Backdoor

Backdoor:MSIL/WebShell.AI!MTB information

Malware Removal

The Backdoor:MSIL/WebShell.AI!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:MSIL/WebShell.AI!MTB virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Backdoor:MSIL/WebShell.AI!MTB?


File Info:

name: 1EAFD8BDAE30826CB039.mlw
path: /opt/CAPEv2/storage/binaries/4303c51fc87be8041c7caf9a61916e3df27fc1aaead6221bad8a2a145d2536f1
crc32: 225CFB9C
md5: 1eafd8bdae30826cb03929c506be3ccb
sha1: 7e7348e00486b67e26c03b21a35166df728d2d64
sha256: 4303c51fc87be8041c7caf9a61916e3df27fc1aaead6221bad8a2a145d2536f1
sha512: 8a32bd2655a08de7d4d8532164b24d1eb0b3d6ec347e41ed17c979331f73a5cce00bb90b568aebac2648ba3e0341eff1367bca3e5d384d3956234faa875a2084
ssdeep: 192:IUpU1U0D0lqbhVHbggSzcfVasYtbFY5XwbMFbU8b:9U1KQVV7gdzcfVasYtYD
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T16A32E81BB7D9CA23DA7E477C297186140376D603A023FB277FC850A89FD37518852B96
sha3_384: 7cf8203da99d3fcf74cc14bbca7109142d4d9beaff466e91a5ed1ae2f4e440698b75397f0703b012f41f27dc3fd740d7
ep_bytes: ff250020001000000000000000000000
timestamp: 2024-03-25 14:54:22

Version Info:

0: [No Data]

Backdoor:MSIL/WebShell.AI!MTB also known as:

BkavW32.AIDetectMalware.CS
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.104945
FireEyeTrojan.GenericKDZ.104945
MalwarebytesTrojan.WebShell.MSIL
ZillyaTrojan.Agent.Win32.3763008
CrowdStrikewin/malicious_confidence_60% (W)
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/Agent.EJA
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R011C0DCR24
ClamAVWin.Packed.Webshell-10014509-0
KasperskyHEUR:Backdoor.MSIL.WebShell.gen
BitDefenderTrojan.GenericKDZ.104945
AvastWin32:BackdoorX-gen [Trj]
TACHYONBackdoor/W32.DN-WebShell.11264.L
EmsisoftTrojan.GenericKDZ.104945 (B)
F-SecureHeuristic.HEUR/AGEN.1370573
DrWebBackDoor.WebshellNET.5
VIPRETrojan.GenericKDZ.104945
TrendMicroTROJ_GEN.R011C0DCR24
IkarusTrojan.MSIL.Agent
GoogleDetected
AviraHEUR/AGEN.1370573
VaristW32/MSIL_Agent1.GWE.gen!Eldorado
Antiy-AVLTrojan[Backdoor]/MSIL.WebShell
MicrosoftBackdoor:MSIL/WebShell.AI!MTB
ArcabitTrojan.Generic.D199F1
ZoneAlarmHEUR:Backdoor.MSIL.WebShell.gen
GDataMSIL.Trojan.PSE.CX8BC6
AhnLab-V3Backdoor/Win.WEBSHELL.C5545120
ALYacTrojan.GenericKDZ.104945
MAXmalware (ai score=80)
VBA32TScope.Trojan.MSIL
PandaTrj/GdSda.A
SentinelOneStatic AI – Malicious PE
FortinetMSIL/Agent.EJA!tr
AVGWin32:BackdoorX-gen [Trj]

How to remove Backdoor:MSIL/WebShell.AI!MTB?

Backdoor:MSIL/WebShell.AI!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment