Threat Database Stealers Trojan.MSIL.Stealer.G

Trojan.MSIL.Stealer.G

By CagedTech in Stealers, Trojans

Threat Scorecard

Popularity Rank: 15,982
Threat Level: 80 % (High)
Infected Computers: 34
First Seen: November 7, 2021
Last Seen: May 28, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.Stealer.G on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise your computer's security and steal sensitive information, making it essential to understand its nature and take prompt action to remove it.

What Is Trojan.MSIL.Stealer.G?

Trojan.MSIL.Stealer.G is a type of Trojan horse malware that can infect your computer through various means, such as malicious downloads, infected software, or exploited vulnerabilities. The name "Trojan" refers to the malware's ability to disguise itself as a legitimate program or file, allowing it to bypass security measures and gain unauthorized access to your system. The ".MSIL" part of the name suggests that the malware is written in Microsoft Intermediate Language, which is a platform-agnostic intermediate representation of the .NET Framework.

How Trojan.MSIL.Stealer.G Operates

Once installed, Trojan.MSIL.Stealer.G can operate in the background, collecting sensitive information such as login credentials, credit card numbers, and personal data. It may also install additional malware, create backdoors for remote access, or modify system settings to disable security features. The malware can communicate with its command and control servers to receive updates, send stolen data, or receive instructions from its operators. Its primary goal is to remain undetected while stealing valuable information or using your computer for malicious activities.

Symptoms of Infection

Identifying a Trojan.MSIL.Stealer.G infection can be challenging, as it often disguises itself as a legitimate program. However, some common symptoms may include unusual system behavior, such as slow performance, frequent crashes, or unfamiliar programs running in the background. You may also notice suspicious network activity, unexpected pop-ups, or changes to your browser settings. If you suspect that your computer is infected, it is crucial to take immediate action to prevent further damage.

How to Remove Trojan.MSIL.Stealer.G

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for a more effective removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malicious files or programs.
  3. Uninstall any suspicious programs or applications that you do not recognize or that were installed without your knowledge.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your computer and perform another full scan with your anti-malware tool to ensure that all remnants of the malware have been removed.

Conclusion

Removing Trojan.MSIL.Stealer.G from your system requires careful attention to detail and a thorough understanding of the malware's behavior. By following the steps outlined above and using reputable security tools, you can effectively remove the malware and prevent future infections. It is essential to remain vigilant and take proactive measures to protect your computer and sensitive information from malware threats. Regularly updating your operating system, using strong antivirus software, and practicing safe browsing habits can help prevent similar infections in the future.

Analysis Report

General information

Family Name: Trojan.MSIL.Stealer.G
Signature status: No Signature

Known Samples

MD5: da77a69b3712d71d22bb858a08b914d0
SHA1: 8ce0f8112c2e44bbb13585e70f0c95805e8cbb9d
File Size: 1.98 MB, 1977344 bytes
MD5: 0ab7d3712b8ff8258fddb81529bd5e0a
SHA1: e87b9735bd50adfb8615cbe902c7c8536e595ef2
SHA256: 47A7C262821B702C4E9FB3F48D15C8D061FA564BD2ABD857CE67CBF4C78CBC97
File Size: 15.36 KB, 15360 bytes
MD5: e825dda85a3adea1b63abd550676fe5c
SHA1: 22ce8253048adb58c8264dcc199e52fca3976a00
SHA256: BA24F6D66A40FFA0D735356565E88593E36DDBE5333A79825F980CB745F41DC0
File Size: 542.72 KB, 542720 bytes
MD5: a57b9dc915e09354772b061d211e3f08
SHA1: 90344afe4c4a90cfe589b1325d6b2de70d97a5db
SHA256: 153443F28D22C4DF78C60CF6F22FF372DB2D1CC2CE08F585BAA15ED6E3543941
File Size: 897.54 KB, 897536 bytes
MD5: 21b511b201d4e9b6565a92fcb31aa587
SHA1: 269919001d525dd659415cb2046606e843ead5f1
SHA256: 782C8D2117DFC85861C9CDBB75CA5F228F175930BE26E234C40D8381D617CA4C
File Size: 28.16 KB, 28160 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 2.41.1.0
  • 1.0.0.0
Comments
  • Generate Chrome/Android ESN
  • Tray tool for NZBHydra
Company Name
  • NetflixESNGenerator
  • RezWare
  • TheOtherP
  • WinFormsApp1
File Description
  • Battle Cats save editor
  • NetflixESNGenerator
  • NZBHydraTray
  • RezWare
  • WinFormsApp1
File Version
  • 2.41.1
  • 1.0.0.0
Internal Name
  • Battle Cats save editor.exe
  • NetflixESNGenerator.dll
  • NZBHydraTray.exe
  • RezWare.dll
  • WinFormsApp1.dll
Legal Copyright
  • Copyright © 2022
  • https://github.com/theotherp/nzbhydra
Original Filename
  • Battle Cats save editor.exe
  • NetflixESNGenerator.dll
  • NZBHydraTray.exe
  • RezWare.dll
  • WinFormsApp1.dll
Product Name
  • Battle Cats save editor
  • NetflixESNGenerator
  • NZBHydra
  • RezWare
  • WinFormsApp1
Product Version
  • 2.41.1
  • 1.0.0.0
  • 1.0.0

File Traits

  • .NET
  • Agile.net
  • Fody
  • HighEntropy
  • Pastebin
  • x64
  • x86

Block Information

Total Blocks: 29
Potentially Malicious Blocks: 1
Whitelisted Blocks: 12
Unknown Blocks: 16

Visual Map

0 0 0 0 0 0 ? ? 0 ? 0 ? 0 ? x ? ? ? ? ? ? 0 0 ? ? ? ? ? 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
\device\namedpipe Generic Read,Write Attributes
\device\namedpipe Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\wow6432node\microsoft\tracing::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enablefiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enableautofiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::maxfilesize  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::filedirectory %windir%\tracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enablefiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enableautofiletracing RegNtPreCreateKey
Show More
HKLM\software\wow6432node\microsoft\tracing\rasmancs::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::maxfilesize  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasmancs::filedirectory %windir%\tracing RegNtPreCreateKey

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateThreadEx
Show More
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
User Data Access
  • GetComputerName
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Other Suspicious
  • AdjustTokenPrivileges
Network Winsock2
  • WSAConnect
  • WSASocket
  • WSAStartup
  • WSAttemptAutodialName
Network Winsock
  • closesocket
  • freeaddrinfo
  • getaddrinfo
  • recv
  • send
  • setsockopt
Network Winhttp
  • WinHttpOpen
Network Info Queried
  • GetAdaptersAddresses
  • GetNetworkParams
Encryption Used
  • BCryptOpenAlgorithmProvider
Process Shell Execute
  • CreateProcess

Shell Command Execution

"nzbhydra.exe"

Related Posts

Trending

Most Viewed

Loading...