Threat Database Stealers Trojan.MSIL.Stealer.RAR

Trojan.MSIL.Stealer.RAR

By CagedTech in Stealers, Trojans

Threat Scorecard

Popularity Rank: 10,886
Threat Level: 80 % (High)
Infected Computers: 2,995
First Seen: June 21, 2023
Last Seen: September 19, 2025
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.MSIL.Stealer.RAR
Signature status: No Signature

Known Samples

MD5: f2d12496f928e26d99ad0d21cbecf70b
SHA1: 0cdd316b77d22e772d0da8258962ecee606cbfce
SHA256: 252D2E3BA0F9C9662615096164F83E7444FDB7FDF11B173389CE25E0C422F944
File Size: 307.71 KB, 307712 bytes
MD5: 5ea0edb5e6545903bbb84e8f37691675
SHA1: c6c1ec6553e8ee43470dfe28d62d5cb190a98c90
SHA256: A22E9D1A812755313129E79468B71E10010820B52061AC1DAE89B34864295327
File Size: 307.71 KB, 307712 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version 1.1.21.1
Comments XHP Booster
File Description XHP
File Version 12.9.1.22
Internal Name Steanings.exe
Legal Copyright XHP Corporation Copyright © 2021
Original Filename Steanings.exe
Product Name XHP booster
Product Version 12.9.1.22

File Traits

  • .NET
  • x86

Block Information

Total Blocks: 489
Potentially Malicious Blocks: 219
Whitelisted Blocks: 186
Unknown Blocks: 84

Visual Map

x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x x x x x x 0 0 x 0 0 x x x x 0 0 0 0 x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 x x 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? x ? ? ? ? ? x x ? ? ? x 0 0 0 0 0 x 0 0 0 0 0 ? 0 x x 0 x 0 0 0 x x x ? 0 0 ? 0 x x x x x x x x x 0 x x x ? 0 0 ? 0 x x 0 x x ? x x x 0 x x x ? ? ? 0 x x 0 ? 0 0 x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x ? x 0 x ? ? x x x x ? x x x x x x x ? x x x x ? x x 0 x ? x x ? x x x x ? x x ? x ? ? ? ? ? ? 0 ? ? ? 0 0 0 ? ? ? ? ? ? ? 0 ? x x ? ? ? x x 0 x x x x x ? 0 ? 0 ? x x x x x x x x 0 0 x ? x x x ? ? ? 0 x x x x ? ? x ? ? ? ? ? ? ? ? ? ? ? x ? x ? ? x x x ? ? ? ? 0 x 0 0 0 0 0 x 0 0 0 x 0 0 0 x 0 0 0 0 x 0 x x x x x 0 0 0 0 ? x 0 x x x 0 x x x x x 0 x x 0 x 0 x x x x 0 0 x 0 0 0 x x x x x x x 0 0 0 0 x x x x x x x x x 0 0 x x x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x 0 x x x 0 x x 0 x 0 x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Stealer.RAR

Windows API Usage

Category API
User Data Access
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Encryption Used
  • BCryptOpenAlgorithmProvider

Trending

Most Viewed

Loading...