Threat Database Hacktool Hacktool.MSIL.DiscordStealer.CG

Hacktool.MSIL.DiscordStealer.CG

By CagedTech in Hacktool, Stealers

Threat Scorecard

Threat Level: 50 % (Medium)
Infected Computers: 1
First Seen: March 3, 2023
Last Seen: December 22, 2025
OS(es) Affected: Windows

The detection of Hacktool.MSIL.DiscordStealer.CG on your system indicates a potential security threat. This detection name suggests that the malware is designed to steal sensitive information, particularly from Discord users. It is essential to understand the nature of this threat and take immediate action to remove it from your system.

What Is Hacktool.MSIL.DiscordStealer.CG?

Hacktool.MSIL.DiscordStealer.CG is a type of malicious software, or malware, that is categorized as a hacktool. Hacktools are programs designed to help attackers gain unauthorized access to systems, steal sensitive information, or disrupt normal system operations. The fact that this malware is named after Discord, a popular communication platform, implies that it may be specifically designed to target users of this service.

How Hacktool.MSIL.DiscordStealer.CG Operates

Malware like Hacktool.MSIL.DiscordStealer.CG typically operates by exploiting vulnerabilities in software or manipulating user behavior to gain access to sensitive information. Once installed on a system, it may attempt to steal login credentials, personal data, or other valuable information. It could also potentially install additional malware or create backdoors for remote access. Understanding how such malware operates is crucial for taking effective measures to protect your system and data.

Symptoms of Infection

Identifying the symptoms of a malware infection can be challenging, as many types of malware are designed to operate stealthily. However, common indicators of infection include unusual system behavior, such as unexpected pop-ups, slow system performance, or unfamiliar programs running in the background. If you suspect that your system has been infected with Hacktool.MSIL.DiscordStealer.CG, it is crucial to act promptly to minimize potential damage.

How to Remove Hacktool.MSIL.DiscordStealer.CG

  1. Boot your system into Safe Mode with Networking to prevent the malware from loading and to allow for internet access. This will make it easier to download and install removal tools.
  2. Download and run a full scan with a reputable anti-malware tool, such as SpyHunter, to detect and remove the malware. Ensure the tool is updated with the latest definitions to improve detection and removal capabilities.
  3. Uninstall any suspicious programs that you do not recognize or that were installed around the time the malware was detected. Be cautious and only remove programs you are certain are not necessary for your system's operation.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings. This can help remove any malicious extensions or settings that the malware may have altered.
  5. After completing the above steps, reboot your system and perform another full scan with your anti-malware tool to ensure that the malware has been completely removed.

Conclusion

Removing Hacktool.MSIL.DiscordStealer.CG from your system requires careful attention to detail and a systematic approach. By understanding the nature of this threat and following the steps outlined above, you can help protect your system and sensitive information from potential harm. Remember, prevention is key; keeping your software up to date, using strong passwords, and being cautious with links and downloads can significantly reduce the risk of future infections.

Analysis Report

General information

Family Name: Hacktool.MSIL.DiscordStealer.CG
Signature status: No Signature

Known Samples

MD5: efb406d15a4b966e21053bd5a353bbfe
SHA1: 20f0069095f068803a12a0740e5f280b9f79174e
SHA256: 9DB06B9EC30B63D325732DA4A384D40537DD193D78A7374228F1FC5ABAA8BB09
File Size: 2.56 MB, 2563072 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.0.1.2
File Description FarsisazInstaller
File Version 1.0.1.2
Internal Name FarsisazInstaller.exe
Legal Copyright Copyright © 2021
Original Filename FarsisazInstaller.exe
Product Name FarsisazInstaller
Product Version 1.0.1.2

File Traits

  • .NET
  • HighEntropy
  • Installer Version
  • RijndaelManaged
  • SmartAssembly
  • x86

Block Information

Total Blocks: 1,693
Potentially Malicious Blocks: 754
Whitelisted Blocks: 939
Unknown Blocks: 0

Visual Map

0 x x 0 x x 0 x x x x x x x x x x 0 x x 0 x x x 0 0 0 0 x 0 x 0 0 0 x 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 x x x 0 x x x 0 x x x x 0 0 x x x 0 x x x 0 x x x 0 x 0 0 x x 0 0 0 x 0 0 0 0 0 0 x x x 0 0 0 x x x x 0 0 0 0 0 0 x x 0 x 0 x x x x x 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 0 0 x x x 0 x 0 0 x 0 x 0 x 0 0 0 0 0 0 x 0 0 x 0 x 0 0 0 0 0 0 0 0 0 x 0 x 0 0 x 0 0 x 0 x x 0 x 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 x x x x x x x x x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 x 0 x x 0 0 0 0 0 0 0 0 0 x x 0 0 0 x x 0 x 0 0 0 x x x 0 0 x 0 x x x x x x x x x 0 x 0 0 x 0 0 x x x x x 0 0 0 0 x 0 0 0 0 0 0 x x x 0 0 x x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x 0 0 0 0 0 x 0 x x 0 0 x 0 0 x x 0 0 0 0 0 0 x x 0 0 x 0 0 0 x x x x 0 x 0 0 0 0 x x x 0 0 x 0 0 x x x x x x 0 x x 0 0 0 0 0 0 x x 0 x x x 0 x x x x 0 0 x 0 x 0 0 0 x 0 0 0 x 0 x x x x x 0 0 x 0 0 0 0 0 x x 0 x x x x x 0 x 0 x x x 0 x x 0 x 0 x 0 0 x 0 x x 0 x x 0 x 0 x 0 0 x x x 0 0 0 0 x x x x 0 0 x x x x 0 x x 0 0 0 0 0 0 x 0 0 x x x x x x x x x 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 x 0 x 0 0 x x x x 0 0 0 0 x 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x 0 0 0 x x 0 x 0 0 0 x 0 x 0 x 0 x 0 0 x x x x x x x x 0 x x x 0 x x 0 0 x 0 x x x x x 0 x 0 x x 0 0 0 x 0 x 0 0 x 0 x x x x 0 x x x x 0 x x x x x 0 x 0 x x 0 x 0 x x x x x x 0 x x x x 0 x x x 0 0 x x x 0 0 0 x 0 x x x x x x x 0 x x 0 x x x x 0 x x x x 0 0 x x 0 x x 0 0 x x x 0 x x 0 x x 0 x x x x 0 x x 0 x x 0 x x x x x x x x x x x 0 x x x x x x x x x x 0 0 x x x 0 x x x x x 0 x x x 0 x 0 x x 0 0 0 0 x 0 x x x x 0 x 0 0 x 0 x x 0 x x x 0 0 0 x 0 x x x 0 0 x x 0 x x x 0 x x x x 0 x x x x x x 0 x x x x x 0 x x x x x 0 x x x x x 0 x 0 x x x 0 x x x x x x x 0 x 0 x x x 0 x 0 x x 0 0 x 0 x x x 0 x 0 x x x x 0 0 x x x 0 x 0 x 0 0 x x x x x x x x x x x x x x x x x x x x x x 0 x 0 x 0 x x x 0 x 0 0 x x 0 x x x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x 0 x 0 0 x x x x 0 x 0 x x x x 0 x x x 0 x 0 0 0 x 0 x 0 x x x x 0 x x x 0 x x x x 0 x x x 0 0 x x 0 x x x x x x 0 0 x 0 0 x 0 x x x x 0 x 0 x 0 0 0 0 x 0 x x 0 0 x 0 x x x x x x 0 x x x x 0 0 x x 0 x x 0 x 0 0 x x x x x 0 x x x x 0 x 0 0 0 0 x 0 x x x x x x x 0 x x x 0 x x 0 x x x 0 0 0 x 0 x x x x 0 0 0 0 0 x x x x x x 0 x x x x x x x x x 0 0 x x x x x x 0 x 0 x x 0 0 x x x x x 0 x x x x 0 x x 0 x x x x x 0 x x x x x x 0 0 x x x x x x x x 0 0 x x x x x x x x x 0 x 0 0 x x 0 0 0 x x 0 0 x x 0 x 0 x x 0 x x x 0 x x 0 x x x x 0 0 x x x 0 x 0 x x x x 0 x x 0 0 0 x x 0 x x x x x 0 x x x 0 0 x x x 0 x 0 x x x x x x 0 0 x x x x x x x x x x x 0 x x 0 0 0 0 0 0 0 x 0 x 0 0 x 0 x x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.DiscordStealer.CG

Registry Modifications

Key::Value Data API Name
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 k�8��8tX��B �� �v 5� xy ��T�B������������5����ee��Bx�< �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9�/��0P%1�1HO1�D5�G6�^6��9ߔ;��=�>3� RegNtPreCreateKey

Windows API Usage

Category API
User Data Access
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation

Related Posts

Trending

Most Viewed

Loading...