Threat Database Trojans Trojan.HorusEyesRAT.B

Trojan.HorusEyesRAT.B

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 6
First Seen: April 18, 2022
Last Seen: January 6, 2026
OS(es) Affected: Windows

Your system has been detected with a threat identified as Trojan.HorusEyesRAT.B, which indicates a potential security risk that requires immediate attention. This detection suggests that your computer may be compromised, and it's essential to understand the nature of this threat and take steps to remove it to protect your personal data and system integrity.

What Is Trojan.HorusEyesRAT.B?

Trojan.HorusEyesRAT.B is a type of malware that falls under the category of Trojans, which are malicious programs designed to gain unauthorized access to a computer system. The name itself does not directly indicate a specific malware family but suggests characteristics of Remote Access Trojans (RATs), which are known for allowing attackers to remotely control infected computers. This type of malware can be particularly dangerous as it can lead to data theft, unauthorized system modifications, and exploitation of system resources for malicious activities.

How Trojan.HorusEyesRAT.B Operates

Typically, Trojans like Trojan.HorusEyesRAT.B operate by disguising themselves as legitimate software or hiding within other programs. Once installed on a system, they can create backdoors that allow hackers to access the system remotely. This access can be used for a variety of malicious purposes, including stealing sensitive information, installing additional malware, or using the infected computer as part of a botnet for distributed denial-of-service (DDoS) attacks or spamming. The exact method of operation can vary, but the end goal is usually to exploit the infected system for financial gain or to cause disruption.

Symptoms of Infection

Symptoms of a Trojan infection can be subtle and may not always be immediately apparent. Common signs include unexpected changes to system settings, unfamiliar programs or icons, slow system performance, and increased network activity. In some cases, infected systems may display pop-ups, experience frequent crashes, or have issues with security software. However, some Trojans are designed to operate stealthily, making them difficult to detect without proper security tools.

How to Remove Trojan.HorusEyesRAT.B

  1. Enter Safe Mode with Networking to prevent the malware from spreading or interfering with the removal process. This mode allows you to use the internet to download removal tools while limiting the malware's ability to run.
  2. Download and run a full scan with a reputable anti-malware tool such as SpyHunter. Ensure the tool is updated to the latest version to increase the chances of detecting and removing the Trojan.
  3. Uninstall any suspicious programs that you do not recognize or that were installed around the time your system became infected. Be cautious and only remove programs you are sure are not necessary for your system's operation.
  4. Reset your web browsers (Chrome, Firefox, Edge) to their default settings. This can help remove any malicious extensions or settings changes made by the Trojan.
  5. Reboot your system and run another full scan with your anti-malware tool to ensure that the Trojan and any associated malware are completely removed.

Conclusion

Removing Trojan.HorusEyesRAT.B from your system is crucial to preventing further damage and protecting your personal data. By following the steps outlined above and maintaining good security practices, such as regularly updating your operating system and security software, being cautious with email attachments and downloads, and using strong, unique passwords, you can significantly reduce the risk of future infections. Remember, vigilance and proactive security measures are key to safeguarding your digital assets in today's evolving cyber threat landscape.

Analysis Report

General information

Family Name: Trojan.HorusEyesRAT.B
Signature status: No Signature

Known Samples

MD5: f31f806de2a192abf591bad0f3d618ee
SHA1: 14d2c0ea3ce5c4a30b6e1662c155fd8b265c536e
SHA256: 1FB7C9A3DE3D96FC0907F99226895571704A85007BCFDA02F843C95120AF7B42
File Size: 33.28 KB, 33280 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is .NET application
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 0.0.0.0
File Version 0.0.0.0
Internal Name Stub_64.exe
Original Filename Stub_64.exe
Product Version 0.0.0.0

File Traits

  • .NET
  • Agile.net
  • Fody
  • HighEntropy
  • ntdll
  • x64

Block Information

Total Blocks: 26
Potentially Malicious Blocks: 10
Whitelisted Blocks: 16
Unknown Blocks: 0

Visual Map

0 0 0 0 x 0 0 0 x x x x 0 x x x x x 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • HorusEyesRAT.B

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcConnectPortEx
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtCancelTimer2
  • ntdll.dll!NtCancelWaitCompletionPacket
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCompareSigningLevels
Show More
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateIoCompletion
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtCreateWaitCompletionPacket
  • ntdll.dll!NtCreateWorkerFactory
  • ntdll.dll!NtDelayExecution
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtGetCachedSigningLevel
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtNotifyChangeKey
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetThreadExecutionState
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtUnsubscribeWnfStateChange
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtYieldExecution
  • UNKNOWN
User Data Access
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Network Winsock2
  • WSAConnect
  • WSASocket
  • WSAStartup
  • WSAttemptAutodialName
Network Winsock
  • closesocket
  • freeaddrinfo
  • getaddrinfo
  • recv
  • send
  • setsockopt
Other Suspicious
  • AdjustTokenPrivileges

Trending

Most Viewed

Loading...