Threat Database Keyloggers Keylogger.Refog.A

Keylogger.Refog.A

By CagedTech in Keyloggers

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 167
First Seen: June 26, 2019
Last Seen: March 10, 2026
OS(es) Affected: Windows

The detection of Keylogger.Refog.A on your system indicates a potential threat to your security and privacy. This detection name suggests a type of malicious software designed to capture and record keystrokes, which can lead to serious consequences such as identity theft and unauthorized access to sensitive information. It is essential to understand the nature of this threat and take immediate action to remove it from your system.

What Is Keylogger.Refog.A?

Keylogger.Refog.A is a type of Trojan horse malware that is designed to secretly monitor and record keystrokes on an infected computer. The primary purpose of this malware is to steal sensitive information such as login credentials, credit card numbers, and other personal data. The name "Keylogger" refers to its ability to log keystrokes, while "Refog.A" may indicate a specific variant or detection signature. It is crucial to note that the exact nature and capabilities of Keylogger.Refog.A can vary, but its primary goal is to compromise user privacy and security.

How Keylogger.Refog.A Operates

Keylogger.Refog.A operates by installing itself on a victim's computer, often through exploited vulnerabilities, phishing attacks, or other forms of social engineering. Once installed, it can start monitoring and recording keystrokes, potentially capturing sensitive information. This malware may also have the ability to transmit the recorded data to a remote server or attacker, allowing them to access the stolen information. The malware may run in the background, making it difficult to detect without proper security software.

Symptoms of Infection

Symptoms of a Keylogger.Refog.A infection can be subtle, but they may include unusual system behavior, slow performance, or unexpected pop-ups and advertisements. In some cases, the malware may cause system crashes or freezes, especially if it is not designed to operate stealthily. However, the most significant symptom is the potential theft of sensitive information, which may not be immediately apparent. It is essential to be vigilant and monitor your system for any suspicious activity, especially if you notice unusual transactions or account activity.

How to Remove Keylogger.Refog.A

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for a more effective removal process.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove Keylogger.Refog.A and any related malware.
  3. Uninstall any suspicious programs or applications that may be related to the malware, as they may be used to reinstall or reactivate the threat.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons that may be associated with the malware.
  5. Reboot your computer and perform another full scan to ensure that the malware has been completely removed and that your system is clean.

Conclusion

Removing Keylogger.Refog.A from your system requires immediate attention and a thorough approach. By following the steps outlined above and using reputable security software, you can help ensure the removal of this malware and protect your sensitive information. It is also essential to practice good security habits, such as regularly updating your operating system and software, using strong passwords, and being cautious when clicking on links or downloading attachments. Remember, prevention and vigilance are key to protecting your digital security and privacy.

Analysis Report

General information

Family Name: Keylogger.Refog.A
Signature status: No Signature

Known Samples

MD5: dcfba43f6058247556b3d8c6a5a6e864
SHA1: 1f569022fcc518d12427095e0bd9684988a7aa22
SHA256: 939D2E9D960F12D7A4FDCD486D465C7862F43EAB0970307A9F32EB3EE63B1F5C
File Size: 578.56 KB, 578560 bytes
MD5: 821b88785772905d96f17826c79208d9
SHA1: c0e9525a19ade8dd6c86cf36a77761ccccdba300
SHA256: 5661E7D5D408751F3B4CD6F90981464CFBF68C3F737E92313FC7B3386FFB24B5
File Size: 578.56 KB, 578560 bytes
MD5: 7f5ce2d8c9149fa8c57f52903b8c8880
SHA1: 4d80a316abba0574fbe937d78f6a3c58969e0f0a
SHA256: 33797592CEEEEB3AEC93DBD2567377D796B30EF8E0BF9DC62EF6BEECC1822F59
File Size: 578.56 KB, 578560 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have security information
  • File has exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
File Version
  • 9.5.2.4800
  • 9.5.0.4600
  • 9.4.7.4500
Product Version
  • 9.5.2.4800
  • 9.5.0.4600
  • 9.4.7.4500

File Traits

  • dll
  • x86

Block Information

Total Blocks: 1,105
Potentially Malicious Blocks: 87
Whitelisted Blocks: 1,018
Unknown Blocks: 0

Visual Map

0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x x 0 0 0 0 0 x x x x 0 0 0 x x x x x x 0 x 0 x x x x x 0 0 x x x 0 0 0 0 0 0 0 0 x x 0 0 x x 0 0 0 x x x 0 0 0 0 0 0 0 0 x 0 x x x 0 x x x x x x x x x 0 x x x 0 x 0 x x 0 x x x x 0 x x x 0 0 0 0 0 x 0 0 0 x x x x x x 0 x x 0 x x 0 x x x x x x x x x 0 0 x x x x x x 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 1 0 0 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 1 1 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 2 3 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 1 1 0 0 1 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 1 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtProtectVirtualMemory
Show More
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\1f569022fcc518d12427095e0bd9684988a7aa22_0000578560.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\c0e9525a19ade8dd6c86cf36a77761ccccdba300_0000578560.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\4d80a316abba0574fbe937d78f6a3c58969e0f0a_0000578560.,LiQMAxHB

Related Posts

Trending

Most Viewed

Loading...