Threat Database Trojans Trojan.CsgoHack.X

Trojan.CsgoHack.X

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 9,926
Threat Level: 80 % (High)
Infected Computers: 1,227
First Seen: February 25, 2022
Last Seen: July 20, 2026
OS(es) Affected: Windows

The detection of Trojan.CsgoHack.X on your system indicates a potential security threat that requires immediate attention. This malware is identified as a Trojan-type threat, which is a broad category of malicious software designed to deceive users into installing or executing it, often by disguising itself as legitimate software. Trojans can lead to a variety of problems, including data theft, unauthorized access to your system, and disruption of your computer's operation.

What Is Trojan.CsgoHack.X?

Trojan.CsgoHack.X, as indicated by its name, suggests a connection to cheating software potentially aimed at the popular game Counter-Strike: Global Offensive (CS:GO). However, without specific details, it's crucial to understand that Trojans are versatile and can be used for a wide range of malicious activities, not limited to gaming cheats. They can install backdoors, keyloggers, or other types of malware, making them a significant threat to your system's security and your personal data.

How Trojan.CsgoHack.X Operates

Trojans typically operate by exploiting trust. They might be disguised as useful software or games, or they might piggyback on legitimate programs. Once installed, they can create backdoors for remote access, steal sensitive information, or download additional malware. The specific operation of Trojan.CsgoHack.X would depend on its intended purpose, which could range from stealing gaming credentials to using your computer as part of a botnet for distributed denial-of-service (DDoS) attacks or spamming.

Symptoms of Infection

Symptoms of a Trojan infection can be subtle and may not always be immediately apparent. Common signs include unusual system behavior, such as unexpected pop-ups, slow performance, or programs starting automatically. You might also notice unfamiliar programs installed on your system, changes to your browser settings, or unexpected network activity. Since Trojans can be designed to remain stealthy, some infections might only be discovered through proactive scanning with security software.

How to Remove Trojan.CsgoHack.X

  1. Boot your computer in Safe Mode with Networking. This will help prevent the malware from loading and make it easier to remove.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter. Ensure your security software is updated to the latest version to increase the chances of detecting and removing the Trojan.
  3. Uninstall any suspicious programs that you do not recognize or that were installed around the time your system was infected.
  4. Reset your web browsers (Chrome, Firefox, Edge, etc.) to their default settings to remove any malicious extensions or settings changes made by the Trojan.
  5. After completing the above steps, reboot your computer and perform another full scan with your anti-malware software to ensure that the Trojan and any associated malware have been completely removed.

Conclusion

Removing Trojan.CsgoHack.X requires careful and thorough action to ensure your system is completely cleaned and protected. It's also essential to take preventive measures to avoid future infections, such as being cautious with downloads, avoiding suspicious links, keeping your operating system and software up to date, and regularly scanning your system with reputable security tools. By taking these steps, you can help protect your system and personal data from the threats posed by Trojans and other types of malware.

Analysis Report

General information

Family Name: Trojan.CsgoHack.X
Signature status: No Signature

Known Samples

MD5: c9e1df291d7ff327c81c077556afcfbd
SHA1: 214c80779a2d2906e9d44c402ab7c36009295cb2
SHA256: 427B08F74414F631AA9FC6297EF5ADF41EC2026CAE6A8E1F5D7C5E1CAF30DFF4
File Size: 199.68 KB, 199680 bytes
MD5: c7ddf7876d3530c601062b8dc5a66324
SHA1: 0f612f5afdb94e2d8368a84cc5251a69dd9dc72d
SHA256: 5EDED55421A89A0A2DCF4955AE2A4FDFC0710E5732EA5ECC3F6DBD4F20500012
File Size: 2.93 MB, 2934784 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name LE Team
File Description
  • Shaiya Client Side DLL
  • WOSTweaks for Spider-Man: Web of Shadows
File Version
  • 1.3.3.0
  • 1.3.0.0
Internal Name
  • LE Team Client Side DLL
  • WOSTweaks
Legal Copyright Copyright (C) 2021 LE Team. All rights reserved.
Legal Trademarks LE Team
Original Filename DINPUT8.dll
Product Name
  • Shaiya DLL
  • WOSTweaks
Product Version
  • 1.3.3.0
  • 1.3.0.0

File Traits

  • dll
  • HighEntropy
  • imgui
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 5,040
Potentially Malicious Blocks: 123
Whitelisted Blocks: 2,069
Unknown Blocks: 2,848

Visual Map

? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 ? ? 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? ? 0 0 ? ? ? ? ? ? 0 0 0 0 ? 0 0 ? 0 0 ? 0 ? ? ? 0 ? ? ? ? 0 ? ? 0 ? ? 0 ? ? ? ? 0 ? ? ? 0 ? ? ? ? 0 ? ? 0 ? 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? 0 ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 ? ? ? ? 0 ? ? 0 ? 0 ? ? ? ? ? ? 0 ? 0 ? ? ? 0 ? 0 ? ? 0 ? 0 ? 0 ? 0 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 0 x ? ? ? ? 0 ? 0 ? 0 ? 0 ? 0 ? ? 0 ? 0 0 ? ? ? ? ? ? 0 ? ? 0 ? ? 0 ? 0 ? ? ? 0 ? ? ? 0 ? 0 ? ? ? ? 0 0 ? ? ? ? 0 ? ? ? ? 0 ? 0 ? ? ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? 0 ? ? 0 ? ? ? ? 0 0 ? ? ? ? 0 ? ? ? 0 0 ? 0 0 ? ? 0 ? ? 0 ? ? ? 0 ? ? ? ? 0 ? ? ? ? ? 0 0 ? ? ? ? 0 ? ? 0 ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 ? 0 ? ? 0 ? ? 0 ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? ? ? ? 0 0 ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? 0 ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? 0 0 0 ? ? 0 ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 0 0 0 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? 0 ? ? ? ? ? ? 0 0 ? ? ? 0 ? 0 ? 0 ? 0 ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? 0 0 0 ? 0 ? ? ? 0 ? 0 ? ? 0 0 ? ? 0 0 0 ? ? 0 ? ? ? ? ? ? 0 ? 0 0 ? ? ? ? 0 ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? 0 ? ? 2 ? 0 ? ? 0 ? ? ? ? ? ? 0 ? ? 2 ? ? ? ? ? 0 ? ? ? 0 ? ? ? 0 0 ? ? ? ? 0 ? ? 0 ? ? ? ? ? 0 0 ? ? 0 0 ? 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? 0 0 ? ? ? ? 0 0 0 0 ? ? 0 0 0 ? ? ? ? 0 ? ? ? ? 0 ? 0 0 ? ? ? ? ? 0 ? ? ? ? 0 0 ? ? 0 0 ? ? 0 ? ? 0 ? ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? 0 ? ? ? ? ? ? 0 0 0 0 ? 0 0 ? ? ? ? 0 0 ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? 0 ? ? ? ? 0 ? 0 ? 0 ? 0 ? 0 ? 0 ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? 0 0 0 ? ? ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? 0 ? ? 0 ? 0 ? ? 0 0 ? ? ? 0 ? 0 ? ? ? x 0 ? ? ? x ? ? ? 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? 0 ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 0 0 ? ? 0 ? ? 0 0 0 ? ? 0 ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? 0 ? 0 ? ? ? ? ? ? 0 0 ? ? ? ? 0 0 0 ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? 2 ? 2 ? 2 ? 2 ? 2 ? 2 ? 2 ? 2 ? 2 ? 2 0 ? 2 ? 2 ? 2 ? 2 ? 2 ? 2 ? 2 ? 2 ? 2 ? 2 ? 2 ? 2 ? 2 ? 2 ? 2 ? 2 ? 2 ? 2 ? 2 ? 2 ? 2 ? 2 ? 2 ? 2 ? 2 ? 2 ? ? ? 0 ? 2 ? 2 ? 2 ? 0 ? 2 ? 0 ? 2 ? 2 ? 2 ? 2 ? 2 ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? 0 ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? 0 ? ? 0 ? ? ? ? 0 0 ? 0 ? 0 0 0 ? ? ? ? 0 ? ? ? 0 ? ? ? ? 0 ? ? 0 0 ? ? ? ? 0 ? ? 0 0 ? ? ? ? 0 ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? 0 ? 0 ? 0 0 0 ? ? ? ? 0 ? ? 0 0 ? ? ? ? 0 ? ? 0 0 ? ? ? ? 0 ? ? 0 0 ? ? ? ? 0 ? ? ? ? 0 ? ? 0 0 ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? 0 ? ? ? ? ? ? 0 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? 0 ? 0 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? 0 ? ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 0 0 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 ? 0 ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? 0 0 ? ? 0 ? ? 0 ? 0 0 ? 0 ? 0 ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? ? ? 0 ? 0 ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? 0 ? 0 ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? 0 ? 0 ? ? ? 0 ? ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? 0 ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? x ? ? 0 ? ? 0 0 ? 0 ? ? ? 0 ? ? ? ? ? ? ? ?
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\214c80779a2d2906e9d44c402ab7c36009295cb2_0000199680.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\0f612f5afdb94e2d8368a84cc5251a69dd9dc72d_0002934784.,LiQMAxHB