Threat Database Stealers Trojan.DiscordStealer.N

Trojan.DiscordStealer.N

By CagedTech in Stealers, Trojans

Threat Scorecard

Popularity Rank: 13,088
Threat Level: 80 % (High)
Infected Computers: 571
First Seen: February 8, 2022
Last Seen: July 16, 2026
OS(es) Affected: Windows

The detection of Trojan.DiscordStealer.N indicates that your system has been compromised by a malicious threat. This type of malware is designed to steal sensitive information, including login credentials, tokens, and other personal data. It's essential to take immediate action to remove the threat and prevent further damage.

What Is Trojan.DiscordStealer.N?

Trojan.DiscordStealer.N is a type of Trojan horse malware that is designed to infiltrate a system without being detected. The name suggests that it may be related to Discord, a popular communication platform, but the exact nature of the threat is not immediately clear. Trojan horses are known for their ability to disguise themselves as legitimate programs, making them difficult to detect and remove.

How Trojan.DiscordStealer.N Operates

Once installed, Trojan.DiscordStealer.N can operate in the background, collecting sensitive information and transmitting it to its creators. This can include login credentials, passwords, and other personal data. The malware may also be able to install additional malicious programs, create backdoors, and modify system settings to maintain its presence on the infected system. The exact mechanisms used by Trojan.DiscordStealer.N are not known, but it's likely that it uses common tactics such as phishing, social engineering, or exploiting vulnerabilities in software.

Symptoms of Infection

Identifying the symptoms of a Trojan.DiscordStealer.N infection can be challenging, as the malware is designed to remain stealthy. However, some common signs of infection include unusual system behavior, such as slow performance, crashes, or unexpected pop-ups. You may also notice that your login credentials are not working, or that your account has been accessed from an unknown location. If you suspect that your system has been infected, it's essential to take immediate action to remove the threat.

How to Remove Trojan.DiscordStealer.N

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for a clean removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and remove any detected threats.
  3. Uninstall any suspicious programs or applications that may be related to the infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform another scan to ensure that the threat has been fully removed.

Conclusion

Removing Trojan.DiscordStealer.N requires a thorough and systematic approach to ensure that the threat is fully eliminated. By following the steps outlined above, you can help to protect your system and prevent further damage. It's also essential to take preventive measures, such as keeping your software up to date, using strong passwords, and being cautious when clicking on links or downloading attachments from unknown sources. Remember that malware threats are constantly evolving, so it's crucial to stay vigilant and take proactive steps to protect your digital security.

Analysis Report

General information

Family Name: Trojan.DiscordStealer.N
Packers: UPX!
Signature status: No Signature

Known Samples

MD5: 292932346f3d6656afc23dbcfff3c759
SHA1: 289e35d90948b5f3514352ccf545f2fae20d4ef9
SHA256: A47A4DEFD64F31F9CB4DB2542D0945D06E832F01BF47CB5942A89E585F671327
File Size: 6.73 MB, 6731264 bytes
MD5: 29557d433886611f1bc8f33e43ed7cc3
SHA1: 58c178f99fce2e54a9a293d57994e7c9a6b1fb21
SHA256: 1B1599257B1A844C58841AF4477EE768DE8AD576544DC0454C291AF3A01167A6
File Size: 520.19 KB, 520192 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Solaris2.hu
File Description Solaris
File Version 1.0.0.0
Internal Name Solaris
Legal Copyright Copyright (C) 2022
Original Filename Solaris.exe
Product Name Solaris
Product Version 1, 0, 0, 1

File Traits

  • GetConsoleWindow
  • HighEntropy
  • No Version Info
  • packed
  • x86

Block Information

Total Blocks: 3,481
Potentially Malicious Blocks: 848
Whitelisted Blocks: 2,375
Unknown Blocks: 258

Visual Map

x 1 0 0 0 0 0 x x 0 0 x x 0 x x 0 x x 0 0 x x x x x x x x x 0 x x x x x x x 0 0 0 0 x x x x x x x x x 0 x x x x x x x x 0 x x 0 x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 0 x x x x x 0 0 x x x x x x x x 0 x x x x x 0 0 x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x 0 0 x x x x x x x x 0 0 0 x x x x x x x x x x 0 x x x x x x x x x x x 0 x x x x 0 x x x 0 x x x x x 0 x x x x 0 x x 0 x x x x 0 0 x x 0 x x x x x x x 0 x x x x x x x 0 x x x x x x x x x 0 0 0 0 x x x x x 0 x x x x x x x x x x x x x x x x 0 0 0 0 x x x x x x x x x x x x x x x x x x x x x x 0 0 x 0 0 0 0 0 0 0 x x x 0 x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x 0 x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 x x x x x x x x x 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x 0 x x x x 0 0 0 x x 0 x x x x x x x x x x x 0 0 x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x 0 x x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x 0 0 1 1 1 1 2 1 1 ? 0 0 0 0 ? 0 ? 0 ? 0 0 0 0 ? ? ? ? ? x 0 0 0 0 0 0 0 x x ? x x ? ? ? ? x ? ? 0 0 0 0 ? 0 0 0 0 0 1 ? ? ? ? ? ? ? 0 ? 0 ? ? x x x 0 0 0 0 0 0 x ? x ? ? x ? ? ? ? ? 0 x ? ? 0 ? x ? x x 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? x 0 x 0 x ? 0 ? ? 0 0 0 x 0 0 ? ? ? ? 0 0 ? 0 ? x x ? 0 x x 0 ? ? x 0 ? 0 x x ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 x x ? 0 0 0 0 0 0 0 0 0 0 x x ? x ? x x x ? 0 0 ? ? ? ? ? ? 0 0 ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 ? 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 ? ? 0 x ? x x ? 0 ? ? ? ? ? 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? ? 0 x 0 0 0 x ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? ? ? ? 0 0 0 0 0 ? 0 0 0 x 0 0 x 0 ? ? 0 ? 0 x 0 ? ? x ? ? 0 x x 0 x 0 0 0 0 0 ? ? 0 x 0 x x x 0 x x x x x x x 0 ? 0 ? ? ? x ? 0 0 x x x x x x x ? ? ? x ? x x x x 0 0 ? ? x x ? ? x 0 0 0 x x ? x ? ? 0 0 ? ? ? 0 x x x 0 x x x ? x x x x x 0 x x x x ? ? ? 0 x x ? x x 0 x x ? ? ? 0 0 0 0 x ? ? ? x 0 0 0 ? x ? ? ? x ? x 0 x x x 0 ? x x x ? ? x x 0 x x 0 ? x x x x ? x ? 0 0 0 x ? 0 ? 0 ? 0 x ? ? 0 x x ? 0 0 0 x x 0 0 x ? x ? x 0 ? ? x x 0 ? ? 0 x x 0 0 0 0 x x x 0 x ? ? x 0 x ? ? 0 0 ? ? ? 0 0 ? x x 0 x ? x x ? ? ? x 0 x x ? 0 ? 0 0 0 x ? 0 0 0 ? ? 0 ? ? 0 ? 0 0 0 ? ? ? x x 0 0 x ? ? ? ? ? ? 0 ? ? x 0 0 0 x ? ? 0 ? 0 0 0 x ? ? ? x ? x ? ? x ? ? ? ? x x x ? ? ? x x ? ? ? ? 0 ? 0 x ? x x ? ? ? 0 0 0 0 x ? ? ? ? 0 x ? 0 ? ? x ? ? x ? x x 0 x 0 x 0 x 0 x x ? ? ? x ? ? x ? x x x ? ? x x x ? x x x ? x x 0 x x ? x x ? 1 ? ? ? x 0 x x ? x ? ? ? 0 x ? ? x ? 0 ? x ? ? ? x 0 x x x ? x 0 ? ? ? ? 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 1 1 1 0 0 x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 1 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 3 1 1 1 1 0 1 1 1 0 0 0 0 0 2 0 0 2 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.BT

Files Modified

File Attributes
\device\namedpipe\dav rpc service Generic Read,Write Data,Write Attributes,Write extended,Append data
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
\device\namedpipe\wkssvc Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\explorer\iconcache_16.db Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\explorer\iconcache_32.db Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\microsoft\windows\explorer\iconcache_idx.db Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\locale.cfg Generic Write,Read Attributes
c:\users\user\downloads\metin2.cfg Generic Read,Write Data,Write Attributes,Write extended,Append data

Registry Modifications

Key::Value Data API Name
HKCU\system\currentcontrolset\control\mediaproperties\privateproperties\directinput\vid_0627&pid_0001\calibration\0::guid 技쁶ᇰƀ䕄呓 RegNtPreCreateKey
HKCU\software\microsoft\directinput\58c178f99fce2e54a9a293d57994e7c9a6b1fb21_00005201926418d6290007f000::name 58C178F99FCE2E54A9A293D57994E7C9A6B1FB21_0000520192 RegNtPreCreateKey
HKCU\software\microsoft\directinput\58c178f99fce2e54a9a293d57994e7c9a6b1fb21_00005201926418d6290007f000::usesmapper RegNtPreCreateKey
HKCU\software\microsoft\directinput\mostrecentapplication::name 58C178F99FCE2E54A9A293D57994E7C9A6B1FB21_0000520192 RegNtPreCreateKey
HKCU\software\microsoft\directinput\mostrecentapplication::id 58C178F99FCE2E54A9A293D57994E7C9A6B1FB21_00005201926418D6290007F000 RegNtPreCreateKey
HKCU\software\microsoft\directinput\mostrecentapplication::version RegNtPreCreateKey
HKCU\software\microsoft\directinput\mostrecentapplication::mostrecentstart ᕅ郹覣ǜ RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
Show More
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\explorer\mountpoints2\##10.200.31.10#amas::_labelfromdesktopini RegNtPreCreateKey

Windows API Usage

Category API
Network Winsock2
  • WSASocket
  • WSAStartup
Network Winsock
  • closesocket
  • connect
  • freeaddrinfo
  • getaddrinfo
  • recv
  • send
  • setsockopt
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Keyboard Access
  • GetKeyState

Related Posts

Trending

Most Viewed

Loading...