Threat Database Keyloggers Trojan.MSIL.Keylogger.EA

Trojan.MSIL.Keylogger.EA

By CagedTech in Keyloggers, Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 17
First Seen: May 25, 2021
Last Seen: December 26, 2021
OS(es) Affected: Windows

The detection of Trojan.MSIL.Keylogger.EA on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the security and privacy of your computer, and it's essential to understand its nature and how to remove it effectively.

What Is Trojan.MSIL.Keylogger.EA?

Trojan.MSIL.Keylogger.EA is a type of Trojan horse malware that is capable of logging keystrokes, which can lead to the theft of sensitive information such as passwords, credit card numbers, and other personal data. The name suggests that it is written in MSIL (Microsoft Intermediate Language), which is a platform-independent intermediate representation of the .NET Framework. This type of malware can be particularly dangerous as it can remain hidden on a system for an extended period, gathering sensitive information without the user's knowledge.

How Trojan.MSIL.Keylogger.EA Operates

Trojan.MSIL.Keylogger.EA operates by infiltrating a system, often through exploited vulnerabilities or social engineering tactics. Once inside, it can install itself in a way that makes it difficult to detect and remove. It may create fake system files, modify registry entries, or even disable security software to maintain its presence on the system. The primary goal of this malware is to capture keystrokes, which it can then transmit back to its command and control servers, potentially leading to identity theft, financial fraud, or other malicious activities.

Symptoms of Infection

Symptoms of a Trojan.MSIL.Keylogger.EA infection can be subtle and may not always be immediately apparent. However, some common indicators include unusual system behavior, such as slow performance, unexpected crashes, or unfamiliar programs running in the background. Users may also notice that their keyboard or mouse behaves erratically, or they might receive unexpected pop-ups or alerts. In some cases, the malware might attempt to connect to the internet without the user's knowledge, which could lead to increased data usage or suspicious network activity.

  • Unexplained system crashes or freezes
  • Slow system performance
  • Unfamiliar programs or icons
  • Erratic keyboard or mouse behavior
  • Unwanted pop-ups or alerts
  • Increased data usage or suspicious network activity

How to Remove Trojan.MSIL.Keylogger.EA

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for a clean removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. This will help identify and remove all components of the Trojan.MSIL.Keylogger.EA malware.
  3. Uninstall any suspicious programs that were installed around the time of the infection. Be cautious and only remove programs that you are certain are malicious or unnecessary.
  4. Reset your web browsers (Chrome, Firefox, Edge) to their default settings to remove any malicious extensions or settings that the malware may have altered.
  5. Reboot your computer and perform another full scan with your anti-malware tool to ensure that all remnants of the malware have been removed.

Conclusion

Removing Trojan.MSIL.Keylogger.EA requires a thorough and careful approach to ensure that all components of the malware are eliminated from your system. By following the steps outlined above and maintaining good security practices, such as keeping your operating system and software up to date, using strong and unique passwords, and being cautious with emails and downloads, you can protect your system from similar threats in the future. Remember, prevention and vigilance are key to maintaining the security and integrity of your computer and personal data.

Analysis Report

General information

Family Name: Trojan.MSIL.Keylogger.EA
Signature status: No Signature

Known Samples

MD5: f9d6762240e81a343cd6b5b4b2d68d42
SHA1: 42c46d929f4299edf9ba992c7e3bd74431f10e2d
SHA256: A93CFDD633323249E81A9AC36C9EF8948E44F34D21D26B97EF8A4DFF8CD96BE8
File Size: 96.26 KB, 96256 bytes
MD5: cd91b7c0bcbdd9e10dcde4b559e1b899
SHA1: a5123dc90d6b3b68bbe310e8cd3ec07f22be3004
SHA256: 2FD5A4D9B6AF17023C89D9D3D5595566A6ABD1B7E332C78DF74FF966C029641E
File Size: 385.54 KB, 385536 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
File Description
  • NFS Underground Race Trainer
  • SkullGirls - Yello Trainer
File Version 1.0.0.0
Internal Name
  • NFS Underground Race Trainer.exe
  • SkullGirls - Yello Trainer.exe
Legal Copyright
  • Copyright © 2014
  • Copyright © 2017
Original Filename
  • NFS Underground Race Trainer.exe
  • SkullGirls - Yello Trainer.exe
Product Name
  • NFS Underground Race Trainer
  • SkullGirls - Yello Trainer
Product Version 1.0.0.0

File Traits

  • .NET
  • HighEntropy
  • VirtualQueryEx
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 30
Potentially Malicious Blocks: 6
Whitelisted Blocks: 14
Unknown Blocks: 10

Visual Map

? ? ? ? ? ? 0 ? 0 0 0 0 ? x x 0 0 x x 0 x 0 0 x 0 ? ? 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Keylogger.EA

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreatePrivateNamespace
Show More
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtCreateThreadEx
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateKey
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenEvent
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDefaultLocale
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationJobObject
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtResumeThread
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationKey
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Other Suspicious
  • AdjustTokenPrivileges
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation

Related Posts

Trending

Most Viewed

Loading...