan.PSE.CX8BC6
GoogleDetected
AhnLab-V3Backdoor/Win.WEBSHELL.C5545120
VBA32TScope.Trojan.MSIL
MAXmalware (ai score=88)
PandaTrj/GdSda.A
TencentBackdoor.MSIL.WebShell.kk
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetMSIL/Agent.EJA!tr
AVGWin32:BackdoorX-gen [Trj]

How to remove Backdoor:MSIL/WebShell.AI!MTB?

Backdoor:MSIL/WebShell.AI!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment