Threat Database Stealers Trojan.Stealer.PA

Trojan.Stealer.PA

By CagedTech in Stealers, Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 132
First Seen: July 23, 2022
Last Seen: July 31, 2026
OS(es) Affected: Windows

The detection of Trojan.Stealer.PA on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise your computer's security and steal sensitive information, making it essential to understand its nature and take steps to remove it.

What Is Trojan.Stealer.PA?

Trojan.Stealer.PA is a type of Trojan horse malware that disguises itself as a legitimate program to gain access to your system. Once inside, it can cause significant damage by stealing personal data, such as login credentials, credit card numbers, and other sensitive information. The name "Trojan.Stealer.PA" suggests that it is a stealer-type Trojan, which is designed to extract and transmit sensitive data to its creators.

How Trojan.Stealer.PA Operates

Trojan.Stealer.PA operates by exploiting vulnerabilities in your system's security or by tricking you into installing it. It can spread through various means, including infected software downloads, phishing emails, or infected websites. Once installed, it can create a backdoor to allow remote access to your system, giving its creators control over your computer. This malware can also communicate with its command and control servers to receive updates and transmit stolen data.

Symptoms of Infection

Identifying the symptoms of a Trojan.Stealer.PA infection can be challenging, as it is designed to remain stealthy. However, some common signs of infection include unusual system behavior, such as slow performance, frequent crashes, or unfamiliar programs running in the background. You may also notice that your personal data is being stolen or that your online accounts are being accessed without your permission. Additionally, your system may exhibit signs of unauthorized access, such as changed passwords or new user accounts.

  • Unexplained changes to your system settings or configuration
  • New, unfamiliar programs or icons on your desktop
  • Unexpected pop-ups or advertisements
  • Slow system performance or frequent crashes

How to Remove Trojan.Stealer.PA

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow you to download removal tools
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove the malware
  3. Uninstall any suspicious programs or applications that may be related to the infection
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons
  5. Reboot your system and perform another full scan to ensure that the malware has been completely removed

Conclusion

Removing Trojan.Stealer.PA from your system requires careful attention to detail and a thorough understanding of its operating methods. By following the steps outlined above and taking proactive measures to secure your system, you can help prevent future infections and protect your sensitive data. Remember to always use reputable anti-malware tools and to keep your operating system and software up to date to minimize the risk of infection. Additionally, being cautious when clicking on links or downloading attachments from unknown sources can help prevent the spread of malware.

Analysis Report

General information

Family Name: Trojan.Stealer.PA
Signature status: No Signature

Known Samples

MD5: 0fab95c5f4a27145e0506af4f798e19b
SHA1: f4995ba9bb690b056e3c7660e71546bcabbaaa0d
SHA256: 720EBC146E17DFE595FEEB97F1077D34FE5719E92B583153748F4FCD77102842
File Size: 67.07 KB, 67072 bytes
MD5: 22784951da250c52cd88968fa01762b8
SHA1: a5fcb78ec690babe9afaa63215491b3ee30c8b31
SHA256: 8B31058AC2630EA81FB859FAE12F7F782E945D02F263C4D468C80F7AAB196729
File Size: 71.68 KB, 71680 bytes
MD5: 8006081be64bd8d1a1b21a917a26dec4
SHA1: 17ed0cd93c101cbd4e06a33dff41a21f9154a7d1
SHA256: 0DE5DEC87A3FC536543BF75F72E4033746C7B3992F7FEAB50A8CBFC60A227F7B
File Size: 72.70 KB, 72704 bytes
MD5: 67ae604fc37e3abe9fdbc8ab0a3a037e
SHA1: 19d84e847d2312a3b828b5dcfeea8a307716d455
SHA256: 579CA960457D8D6C09990BE343EC7DA43BE7E69C4213203C462BFC7D93564B28
File Size: 19.46 KB, 19456 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have resources
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • dll
  • x86

Block Information

Total Blocks: 85
Potentially Malicious Blocks: 14
Whitelisted Blocks: 56
Unknown Blocks: 15

Visual Map

x 0 0 0 ? x x x x x x x x x 0 x ? ? 0 0 ? x 0 ? ? ? ? ? ? ? ? ? ? ? x x 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 2 1 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtProtectVirtualMemory
Show More
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\f4995ba9bb690b056e3c7660e71546bcabbaaa0d_0000067072.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\a5fcb78ec690babe9afaa63215491b3ee30c8b31_0000071680.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\17ed0cd93c101cbd4e06a33dff41a21f9154a7d1_0000072704.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\19d84e847d2312a3b828b5dcfeea8a307716d455_0000019456.,LiQMAxHB