Threat Database Stealers Trojan.Stealer.ACJ

Trojan.Stealer.ACJ

By CagedTech in Stealers, Trojans

Threat Scorecard

Popularity Rank: 23,635
Threat Level: 80 % (High)
Infected Computers: 3
First Seen: July 14, 2023
Last Seen: May 23, 2026
OS(es) Affected: Windows

The detection of Trojan.Stealer.ACJ on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise your computer's security and steal sensitive information, making it essential to understand its nature and take prompt action to remove it.

What Is Trojan.Stealer.ACJ?

Trojan.Stealer.ACJ is a type of Trojan horse malware that can infect your computer through various means, such as exploited vulnerabilities, phishing emails, or infected software downloads. Once inside, it can cause significant harm by stealing personal data, logging keystrokes, and potentially allowing unauthorized access to your system. The "Trojan" part of its name refers to its ability to disguise itself as legitimate software, making it difficult to detect without proper security tools.

How Trojan.Stealer.ACJ Operates

Upon infection, Trojan.Stealer.ACJ can operate in the background, hidden from the user's view. It may communicate with its command and control servers to receive updates or send stolen data. This malware can also create backdoors, allowing hackers to access your system remotely and perform malicious activities. Its primary goal is to gather sensitive information, such as login credentials, credit card numbers, or other personal data, which can be used for identity theft, financial fraud, or other malicious purposes.

Symptoms of Infection

Identifying a Trojan.Stealer.ACJ infection can be challenging, as it often does not display obvious symptoms. However, you may notice unusual system behavior, such as slow performance, frequent crashes, or unfamiliar programs running in the background. Additionally, you might receive unexpected pop-ups, experience unusual network activity, or find unfamiliar icons on your desktop. If you suspect that your system has been compromised, it is crucial to take immediate action to mitigate potential damage.

  • Unexplained system crashes or freezes
  • New, unfamiliar programs or icons
  • Increased network activity without apparent cause
  • Pop-ups or unexpected ads
  • Slow system performance

How to Remove Trojan.Stealer.ACJ

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for internet access for updates and scanning.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all instances of the malware.
  3. Uninstall any suspicious programs that you do not recognize or that were installed around the time of the suspected infection.
  4. Reset your web browsers (Chrome, Firefox, Edge) to their default settings to remove any malicious extensions or settings changes made by the malware.
  5. Reboot your computer and perform another full scan to ensure that all remnants of the malware have been removed.

Conclusion

Removing Trojan.Stealer.ACJ from your system requires careful and immediate action to prevent further damage. By following the steps outlined above and maintaining good security practices, such as keeping your operating system and software up to date, using strong antivirus software, and being cautious with emails and downloads, you can significantly reduce the risk of future infections. Remember, vigilance and proactive security measures are key to protecting your digital assets and personal information in today's evolving cybersecurity landscape.

Analysis Report

General information

Family Name: Trojan.Stealer.ACJ
Signature status: No Signature

Known Samples

MD5: 2b9d9f2fa62a0763b3853dc50b8227c8
SHA1: 2f24b6ec5f765e4c41a0b3f99c11a02061205cf3
SHA256: D7E0EA803AD2C7AC5ACF5B8B92A4741E92E2492C169318161FA28D4FFBCCE34D
File Size: 776.70 KB, 776704 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Microsoft Corporation
File Description Win32 Cabinet Self-Extractor
File Version 11.00.17763.1 (WinBuild.160101.0800)
Internal Name Wextract
Legal Copyright © Microsoft Corporation. All rights reserved.
Original Filename WEXTRACT.EXE .MUI
Product Name Internet Explorer
Product Version 11.00.17763.1

File Traits

  • HighEntropy
  • No Version Info
  • x86

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\k6944499.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\k6944499.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\tmp4351$.tmp Generic Write,Read Attributes,Delete
c:\users\user\appdata\local\temp\ixp000.tmp\x8580166.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\x8580166.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp001.tmp\j4123810.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp001.tmp\j4123810.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp001.tmp\tmp4351$.tmp Generic Write,Read Attributes,Delete
c:\users\user\appdata\local\temp\ixp001.tmp\x3486125.exe Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\ixp001.tmp\x3486125.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp002.tmp\g0308721.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp002.tmp\g0308721.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp002.tmp\i5501530.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp002.tmp\i5501530.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp002.tmp\tmp4351$.tmp Generic Write,Read Attributes,Delete

Registry Modifications

Key::Value Data API Name
HKLM\software\wow6432node\microsoft\windows\currentversion\runonce::wextract_cleanup0 rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Sljphiab\AppData\Local\Temp\IXP000.TMP\" RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\runonce::wextract_cleanup1 rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Sljphiab\AppData\Local\Temp\IXP001.TMP\" RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\runonce::wextract_cleanup2 rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Sljphiab\AppData\Local\Temp\IXP002.TMP\" RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 鶳ǜ RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
Show More
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Process Terminate
  • TerminateProcess

Shell Command Execution

C:\Users\Sljphiab\AppData\Local\Temp\IXP000.TMP\x8580166.exe
C:\Users\Sljphiab\AppData\Local\Temp\IXP001.TMP\x3486125.exe
C:\Users\Sljphiab\AppData\Local\Temp\IXP002.TMP\g0308721.exe

Trending

Most Viewed

Loading...