Threat Database Stealers Trojan.Stealer.EJ

Trojan.Stealer.EJ

By CagedTech in Stealers, Trojans

Threat Scorecard

Popularity Rank: 11,399
Threat Level: 80 % (High)
Infected Computers: 515
First Seen: February 18, 2023
Last Seen: July 3, 2026
OS(es) Affected: Windows

The detection of Trojan.Stealer.EJ on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise your computer's security and steal sensitive information. It is essential to understand the nature of this threat and take prompt action to remove it and prevent further damage.

What Is Trojan.Stealer.EJ?

Trojan.Stealer.EJ is a type of Trojan horse malware that can infiltrate your system without your knowledge or consent. Trojans are malicious programs that disguise themselves as legitimate software, allowing them to bypass security measures and gain unauthorized access to your computer. The ".Stealer" part of the name suggests that this particular Trojan is designed to steal sensitive information, such as login credentials, financial data, or personal files.

How Trojan.Stealer.EJ Operates

Once installed, Trojan.Stealer.EJ can operate in the background, secretly collecting and transmitting sensitive information to its creators or other malicious actors. It may also download and install additional malware, create backdoors for remote access, or disrupt system performance. The exact mechanisms of Trojan.Stealer.EJ are not publicly known, but its primary goal is to compromise your system's security and exploit your personal data for malicious purposes.

Symptoms of Infection

Identifying a Trojan.Stealer.EJ infection can be challenging, as it may not exhibit obvious symptoms. However, you may notice unusual system behavior, such as slow performance, frequent crashes, or unfamiliar programs running in the background. You may also receive suspicious emails or messages, or notice unauthorized transactions on your financial statements. If you suspect that your system has been infected, it is crucial to take immediate action to contain and remove the threat.

How to Remove Trojan.Stealer.EJ

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for a more effective removal process.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all instances of Trojan.Stealer.EJ and any associated malware.
  3. Uninstall any suspicious programs or applications that may be related to the infection, as they may be malicious or compromised.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or plugins.
  5. Reboot your computer and perform another full scan to ensure that the malware has been completely removed and that your system is clean.

Conclusion

Removing Trojan.Stealer.EJ from your system requires careful attention and a thorough approach. By following the steps outlined above and taking proactive measures to secure your system, you can help prevent future infections and protect your sensitive information. Remember to stay vigilant and monitor your system's performance regularly to detect and respond to any potential security threats. It is also essential to keep your operating system, software, and security tools up to date to ensure you have the latest protections against emerging threats.

Analysis Report

General information

Family Name: Trojan.Stealer.EJ
Signature status: No Signature

Known Samples

MD5: 2ec5b0ba0f12d8cdec7fd4db4d571cdc
SHA1: 7c4309a9e5ca32283b1b181ab75017850a876d08
SHA256: 218E1B23C8BF1CE0DD8F7DB7E59FFC0ED5D30F3D7A37562BEE67012DA275C35C
File Size: 1.01 MB, 1014784 bytes
MD5: 0ea5a1a3c6296d3960b91083d708c640
SHA1: 8678909be2040234d2b542e306a413e4a5342286
SHA256: D1A99F8F6010AE8214AF25DF78A56B4ED880E1644652D5929BBB2C28F7FE8176
File Size: 1.12 MB, 1120768 bytes
MD5: b51a5a08d626c4504070344225eb2855
SHA1: 1afbe3d772dc50a67395c7a8371af2483b855e1e
SHA256: 2AC515C3C6FCC1F18D4DCC31ED001159F3DE40F0EA1BE9BDFCA383141CA24515
File Size: 5.37 MB, 5368320 bytes
MD5: 8ebd91cbb3a7c9ceaed98c6b436cba88
SHA1: 908f9dcbd3547673e9c499feba45772db8c60608
SHA256: 875A9D78E5D9F114EBE62566813E706A2E34DA4237D426D66023B2C84AFCC080
File Size: 994.30 KB, 994304 bytes
MD5: c7f4c93de830365273662017bea0035d
SHA1: 41f2effb855f3fe7cf331bab1d6ab7a7052919aa
SHA256: 9F6465E988AA5907F6FA820961BCDD1C4AC19D279DD4819B5D0BDE5CAD32C756
File Size: 175.10 KB, 175104 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • dll
  • GetConsoleWindow
  • HighEntropy
  • No Version Info
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 326
Potentially Malicious Blocks: 37
Whitelisted Blocks: 194
Unknown Blocks: 95

Visual Map

x 0 0 x x 0 0 x 0 0 x x x x x 0 x 0 ? 0 ? ? 0 0 x x x 0 x x x x x x ? ? x x ? ? ? ? ? ? ? ? ? ? ? 0 ? ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 x x 0 x 2 0 1 1 0 0 0 0 0 1 2 3 1 1 0 1 0 0 2 2 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? 0 ? ? ? ? ? x ? ? ? ? ? ? 0 0 x 0 ? ? ? 0 x ? x x 0 x ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? ? 0 ? ? ? ? ? ? 1 ? ? 0 ? x 0 ? ? 0 ? ? ? ? 0 ? ? ? ? ? ? ? 0 ? ? ? ? 0 0 x ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 ? ? 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 2 0 0 0 1 0 0 0 0 2 x x ? ? ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • DLAssistant.A
  • JuicyPotato.A
  • Linkury.BA
  • StartSurf.A
  • Turla.J

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWriteFile
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\41f2effb855f3fe7cf331bab1d6ab7a7052919aa_0000175104.,LiQMAxHB

Trending

Most Viewed

Loading...