Threat Database Trojans Trojan.Grandoreiro.L

Trojan.Grandoreiro.L

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 4
First Seen: January 2, 2026
Last Seen: April 8, 2026
OS(es) Affected: Windows

The detection of Trojan.Grandoreiro.L on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the security and integrity of your computer, and it is essential to understand its nature and take steps to remove it to prevent further damage.

What Is Trojan.Grandoreiro.L?

Trojan.Grandoreiro.L is a type of Trojan horse malware, which is a broad category of malicious software that disguises itself as legitimate programs. Trojans are known for their ability to deceive users into installing them, often by masquerading as useful applications or hiding within other software. Once installed, Trojans can perform a wide range of malicious activities, from stealing sensitive information to providing unauthorized access to the infected computer.

How Trojan.Grandoreiro.L Operates

The exact operational details of Trojan.Grandoreiro.L can vary, but like other Trojans, it likely operates by exploiting vulnerabilities in software or manipulating user behavior to gain unauthorized access to the system. After gaining access, the malware can communicate with its command and control servers to receive instructions, which might include downloading additional malware, stealing personal data, or using the infected computer as part of a botnet for distributed denial-of-service (DDoS) attacks or spamming.

Symptoms of Infection

Identifying a Trojan infection can be challenging due to its stealthy nature. However, some common symptoms may indicate the presence of malware like Trojan.Grandoreiro.L. These include unexpected changes in system performance, such as slower operation, frequent crashes, or unusual network activity. Additionally, you might notice new, unfamiliar programs or toolbars in your browser, or find that your browser's homepage has been changed without your consent. In some cases, the malware might trigger pop-ups or display fake alerts to deceive you into installing more malicious software or revealing sensitive information.

How to Remove Trojan.Grandoreiro.L

  1. Boot into Safe Mode with Networking: This will help prevent the malware from loading and give you a cleaner environment to perform the removal process. To do this, restart your computer, and as it boots up, press the F8 key repeatedly until you see the Advanced Boot Options menu. Select Safe Mode with Networking and press Enter.
  2. Perform a Full Scan with a Reputable Tool: Use an anti-malware tool, such as SpyHunter, that is capable of detecting and removing Trojans. Ensure the tool is updated with the latest definitions before running the scan. This will help identify and remove the malware and any related components.
  3. Uninstall Suspicious Programs: Go through the list of installed programs on your computer and uninstall any that you do not recognize or that were installed around the time the symptoms appeared.
  4. Reset Your Browser Settings: Malware often targets browsers, so resetting them to their default settings can help remove malicious extensions or settings. For Chrome, Firefox, and Edge, you can find the reset option in their respective settings or preferences menus.
  5. Reboot and Re-scan: After completing the above steps, restart your computer in normal mode and perform another scan with your anti-malware tool to ensure that all traces of the malware have been removed.

Conclusion

Removing Trojan.Grandoreiro.L from your system requires a combination of technical knowledge and the right tools. By following the steps outlined above and maintaining vigilance in your online activities, you can significantly reduce the risk of future infections. Remember, prevention is key, so always be cautious when downloading software, avoid suspicious links or emails, and keep your operating system and applications updated with the latest security patches.

Analysis Report

General information

Family Name: Trojan.Grandoreiro.L
Signature status: No Signature

Known Samples

MD5: 9dde93c917f42af6696c0465e8ef4c72
SHA1: ffec24e9fce0d6d3baf9338d70fea9f8edd4fec2
SHA256: B1CC2683561A46DE3159CB4C98C7B1F606639AC0B1F6E6E82713FBAFA9E274CD
File Size: 562.69 KB, 562688 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have resources
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • dll
  • HighEntropy
  • x86

Block Information

Total Blocks: 2,409
Potentially Malicious Blocks: 519
Whitelisted Blocks: 1,890
Unknown Blocks: 0

Visual Map

0 x x x 0 0 x 1 0 x x 0 0 x x 0 x x x x x 0 x 0 0 x x 0 x 0 x x 0 0 x x 0 0 x x x 0 0 0 x 0 0 0 0 0 0 0 0 x x x x x 0 x x x x x x x x 0 x x 0 x x x x x 0 x x 1 0 0 x x x x x x x x 0 x x x x x 0 x 0 0 0 x x 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 x 0 x x 1 x x x x x 0 x x x x 0 x x 0 0 0 x x x x x 0 x 0 0 x x x x x x 0 x x x 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 x x 0 0 x 0 0 x x 0 x 0 x x x x x 0 0 0 0 0 x x x 0 0 x x x 0 x 0 x x x x x 0 0 0 x 0 0 x x x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 x x x x 0 0 0 0 0 x x x x x 0 x x 0 x x 1 0 0 0 0 0 x 0 0 0 0 x 0 x x x 0 0 0 0 0 x x x x 0 0 x 0 x 0 0 0 0 x 0 0 0 x 0 0 0 x x 0 x 0 x x 0 x x x x x x x 0 x x x x x 0 0 x x x x x x x x x x x x x x 0 x x x x 0 x x x 0 0 0 0 0 x 0 x x x x x x x x x x x x x x 0 x x x x 0 0 x x 0 x x x x 1 x 0 x 0 0 x 0 x x x x 0 0 0 0 0 0 x 0 x 0 0 x x x x x x x x 1 x x x x x x x 0 0 0 0 x 0 0 0 x x 0 0 0 x 0 0 x x x x x 1 1 1 1 1 1 1 x x x x x x 1 1 0 x x x x x x x 0 x x x x 0 x x x x x x x x x x x x x x 0 x x x x 0 x x 0 x x x 0 x x x x x 0 x x x 0 x x 0 0 x x x x x x x x x x x 0 x x x x 0 x x x 0 x x x 0 x 0 0 0 x x x x x x x 0 x 0 0 x x x x x x x x 0 0 0 0 0 x 0 x 0 0 0 x x 0 0 x x x x x x x x 0 0 0 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 x x x x x x x x x x x x x x x 0 0 0 0 0 x 0 x 0 0 0 0 0 x x x x x x x x x x x 0 0 0 x x x 0 x x x x x x x x 0 0 x 0 0 x x x x 0 x x x 0 0 0 0 0 x x x 0 0 0 0 x x x 0 0 x x x x x x 0 x x x x x x x x x x x x x x x 0 0 0 x 0 0 0 1 1 1 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 1 3 1 1 1 1 0 1 0 0 1 0 0 0 0 2 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 1 0 0 0 2 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 2 2 0 2 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\ffec24e9fce0d6d3baf9338d70fea9f8edd4fec2_0000562688.,LiQMAxHB

Related Posts

Trending

Most Viewed

Loading...