Threat Database Stealers Trojan.Stealer.BR

Trojan.Stealer.BR

By CagedTech in Stealers, Trojans

Threat Scorecard

Popularity Rank: 10,616
Threat Level: 80 % (High)
Infected Computers: 337
First Seen: September 3, 2022
Last Seen: June 9, 2026
OS(es) Affected: Windows

The detection of Trojan.Stealer.BR on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise your computer's security and steal sensitive information, making it essential to understand its nature and take steps to remove it. In this report, we will provide an overview of Trojan.Stealer.BR, its operating methods, symptoms of infection, and a step-by-step guide on how to remove it from your system.

What Is Trojan.Stealer.BR?

Trojan.Stealer.BR is a type of Trojan horse malware that disguises itself as a legitimate program or file to gain access to your computer. Once inside, it can cause significant harm by stealing sensitive information, such as login credentials, credit card numbers, and personal data. The name "Trojan.Stealer.BR" suggests that it is a type of malware that is designed to steal information, but the exact nature and capabilities of this specific threat are not well understood without further analysis.

How Trojan.Stealer.BR Operates

Trojan.Stealer.BR, like other Trojans, operates by exploiting vulnerabilities in your system or tricking you into installing it. It may arrive as an email attachment, a download from a compromised website, or a payload from another malware infection. Once installed, it can communicate with its command and control servers to receive instructions and transmit stolen data. The malware may also install additional components, such as keyloggers or screen scrapers, to gather more information.

Symptoms of Infection

Symptoms of a Trojan.Stealer.BR infection can vary, but common signs include unusual system behavior, such as slow performance, unexpected crashes, or unfamiliar programs running in the background. You may also notice suspicious network activity, such as unexpected outgoing connections or data transfers. In some cases, the malware may not exhibit any noticeable symptoms, making it difficult to detect without the aid of security software.

How to Remove Trojan.Stealer.BR

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for internet access. This will make it easier to download and install removal tools.
  2. Download and install a reputable anti-malware tool, such as SpyHunter, and perform a full scan of your system to detect and remove all components of the Trojan.Stealer.BR malware.
  3. Uninstall any suspicious programs or applications that you do not recognize or that were installed around the time of the infection. Be cautious when uninstalling programs, as some may be legitimate or required by your system.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or settings that the malware may have installed.
  5. Reboot your computer and perform another full scan with your anti-malware tool to ensure that all components of the malware have been removed.

Conclusion

Removing Trojan.Stealer.BR from your system requires careful attention to detail and a thorough understanding of the malware's operating methods. By following the steps outlined in this report, you can help to ensure the complete removal of the malware and prevent future infections. It is essential to remain vigilant and take proactive steps to protect your system, such as keeping your operating system and software up to date, using strong antivirus software, and avoiding suspicious downloads and email attachments. Remember, prevention is key to protecting your sensitive information and maintaining the security of your computer.

Analysis Report

General information

Family Name: Trojan.Stealer.BR
Signature status: No Signature

Known Samples

MD5: b7ef9d6e5b3fa256ee6c77de9eec0f83
SHA1: 4e43cadccbe6b78e524f69c09b0f9e721732a352
SHA256: 7EF1CFB3B8BAFFB2A3C594EDE8CA49B0E55E6D66A0CDCE38DEB315762AC1F73F
File Size: 657.92 KB, 657920 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name XOS Digital
File Description TS Source for Hemi Playback Engine
File Version 25.1.1.9
Internal Name TSSource.dll
Legal Copyright 2014 XOS Digital
Original Filename TSSource.dll
Product Name TSSource
Product Version 25.1

File Traits

  • dll
  • HighEntropy
  • x86

Block Information

Total Blocks: 1,719
Potentially Malicious Blocks: 1
Whitelisted Blocks: 1,481
Unknown Blocks: 237

Visual Map

? 0 0 0 0 0 0 ? 0 ? 0 ? ? ? ? ? ? ? ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? ? 0 ? 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 ? 0 0 ? ? ? ? ? ? 0 ? 0 ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 ? 0 ? 0 0 0 ? ? 0 ? ? ? 0 0 0 ? ? 0 0 0 0 0 0 0 ? 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 ? 0 ? 0 ? 0 0 ? 0 ? ? ? 0 ? ? ? 0 ? ? 0 ? 0 ? ? 0 ? ? ? ? 0 ? ? 0 0 0 ? 0 ? ? ? ? ? ? 0 0 0 ? 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 ? ? 0 0 0 ? 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 ? 0 ? ? ? 0 0 0 ? ? 0 0 0 0 ? 0 ? ? ? ? ? ? ? 0 0 0 0 0 ? ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 ? ? ? ? 0 0 ? 0 ? ? 0 0 0 0 0 ? ? ? 0 ? ? ? ? ? ? 1 ? 0 ? ? ? ? ? ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? ? ? ? ? ? ? 0 ? ? ? ? 0 ? ? ? 0 0 0 ? ? 0 0 0 0 0 0 0 ? 0 0 ? ? ? 0 0 ? ? ? ? 0 0 0 0 0 ? ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 0 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 0 0 ? 0 ? 0 0 ? ? 0 ? 0 ? 0 ? 0 0 ? ? ? ? ? ? ? ? 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 2 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 1 2 0 0 1 0 0 1 0 0 0 0 3 1 1 1 1 0 1 0 2 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 1 0 0 0 0 0 2 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWriteFile
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\4e43cadccbe6b78e524f69c09b0f9e721732a352_0000657920.,LiQMAxHB

Trending

Most Viewed

Loading...