Backdoor

About “Backdoor:MSIL/WebShell.AK!MTB” infection

Malware Removal

The Backdoor:MSIL/WebShell.AK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:MSIL/WebShell.AK!MTB virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Backdoor:MSIL/WebShell.AK!MTB?


File Info:

name: 666431D8B95B0D451F58.mlw
path: /opt/CAPEv2/storage/binaries/e6906b20b53424c3b0ab423dd9d5f13357ba604477c32d2b22e8c0e00fa06503
crc32: 879554E4
md5: 666431d8b95b0d451f586226f2567074
sha1: c9e1cc9d0a834af69379d93133f8cee82bf3b312
sha256: e6906b20b53424c3b0ab423dd9d5f13357ba604477c32d2b22e8c0e00fa06503
sha512: 1eed66366e52fa138b319bd3be95c7de23f24f82ee88345b3965750661b2c7e8bad61ac8c01930dc845cfb3347fb7a9e464568456a0415c5b7a18f377c79d2fe
ssdeep: 1536:PBCte5XmmmmmmmmmmmmmgYXVy14j8R8BNYagNGUYnQ/1Ty:ye5xZ+YufzeT
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1AEC3610226D19A06D87B423892324E58DFB7E8079232D6187DDE75BF1FB7E008517FA5
sha3_384: 87f13d959d0cedc0337cf39f051cfd5901348ef58dc6e1164f3e706053a28e188f8c72740936ae4fbc595e81e3df54e6
ep_bytes: ff250020400000000000000000000000
timestamp: 2023-03-09 17:35:38

Version Info:

0: [No Data]

Backdoor:MSIL/WebShell.AK!MTB also known as:

BkavW32.AIDetectMalware.CS
LionicTrojan.Win32.WebShell.m!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.MSILHeracles.68688
SkyhighGenericRXVO-FQ!666431D8B95B
McAfeeGenericRXVO-FQ!666431D8B95B
Cylanceunsafe
ZillyaBackdoor.WebShell.Win32.10
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:MSIL/WebShell.a5994cdc
K7GWTrojan ( 0059fd5d1 )
K7AntiVirusTrojan ( 0059fd5d1 )
ArcabitTrojan.MSILHeracles.D10C50
SymantecTrojan.Gen.2
ESET-NOD32a variant of MSIL/Agent.EJA
CynetMalicious (score: 99)
APEXMalicious
ClamAVWin.Packed.Webshell-10013238-0
KasperskyHEUR:Backdoor.MSIL.WebShell.gen
BitDefenderGen:Variant.MSILHeracles.68688
AvastWin32:BackdoorX-gen [Trj]
TencentMalware.Win32.Gencirc.13bf5e96
EmsisoftGen:Variant.MSILHeracles.68688 (B)
F-SecureTrojan.TR/Agent.rqkqi
DrWebBackDoor.WebshellNET.5
VIPREGen:Variant.MSILHeracles.68688
TrendMicroTROJ_GEN.R002C0DAA24
SophosMal/Generic-S
IkarusTrojan.MSIL.Agent
VaristW32/MSIL_Agent.EYN.gen!Eldorado
AviraTR/Agent.rqkqi
Antiy-AVLTrojan[Backdoor]/MSIL.WebShell
MicrosoftBackdoor:MSIL/WebShell.AK!MTB
ZoneAlarmHEUR:Backdoor.MSIL.WebShell.gen
GDataGen:Variant.MSILHeracles.68688
GoogleDetected
AhnLab-V3Trojan/Win.Generic.C5392756
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002C0DAA24
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetMSIL/Agent.EJA!tr
AVGWin32:BackdoorX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Backdoor:MSIL/WebShell.AK!MTB?

Backdoor:MSIL/WebShell.AK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment