Backdoor

Backdoor:MSIL/Webshell.BB!MTB (file analysis)

Malware Removal

The Backdoor:MSIL/Webshell.BB!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:MSIL/Webshell.BB!MTB virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Backdoor:MSIL/Webshell.BB!MTB?


File Info:

name: E634AAE37B07960444C0.mlw
path: /opt/CAPEv2/storage/binaries/7ef36569b7dcb9cba7052590235b0ab581c1bc6c38279829a4efec6e090af733
crc32: 4B62119E
md5: e634aae37b07960444c0e83776024082
sha1: 23b40b8cbfd7f5609ee4781e80506ae618f4f35b
sha256: 7ef36569b7dcb9cba7052590235b0ab581c1bc6c38279829a4efec6e090af733
sha512: efafff8e69304effa981ac6dfa8e5f8afd04ccd017a93fdbce8a350f5acdf9f93b7fcd77b1cae7836b57080f293761e186dae65b267fbacc475f01aabe32d003
ssdeep: 192:BhpsifXpjjkJpj3fLeMLYOs1TD+t82VFLsTmxOQadkX7Lt4TwT:Bga4pj3fLeML1g2DoTmxOtKX7Lt4TwT
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T13252E71EAB98CD13C6BB9331A7B29604C4B695070596CF1ABDDCA5C61FB334402A2FD8
sha3_384: 6172663a13d7a51aa95c0d886ccff7365bf3cb7d333eb9f6ea96dec1bac00d4a8eb6244831b58c0079c3e31311a7b360
ep_bytes: ff250020001000000000000000000000
timestamp: 2024-01-18 23:00:14

Version Info:

0: [No Data]

Backdoor:MSIL/Webshell.BB!MTB also known as:

BkavW32.AIDetectMalware.CS
LionicTrojan.Win32.Webshell.m!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.MSILHeracles.61452
SkyhighBehavesLike.Win32.Infected.lm
ALYacGen:Variant.MSILHeracles.61452
Cylanceunsafe
ZillyaTrojan.Webshell.Win32.16517
SangforBackdoor.Msil.Agent.V8vu
AlibabaBackdoor:MSIL/WebShell.76df12fe
ArcabitTrojan.MSILHeracles.DF00C
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/Webshell.EV
CynetMalicious (score: 99)
ClamAVWin.Packed.Webshell-10016062-0
KasperskyHEUR:Backdoor.MSIL.WebShell.gen
BitDefenderGen:Variant.MSILHeracles.61452
AvastWin32:BackdoorX-gen [Trj]
SophosMal/Generic-S
F-SecureTrojan.TR/Dropper.MSIL.Gen
DrWebBackDoor.WebshellNET.9
VIPREGen:Variant.MSILHeracles.61452
EmsisoftGen:Variant.MSILHeracles.61452 (B)
SentinelOneStatic AI – Suspicious PE
VaristW32/WebShell.E.gen!Eldorado
AviraTR/Dropper.MSIL.Gen
MicrosoftBackdoor:MSIL/Webshell.BB!MTB
ZoneAlarmHEUR:Backdoor.MSIL.WebShell.gen
GDataGen:Variant.MSILHeracles.61452
GoogleDetected
AhnLab-V3Backdoor/Win.WEBSHELL.C5557106
McAfeeArtemis!E634AAE37B07
MalwarebytesTrojan.WebShell
PandaTrj/GdSda.A
TencentBackdoor.MSIL.WebShell.kt
IkarusTrojan.MSIL.Webshell
FortinetW32/Webshell.EE!tr
AVGWin32:BackdoorX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Backdoor:MSIL/Webshell.BB!MTB?

Backdoor:MSIL/Webshell.BB!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment