Threat Database Stealers Trojan.MSIL.Stealer.PA

Trojan.MSIL.Stealer.PA

By CagedTech in Stealers, Trojans

Threat Scorecard

Popularity Rank: 15,638
Threat Level: 80 % (High)
Infected Computers: 148
First Seen: February 18, 2023
Last Seen: February 10, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.MSIL.Stealer.PA
Signature status: No Signature

Known Samples

MD5: 7a7c85ea2fbf74786fef9c3cb93c69cb
SHA1: cceebbb996388d854beb254a48b5405f452dc584
SHA256: 6CAE1144E1350EF72553235C1D271A5599DFA2C575DAE7593C27EE961DE338F6
File Size: 15.87 KB, 15872 bytes
MD5: fab28671c7156d1acd4ae8e818e23af2
SHA1: e00cf32581fe13d954da362902a6a9d4c8087639
SHA256: D12A0D918C70DEBF5CF25F67DCB9879E7D3B48BE7BF7DB561E80314753BEF92B
File Size: 14.85 KB, 14848 bytes
MD5: 1759e81399785c82d8dce61f0c74d169
SHA1: 389825ec0914c16fbb0281f0d90d71ed031cc70f
SHA256: D8126DB1C41608ED9E126C4059568976B89B093F6BC00AF48268E6D9D58F21C3
File Size: 14.85 KB, 14848 bytes
MD5: 4610b34d475b4bfcefa50660d111c091
SHA1: d1943ce6d4d4a0ac912d2d95d0314e20fd8c811d
SHA256: 7EEBFCB1A54D04C7926F60DC1A20AC5F9B8EFEEBF75E801C7D8FA1A195EB65D0
File Size: 15.87 KB, 15872 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 1.0.0.0
File Description
  • ExceptionHandling
  • FrpLoader
  • WindowsApp5
  • WindowsApp6
File Version 1.0.0.0
Internal Name
  • ExceptionHandling.exe
  • FrpLoader.exe
  • WindowsApp5.exe
  • WindowsApp6.exe
Legal Copyright
  • Copyright © 2019
  • Copyright © 2023
  • Copyright © 2024
Original Filename
  • ExceptionHandling.exe
  • FrpLoader.exe
  • WindowsApp5.exe
  • WindowsApp6.exe
Product Name
  • ExceptionHandling
  • FrpLoader
  • WindowsApp5
  • WindowsApp6
Product Version 1.0.0.0

File Traits

  • .NET
  • x86

Block Information

Total Blocks: 43
Potentially Malicious Blocks: 0
Whitelisted Blocks: 41
Unknown Blocks: 2

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Agent.XGG
  • MSIL.BadJoke.F
  • MSIL.BadJoke.TN
  • MSIL.BadJoke.XF
  • MSIL.BadJoke.XH
Show More
  • MSIL.Brute.ME
  • MSIL.Brute.MEA
  • MSIL.Downloader.Tiny.CF
  • MSIL.Dropper.X
  • MSIL.Filecoder.XF
  • MSIL.HackAgent.XD
  • MSIL.Krypt.EEBT
  • MSIL.Krypt.FRA
  • MSIL.Krypt.JUB
  • MSIL.Krypt.MBCAG
  • MSIL.Krypt.MKC
  • MSIL.Krypt.MKD
  • MSIL.Kryptik.XB
  • MSIL.Perseus.P
  • MSIL.RunescapeHack.D

Windows API Usage

Category API
User Data Access
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Keyboard Access
  • GetKeyState
Encryption Used
  • BCryptOpenAlgorithmProvider

Trending

Most Viewed

Loading...