Trojan

IL:Trojan.MSILZilla.12157 (file analysis)

Malware Removal

The IL:Trojan.MSILZilla.12157 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What IL:Trojan.MSILZilla.12157 virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine IL:Trojan.MSILZilla.12157?


File Info:

name: 42AA84A299264BCC8601.mlw
path: /opt/CAPEv2/storage/binaries/200831da0a65bef54037b30efefb7fa4362209567cb71a86346834b50cf60ef4
crc32: BDB7903B
md5: 42aa84a299264bcc8601d733234bc43d
sha1: ffe8364d2cc6365e8f87db4278536a410a527468
sha256: 200831da0a65bef54037b30efefb7fa4362209567cb71a86346834b50cf60ef4
sha512: 0cee3a8e66609bd4f93a660b6dee01ec00a252512c5c11a754ce0b307e69d8759d4aba9ed5e3c9fdbe8d921840f53eb75ad3cc9a757b222d79d985e4f1d30470
ssdeep: 48:6cfkByTF3nONje1eFJ3E3LczguOCx915qBHHuulcxvqXSfbNtm:QQ3v3LMgwx9Pk5axhzNt
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12CC12F0167AA85F3D2618B72C66A4300A37BA731059ACFCE2E84C3697CFD1538F526E0
sha3_384: cb9c20c408219ecdf34a89cceffb94df69284118833312066f792fa147a023638e74383fccd4df084496fb7427e2843d
ep_bytes: ff250020400000000000000000000000
timestamp: 2023-11-03 17:39:53

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: Crypted.exe
LegalCopyright:
OriginalFilename: Crypted.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

IL:Trojan.MSILZilla.12157 also known as:

BkavW32.Common.623BDE5D
LionicTrojan.Win32.Tiny.m!c
Elasticmalicious (high confidence)
MicroWorld-eScanIL:Trojan.MSILZilla.12157
SkyhighArtemis!Trojan
McAfeeArtemis!42AA84A29926
Cylanceunsafe
ZillyaDownloader.Tiny.Win32.17539
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004dcb4e1 )
AlibabaTrojanDownloader:MSIL/Citrate.124f629f
K7GWTrojan ( 004dcb4e1 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecMSIL.Downloader!gen7
ESET-NOD32a variant of MSIL/TrojanDownloader.Tiny.APB
CynetMalicious (score: 99)
APEXMalicious
ClamAVWin.Packed.Razy-9794845-0
KasperskyHEUR:Backdoor.MSIL.Citrate.gen
BitDefenderIL:Trojan.MSILZilla.12157
SUPERAntiSpywareTrojan.Agent/Gen-Virtool
AvastWin32:RATX-gen [Trj]
EmsisoftIL:Trojan.MSILZilla.12157 (B)
F-SecureHeuristic.HEUR/AGEN.1365506
VIPREIL:Trojan.MSILZilla.12157
TrendMicroTROJ_GEN.R002C0DK323
SophosMal/DotNet-C
IkarusTrojan-Downloader.MSIL.Tiny
GDataIL:Trojan.MSILZilla.12157
JiangminBackdoor.MSIL.ghgt
VaristW32/MSIL_Troj.ADF.gen!Eldorado
AviraHEUR/AGEN.1365506
Antiy-AVLTrojan[Downloader]/MSIL.Tiny
Kingsoftmalware.kb.c.1000
ArcabitIL:Trojan.MSILZilla.D2F7D
ZoneAlarmHEUR:Backdoor.MSIL.Citrate.gen
MicrosoftTrojanDownloader:MSIL/Tiny.AP!MTB
GoogleDetected
AhnLab-V3Trojan/Win32.Tiggre.C2524515
BitDefenderThetaGen:NN.ZemsilF.36680.am0@aqnYJKi
MAXmalware (ai score=80)
MalwarebytesTrojan.MalPack.PGen
TrendMicro-HouseCallTROJ_GEN.R002C0DK323
RisingBackdoor.Citrate!8.10E07 (TFE:C:zCldIufCGWV)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Tiny.APB!tr.dldr
AVGWin32:RATX-gen [Trj]
Cybereasonmalicious.d2cc63
DeepInstinctMALICIOUS

How to remove IL:Trojan.MSILZilla.12157?

IL:Trojan.MSILZilla.12157 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment