Threat Database Trojans Trojan.Sathurbot.AA

Trojan.Sathurbot.AA

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 32
First Seen: April 20, 2022
Last Seen: April 19, 2026
OS(es) Affected: Windows

The detection of Trojan.Sathurbot.AA on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the security and integrity of your computer, and it's essential to understand its nature and how to remove it effectively.

What Is Trojan.Sathurbot.AA?

Trojan.Sathurbot.AA is a type of Trojan horse malware, which is a broad category of malicious software that disguises itself as legitimate programs. Trojans are known for their ability to sneak into systems by exploiting vulnerabilities or through social engineering tactics, such as tricking users into downloading and installing them. The name Trojan.Sathurbot.AA itself does not directly indicate a specific malware family but suggests it is a variant of Trojan horse malware.

How Trojan.Sathurbot.AA Operates

Once installed, Trojan.Sathurbot.AA can operate in various ways, depending on its intended purpose. Trojans can create backdoors for remote access, allowing attackers to control the infected system, steal sensitive information, or use the system for malicious activities such as spamming, spreading malware, or participating in DDoS attacks. They can also install additional malware, modify system settings, and disrupt system performance.

Symptoms of Infection

Symptoms of a Trojan infection can vary widely but may include unusual system behavior, such as unexpected pop-ups, slow performance, frequent crashes, or unfamiliar programs running in the background. Users might also notice changes in their browser settings, new toolbars, or unexpected redirects to malicious websites. In some cases, the infection might not display any obvious symptoms, making it difficult to detect without proper security software.

How to Remove Trojan.Sathurbot.AA

  1. Start your computer in Safe Mode with Networking to prevent the malware from loading and to allow for a clean environment to perform removal steps.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. This can help identify and remove the malware and any associated files or registry entries.
  3. Uninstall suspicious programs that you do not recognize or that were installed around the time the malware was detected. Be cautious and only remove programs you are sure are not needed.
  4. Reset your browsers (Chrome, Firefox, Edge, etc.) to their default settings to remove any malicious extensions or settings changes made by the malware.
  5. After completing the above steps, reboot your system and perform another full scan with your anti-malware tool to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.Sathurbot.AA requires careful and thorough steps to ensure that all components of the malware are eliminated from your system. It's crucial to use reputable security software and follow safe removal practices to avoid causing further damage. After removal, maintaining good security practices, such as keeping your operating system and software up to date, using strong antivirus software, and being cautious with emails and downloads, can help protect your system from future infections.

Analysis Report

General information

Family Name: Trojan.Sathurbot.AA
Signature status: No Signature

Known Samples

MD5: 56396239ec798efee4135a33d59270c8
SHA1: e2f77e17247551f55abe30e4a0e3475bbb704c2f
SHA256: D5E420A71CFE4EABA3F25172B701BE8A759DB29AE0380720429703A7E447FE7E
File Size: 304.64 KB, 304640 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have security information
  • File has exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name RECOSO GmbH
File Description BAPrintManager - Dynamic Link Library (DLL)
File Version 14.12.0.1
Internal Name BAPrintManager.dll
Legal Copyright (c) RECOSO GmbH. Alle Rechte vorbehalten.
Original Filename BAPrintManager.dll
Product Name BAPrintManager
Product Version 14.12.0.1

File Traits

  • dll
  • x86

Block Information

Total Blocks: 758
Potentially Malicious Blocks: 8
Whitelisted Blocks: 373
Unknown Blocks: 377

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? ? ? ? ? 0 0 0 0 0 ? ? ? ? ? ? ? ? ? 0 0 ? ? 0 ? ? ? 0 ? 0 ? ? 0 ? ? ? ? ? ? 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? ? ? 0 0 0 ? x 0 0 ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? 0 ? ? ? ? ? 0 ? 0 ? ? ? ? ? 0 0 0 0 ? 0 0 0 1 0 0 0 ? 0 0 0 ? ? 0 0 0 ? ? 0 0 0 ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 ? ? 0 ? ? 0 ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 2 0 0 1 1 0 0 0 0 1 0 1 0 1 0 1 1 3 1 2 3 1 0 0 2 2 0 0 0 0 0 0 0 0 0 0 0 0 1 2 0 ? 0 0 ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? x ? x ? ? ? x 1 x 0 ? ? ? ? ? ? ? ? ? ? x ? ? ? x 1 x 0 ? ? ? ? ? ? ? ? ? 0 0 0 ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 1 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\e2f77e17247551f55abe30e4a0e3475bbb704c2f_0000304640.,LiQMAxHB

Trending

Most Viewed

Loading...