Threat Database Trojans Trojan.Keatep.A

Trojan.Keatep.A

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 18,182
Threat Level: 80 % (High)
Infected Computers: 112
First Seen: December 24, 2018
Last Seen: July 20, 2026
OS(es) Affected: Windows

The detection of Trojan.Keatep.A on your system indicates a potential security threat that requires immediate attention. Trojan-type threats are known for their ability to disguise themselves as legitimate software, making them difficult to detect and remove. In this report, we will provide an overview of the Trojan.Keatep.A threat, its operating methods, symptoms of infection, and steps to remove it from your system.

What Is Trojan.Keatep.A?

Trojan.Keatep.A is a type of malware that can compromise the security of your system by allowing unauthorized access to your data and taking control of your computer. The name "Trojan" refers to the fact that this type of malware often disguises itself as a legitimate program or file, making it difficult for users to detect. Trojan.Keatep.A can be used to steal sensitive information, install additional malware, or disrupt system operations.

How Trojan.Keatep.A Operates

Trojan.Keatep.A operates by exploiting vulnerabilities in your system or by tricking users into installing it voluntarily. Once installed, it can communicate with its command and control servers to receive instructions and transmit stolen data. Trojan.Keatep.A can also install additional malware or create backdoors to allow other malicious programs to enter your system. Its operating methods can vary, but the primary goal is to remain undetected while stealing sensitive information or disrupting system operations.

Symptoms of Infection

Symptoms of a Trojan.Keatep.A infection can vary, but common indicators include slow system performance, unexpected pop-ups or ads, and unfamiliar programs or icons on your desktop. You may also experience data loss, corrupted files, or unauthorized changes to your system settings. In some cases, the infection may not exhibit any noticeable symptoms, making it difficult to detect without the use of antivirus software.

  • Unexplained changes to system settings or files
  • Slow system performance or crashes
  • Unexpected pop-ups, ads, or browser redirects
  • Data loss or corrupted files
  • Unfamiliar programs or icons on your desktop

How to Remove Trojan.Keatep.A

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for internet access.
  2. Perform a full scan of your system using a reputable antivirus tool, such as SpyHunter, to detect and remove the Trojan.Keatep.A infection.
  3. Uninstall any suspicious programs or applications that may be related to the infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform another full scan to ensure that the infection has been completely removed.

Conclusion

The removal of Trojan.Keatep.A requires careful attention to detail and a comprehensive approach to ensure that the infection is completely eliminated. By following the steps outlined in this report, you can help protect your system and sensitive data from the potential risks associated with this type of malware. It is essential to remain vigilant and to regularly scan your system for potential threats to prevent future infections. Remember to always use reputable antivirus software and to keep your operating system and applications up to date to reduce the risk of infection.

Analysis Report

General information

Family Name: Trojan.Keatep.A
Signature status: No Signature

Known Samples

MD5: e0ff054e59cf104848752f9b59c16259
SHA1: fe92c5f7a410b1dc97ebc8b0b07d331dae907195
SHA256: D311B9FD39C91A6E4E94DAAE68E41A4D603BE5401ECD4064F2CEF79F13A2480E
File Size: 123.39 KB, 123392 bytes
MD5: 9127aa021a641f52fc27ad593217ddc4
SHA1: 4f443953b76ad32af1207aaf6b25e6ea556b34fb
SHA256: 1EDE6192FFC1E8B7ADE2E975AF39F5BCCCD0D1DAE410A60AF07FA2A2E602137E
File Size: 123.39 KB, 123392 bytes
MD5: 3d98e3e1e65337fa8f65bdce00fe28a1
SHA1: 80fb157d18dd31a965cabe95cae0584929a6f706
SHA256: 15997F5A3D512254BBFC9FE06B35F046027A9A2203662E0137A8810576880FD9
File Size: 123.39 KB, 123392 bytes
MD5: 8ad342762b67d97dbcfbce63634d635d
SHA1: 7957900fdd7c60bca336586f672d018d165d23a2
SHA256: DF88623A1487A584B75BB6ECBB62B8810495E521AE16C02CCF111570A339AD9B
File Size: 123.39 KB, 123392 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have resources
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • dll
  • HighEntropy
  • x86

Block Information

Total Blocks: 4
Potentially Malicious Blocks: 3
Whitelisted Blocks: 1
Unknown Blocks: 0

Visual Map

x x x 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Keatep.A
  • Pramro.B

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\users\user\appdata\local\temp\20bcad.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\5c49.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\6c5c1c.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\b0573f.exe Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\explorer\advanced::hidden  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center::antivirusoverride  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center::antivirusdisablenotify  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center::firewalldisablenotify  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center::firewalloverride  RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtProtectVirtualMemory
Show More
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\fe92c5f7a410b1dc97ebc8b0b07d331dae907195_0000123392.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\4f443953b76ad32af1207aaf6b25e6ea556b34fb_0000123392.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\80fb157d18dd31a965cabe95cae0584929a6f706_0000123392.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\7957900fdd7c60bca336586f672d018d165d23a2_0000123392.,LiQMAxHB

Related Posts

Trending

Most Viewed

Loading...