Threat Database Trojans Trojan.Lumma.EJ

Trojan.Lumma.EJ

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 4
First Seen: June 26, 2025
Last Seen: November 21, 2025
OS(es) Affected: Windows

The detection of Trojan.Lumma.EJ on your system indicates a potential security threat. This report aims to provide you with general guidance on understanding and removing the detected threat. It's essential to approach this situation with caution and follow the recommended steps to ensure the security of your system and data.

What Is Trojan.Lumma.EJ?

Trojan.Lumma.EJ is identified as a Trojan-type threat, which typically refers to a broad category of malicious software that can allow unauthorized access to a computer system. Trojans can be used to steal sensitive information, install additional malware, or provide a backdoor for remote access. The name itself does not directly indicate a specific malware family but suggests it is part of the Trojan category, known for its deceptive nature and potential to cause significant harm.

How Trojan.Lumma.EJ Operates

Trojan.Lumma.EJ, like other Trojans, likely operates by disguising itself as legitimate software or attaching itself to legitimate programs to gain entry into a system. Once inside, it can execute a variety of malicious actions, depending on its design and the intentions of its creators. This can include data theft, espionage, or the installation of additional malware to further compromise the system. The exact mechanisms and goals of Trojan.Lumma.EJ are not specified here, as the focus is on general guidance for removal and system protection.

Symptoms of Infection

Symptoms of a Trojan infection can vary widely but may include unusual system behavior, such as slow performance, frequent crashes, or the appearance of unwanted programs or toolbars in your web browser. You might also notice that your system is connecting to the internet without your input, or you may receive notifications from your security software indicating the detection of malware. However, some Trojans are designed to operate stealthily, making them difficult to detect without specific security tools.

How to Remove Trojan.Lumma.EJ

  1. Boot into Safe Mode with Networking: This will help prevent the malware from loading and make it easier to remove. To do this, restart your computer and press the key to access your boot menu (this varies by computer but is often F8, F12, or Del). Select Safe Mode with Networking and let your computer boot up.
  2. Perform a Full Scan with a Reputable Tool: Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. This can help identify and remove the Trojan and any other malware that might be present.
  3. Uninstall Suspicious Programs: Go through your installed programs and uninstall anything that looks suspicious or unfamiliar. Be cautious, as some legitimate programs might have similar names to malicious ones.
  4. Reset Your Web Browsers: Resetting your web browsers (Google Chrome, Mozilla Firefox, Microsoft Edge) to their default settings can help remove any malicious extensions or settings that the Trojan might have installed. You can usually find this option in the browser's settings or preferences menu.
  5. Reboot and Re-scan: After completing the above steps, reboot your computer and perform another scan with your anti-malware tool to ensure that the threat has been successfully removed.

Conclusion

Removing Trojan.Lumma.EJ requires a methodical approach to ensure that all components of the malware are eliminated from your system. By following the steps outlined above and maintaining vigilance in your online activities, you can help protect your system and data from future threats. Regularly updating your operating system, browsers, and security software, as well as being cautious when opening emails or downloading software from the internet, are crucial practices for preventing malware infections.

Analysis Report

General information

Family Name: Trojan.Lumma.EJ
Signature status: Hash Mismatch

Known Samples

MD5: e7321d215acc1313c29a6c8829d0bd5e
SHA1: 43660c726d4b0f42daada8cff083e865acb4101c
SHA256: A3A9B4B7B501210BDADC7DB6DEC6B596ABFCD57E824EE09BB4C1CE5160CE0695
File Size: 5.94 MB, 5941152 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Comments Acronis True Image Shell Extensions
Company Name Acronis
File Description Acronis True Image Shell Extensions
File Version 20,0,1,3260
Internal Name tishell
Legal Copyright Copyright (C) 2000-2024 Acronis"
Legal Trademarks Acronis
Original Filename tishell.dll
Product Name Acronis True Image
Product Version 20,0,1,3260

Digital Signatures

Signer Root Status
Acronis International GmbH DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Hash Mismatch

File Traits

  • big overlay
  • dll
  • HighEntropy
  • x86

Block Information

Total Blocks: 73
Potentially Malicious Blocks: 3
Whitelisted Blocks: 69
Unknown Blocks: 1

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.LFU
  • Lumma.EJ

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtProtectVirtualMemory
Show More
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\43660c726d4b0f42daada8cff083e865acb4101c_0005941152.,LiQMAxHB

Trending

Most Viewed

Loading...