Trojan

What is “IL:Trojan.MSILZilla.21303”?

Malware Removal

The IL:Trojan.MSILZilla.21303 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What IL:Trojan.MSILZilla.21303 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Sniffs keystrokes
  • CAPE detected the njRat malware family

How to determine IL:Trojan.MSILZilla.21303?


File Info:

name: 92055CD139E29DEEF4A7.mlw
path: /opt/CAPEv2/storage/binaries/5bd46e142d59364a53282c9e292bac97d71605547432515519a6e2eac73e84dd
crc32: CB806733
md5: 92055cd139e29deef4a7ac356a73fdb1
sha1: 4b2b1de7085c414e79f6f68505828efe3c7f0d2e
sha256: 5bd46e142d59364a53282c9e292bac97d71605547432515519a6e2eac73e84dd
sha512: 29914478e35aeeafa6e80344e621df96836b6562176e833c7616881a6113e9bc1b69059f7876b3ed6ad5e54173ebb898fb7d3d79cd29ea98b03797ac2643e234
ssdeep: 12288:5ToPWBv/cpGrU3yh7zMB0leI0XcPzV4ODO:5TbBv5rUKzMeeHsPu7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1ADA49C817AC19CB2FC6229361B25E631653C7CB29FFDCA9B53C04D5BB9217C09631AE1
sha3_384: 389ce1f2520e4db9d01db9a9f3c374ca43771c74f5823f6960cceb87506ad3d2598ab196b56732645df6d14181efcad8
ep_bytes: e866050000e978feffffcccccccccccc
timestamp: 2022-03-03 13:15:57

Version Info:

0: [No Data]

IL:Trojan.MSILZilla.21303 also known as:

BkavW32.AIDetect.malware2
FireEyeGeneric.mg.92055cd139e29dee
BitDefenderIL:Trojan.MSILZilla.21303
Cybereasonmalicious.139e29
ArcabitIL:Trojan.MSILZilla.D5337
BaiduMSIL.Backdoor.Bladabindi.a
CyrenW32/MSIL_Troj.FT.gen!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Bladabindi.BC
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Backdoor.MSIL.SpyGate.gen
MicroWorld-eScanIL:Trojan.MSILZilla.21303
RisingBackdoor.njRAT!1.9E49 (CLASSIC:npDOCoTASUC6DAAAcVtBtQ)
EmsisoftIL:Trojan.MSILZilla.21303 (B)
ComodoBackdoor.MSIL.Bladabindi.BA@7oej5x
DrWebBackDoor.BladabindiNET.10
VIPREIL:Trojan.MSILZilla.21303
TrendMicroBKDR_BLADABI.SMC
McAfee-GW-EditionBehavesLike.Win32.Generic.gh
Trapminesuspicious.low.ml.score
SophosGeneric ML PUA (PUA)
IkarusTrojan.MSIL.Bladabindi
AviraTR/Dropper.Gen7
MicrosoftBackdoor:MSIL/Bladabindi.BI
GDataIL:Trojan.MSILZilla.21303
Acronissuspicious
BitDefenderThetaGen:NN.ZemsilF.34786.cm0@aWWksEl
ALYacIL:Trojan.MSILZilla.21303
MAXmalware (ai score=85)
MalwarebytesTrojan.Agent
SentinelOneStatic AI – Suspicious SFX
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Bladabindi.AS!tr
AVGWin32:BackdoorX-gen [Trj]
AvastWin32:BackdoorX-gen [Trj]

How to remove IL:Trojan.MSILZilla.21303?

IL:Trojan.MSILZilla.21303 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment