Threat Database Stealers Trojan.MSIL.DiscordStealer.N

Trojan.MSIL.DiscordStealer.N

By CagedTech in Stealers, Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 41
First Seen: February 20, 2022
Last Seen: April 2, 2026
OS(es) Affected: Windows

The detection of Trojan.MSIL.DiscordStealer.N indicates that your system has been compromised by a malicious threat. This type of malware is designed to steal sensitive information, including login credentials and other personal data. It is essential to take immediate action to remove the threat and prevent further damage.

What Is Trojan.MSIL.DiscordStealer.N?

Trojan.MSIL.DiscordStealer.N is a type of Trojan horse malware that is designed to infiltrate a system and steal sensitive information. The name suggests that it may be related to Discord, a popular communication platform, but the exact nature of the threat is not immediately clear. What is known is that this malware is capable of causing significant harm to a system and its users.

How Trojan.MSIL.DiscordStealer.N Operates

Trojan.MSIL.DiscordStealer.N operates by infiltrating a system and establishing a connection with its command and control server. From there, it can receive instructions and transmit stolen data back to the attackers. The malware may use various techniques to evade detection, including disguising itself as a legitimate program or hiding in the system's temporary files. Once installed, the malware can begin to steal sensitive information, including login credentials, credit card numbers, and other personal data.

Symptoms of Infection

The symptoms of a Trojan.MSIL.DiscordStealer.N infection can be subtle, but they may include unusual system behavior, such as slow performance, frequent crashes, or unfamiliar programs appearing on the system. Users may also notice that their login credentials are not working or that their personal data is being used without their permission. In some cases, the malware may also display fake error messages or alerts in an attempt to trick the user into revealing sensitive information.

  • Unusual system behavior, such as slow performance or frequent crashes
  • Unfamiliar programs or icons appearing on the system
  • Login credentials not working or being used without permission
  • Fake error messages or alerts

How to Remove Trojan.MSIL.DiscordStealer.N

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter
  3. Uninstall any suspicious programs or applications that may be related to the malware
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings
  5. Reboot your system and perform another scan to ensure that the malware has been completely removed

Conclusion

Removing Trojan.MSIL.DiscordStealer.N from your system requires immediate attention and careful action. By following the steps outlined above, you can help to ensure that the malware is completely removed and that your system is protected from further harm. It is also essential to take steps to prevent future infections, including keeping your operating system and software up to date, using strong passwords, and being cautious when opening email attachments or clicking on links from unfamiliar sources. By taking these precautions, you can help to protect your system and your personal data from the threats posed by Trojan.MSIL.DiscordStealer.N and other types of malware.

Analysis Report

General information

Family Name: Trojan.MSIL.DiscordStealer.N
Signature status: No Signature

Known Samples

MD5: df95d6893c86424fb0838497f97d8bd9
SHA1: da4d984338a880dd79bcbed60ba946d1e03cbabe
SHA256: ED470E7D150876FD529027C58AE814F0F463A477AFA23DF1C93AAFC89F545A3F
File Size: 665.60 KB, 665600 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
File Description learn_c++_in_cs
File Version 1.0.0.0
Internal Name learn_c___in_cs.exe
Legal Copyright Copyright © 2021
Original Filename learn_c___in_cs.exe
Product Name learn_c++_in_cs
Product Version 1.0.0.0

File Traits

  • .NET
  • CreateThread
  • HighEntropy
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 53
Potentially Malicious Blocks: 37
Whitelisted Blocks: 13
Unknown Blocks: 3

Visual Map

0 x x ? x x x x x x ? x x x 0 0 0 x x 0 x x x x x 0 x 0 x x x x x x x x x x x x x x 0 ? 0 0 0 0 0 x x x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.DiscordStealer.N

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtDuplicateObject
Show More
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN
User Data Access
  • GetComputerNameEx
  • GetUserObjectInformation

Related Posts

Trending

Most Viewed

Loading...