Trojan

What is “Trojan:MSIL/Webshell.AMAF!MTB”?

Malware Removal

The Trojan:MSIL/Webshell.AMAF!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:MSIL/Webshell.AMAF!MTB virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Trojan:MSIL/Webshell.AMAF!MTB?


File Info:

name: 9B0FA2A2B6B7BAFD863A.mlw
path: /opt/CAPEv2/storage/binaries/4a39beea65831f150f06689820298671f855f680322469b6e8f3e278b8455789
crc32: 8A9E16B9
md5: 9b0fa2a2b6b7bafd863a730fc3f4cda7
sha1: 3b85145384e2238a81a2586580babc52f1791e40
sha256: 4a39beea65831f150f06689820298671f855f680322469b6e8f3e278b8455789
sha512: 393d16985704a4f1489aa91555fadf717233fceb958469912d17464cb319a3afb2296d0c94b016d25932cba588ac859547529fd6afec47950d9252b40b469b7e
ssdeep: 384:G2VuEvxHU5TFayenFJN4jD0jNY6KYBMwMjrD0AtkNHX0AmsYoRW/Dwj6C3:eEvmFLenFrfsS
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1DC62A6246B9491E8C9B64F35107542C763FBE74B9FA4CF4C1565229CCF1390B93A3AB2
sha3_384: 83e4e8baffd2837229115a56445eb23b0a2d6c3333fa9a85056191ae25e5633891634f88c658a20754c2d1c7e1717fd6
ep_bytes: ff250020400000000000000000000000
timestamp: 2024-01-16 18:38:12

Version Info:

Translation: 0x007f 0x04b0
Comments:
CompanyName:
FileDescription:
FileVersion: 0.0.0.0
InternalName: App_Web_6384105589218361017302229.aspx.c016e702.y8yicoth.dll
LegalCopyright:
LegalTrademarks:
OriginalFilename: App_Web_6384105589218361017302229.aspx.c016e702.y8yicoth.dll
ProductName:
ProductVersion:

Trojan:MSIL/Webshell.AMAF!MTB also known as:

BkavW32.AIDetectMalware.CS
LionicTrojan.Win32.Webshell.m!c
MicroWorld-eScanGeneric.MSIL.Chopper.A.D5AC6D07
FireEyeGeneric.mg.9b0fa2a2b6b7bafd
SkyhighRDN/Generic BackDoor
McAfeeRDN/Generic BackDoor
Cylanceunsafe
ZillyaTrojan.Webshell.Win32.19745
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005970621 )
AlibabaBackdoor:MSIL/WebShell.6a913f0e
K7GWTrojan ( 005970621 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitGeneric.MSIL.Chopper.A.D5AC6D07
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Webshell.DE
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Backdoor.MSIL.WebShell.gen
BitDefenderGeneric.MSIL.Chopper.A.D5AC6D07
AvastWin32:BackdoorX-gen [Trj]
TencentMsil.Backdoor.Webshell.Jqil
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1364305
DrWebBackDoor.WebshellNET.1
VIPREGeneric.MSIL.Chopper.A.D5AC6D07
TrendMicroTROJ_GEN.R011C0DAI24
EmsisoftGeneric.MSIL.Chopper.A.D5AC6D07 (B)
SentinelOneStatic AI – Malicious PE
GoogleDetected
AviraHEUR/AGEN.1364305
KingsoftMSIL.Backdoor.WebShell.gen
MicrosoftTrojan:MSIL/Webshell.AMAF!MTB
ZoneAlarmHEUR:Backdoor.MSIL.WebShell.gen
GDataGeneric.MSIL.Chopper.A.D5AC6D07
VaristW32/ABRisk.MINA-1212
AhnLab-V3Trojan/Win.Generic.C5570770
ALYacGeneric.MSIL.Chopper.A.D5AC6D07
MAXmalware (ai score=100)
VBA32Backdoor.MSIL.Webshell.Heur
MalwarebytesTrojan.WebShell.MSIL
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R011C0DAI24
IkarusTrojan.MSIL.Webshell
MaxSecureTrojan.Malware.116271617.susgen
FortinetMSIL/Webshell.DE!tr
AVGWin32:BackdoorX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:MSIL/Webshell.AMAF!MTB?

Trojan:MSIL/Webshell.AMAF!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment