Threat Database Stealers Trojan.Stealer.ESA

Trojan.Stealer.ESA

By CagedTech in Stealers, Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 2
First Seen: August 15, 2025
Last Seen: February 12, 2026
OS(es) Affected: Windows

The detection of Trojan.Stealer.ESA on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the security of your computer and steal sensitive information. It is essential to understand the nature of this threat and take prompt action to remove it and prevent future infections.

What Is Trojan.Stealer.ESA?

Trojan.Stealer.ESA is a type of Trojan horse malware that can infect your computer through various means, such as downloading malicious software, opening infected email attachments, or visiting compromised websites. Once installed, it can hide in the background and perform malicious activities without your knowledge or consent. The primary goal of this malware is to steal sensitive information, such as login credentials, credit card numbers, and personal data, which can be used for identity theft, financial fraud, or other malicious purposes.

How Trojan.Stealer.ESA Operates

Trojan.Stealer.ESA operates by exploiting vulnerabilities in your system or using social engineering tactics to trick you into installing it. Once installed, it can communicate with its command and control servers to receive instructions and transmit stolen data. This malware can also install additional malicious components, such as keyloggers, screen scrapers, or ransomware, to further compromise your system. It may also attempt to disable your security software or firewall to avoid detection and removal.

Symptoms of Infection

The symptoms of a Trojan.Stealer.ESA infection can be subtle, but they may include unusual system behavior, such as slow performance, unexpected crashes, or unfamiliar programs running in the background. You may also notice suspicious network activity, such as unusual outgoing connections or data transfers. Additionally, you may receive alerts from your security software or notice that your personal data is being stolen or misused.

How to Remove Trojan.Stealer.ESA

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow you to download and install removal tools.
  2. Download and install a reputable anti-malware tool, such as SpyHunter, and perform a full scan of your system to detect and remove all instances of the malware.
  3. Uninstall any suspicious programs or applications that may be related to the malware.
  4. Reset your web browsers, such as Chrome, Firefox, or Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your computer and perform another full scan with your anti-malware tool to ensure that all remnants of the malware have been removed.

Conclusion

Removing Trojan.Stealer.ESA from your system requires careful attention to detail and a thorough understanding of the malware's behavior. By following the steps outlined above, you can effectively remove this threat and prevent future infections. It is essential to remain vigilant and take proactive measures to protect your system, such as keeping your operating system and software up to date, using strong antivirus software, and avoiding suspicious downloads or email attachments. By taking these precautions, you can help ensure the security and integrity of your personal data and prevent the spread of malware.

Analysis Report

General information

Family Name: Trojan.Stealer.ESA
Signature status: No Signature

Known Samples

MD5: 772f3680a96c2c1b4fac030f96b21bae
SHA1: 0882f11ef35fca39a205fcd8cd83efbbc00c6d43
SHA256: FFBC6B4D798A9755203D14EFB72BC64C34C92CD759083561B6F6E8064BB1EFF0
File Size: 999.02 KB, 999016 bytes
MD5: 029b2a0fabe089742945563e399f6ed8
SHA1: e623c82ef0c4cee54dd492ac7da1bf4230f9614e
SHA256: 166AD01E47F9264E5AECE8EC0433CD5459AE5546451FC5592CE9CCA0673CE73F
File Size: 1.40 MB, 1401856 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have resources
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Build I D NBVxTuDH-858174
Company Name Microsoft Corporation
File Description UwuGfL
File Version 10.0.19041.1
Internal Name iJV
Legal Copyright Microsoft Corporation. All rights reserved.
Legal Trademarks iJV is a Trademark of Microsoft Corporation.
Original Filename ucqonq.exe
Product Name THXf
Product Version 10.0.19041.1

Digital Signatures

Signer Root Status
Microsoft Windows Microsoft Windows Production PCA 2011 Hash Mismatch

File Traits

  • HighEntropy
  • No Version Info
  • ntdll
  • WriteProcessMemory
  • x64

Block Information

Total Blocks: 3,704
Potentially Malicious Blocks: 63
Whitelisted Blocks: 3,232
Unknown Blocks: 409

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? ? ? ? 0 0 0 ? 0 0 0 0 0 0 ? ? 0 ? 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 ? 0 0 ? 0 ? 0 ? 0 0 0 0 0 ? 0 ? 0 0 0 ? 0 0 ? 0 0 0 0 0 0 ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? ? 0 0 0 0 0 0 ? ? 0 ? 0 ? 0 0 ? 0 ? 0 0 0 0 ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 x 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 ? ? 0 ? ? 0 0 0 0 0 0 ? ? 0 0 0 0 0 ? 0 0 0 0 ? 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 ? 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? 0 0 ? ? 0 ? ? ? ? 0 ? ? 0 ? ? ? 0 0 ? 0 0 0 0 ? ? ? 0 0 ? ? 0 0 ? 0 0 ? ? 0 0 0 0 0 ? ? 0 ? 0 0 ? ? ? 0 ? ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? 0 0 0 0 0 0 ? 0 0 0 0 ? ? 0 ? 0 0 0 0 0 ? 0 ? ? 0 0 ? 0 ? 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x ? 0 0 0 ? 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? ? 0 0 ? 0 0 ? ? ? x ? 0 ? 0 0 0 ? ? 0 ? 0 ? 0 ? 0 0 ? ? ? 0 0 x 0 0 0 x ? ? 0 ? ? ? 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 ? ? ? x ? 0 ? ? ? 0 ? 0 ? ? ? ? ? ? 0 0 ? 0 0 0 0 0 ? ? 0 0 0 ? ? ? ? 0 ? 0 0 ? ? ? 0 ? ? ? 0 0 ? ? ? 0 0 ? ? 0 0 ? ? ? 0 0 0 ? ? 0 ? 0 0 0 ? ? 0 ? 0 ? 0 ? 0 0 0 ? ? 0 0 ? 0 0 0 0 0 ? x 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 ? ? 0 ? ? ? 0 0 0 ? ? 0 0 0 0 ? 0 ? ? ? 0 0 ? ? 0 0 0 0 0 0 ? ? ? 0 ? ? 0 0 0 0 0 0 0 ? ? ? ? ? 0 ? 0 ? ? 0 ? 0 ? 0 ? 0 ? ? 0 0 ? 0 0 ? ? 0 0 ? 0 0 ? ? 0 0 ? 0 0 ? 0 ? 0 0 ? ? ? x 0 0 0 ? ? 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? ? ? x ? 0 ? 0 ? 0 ? 0 ? 0 ? ? ? ? 0 0 0 0 0 ? 0 0 0 ? 0 0 ? 0 ? ? 0 0 ? 0 0 ? ? 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? 0 0 0 ? 0 0 0 0 ? ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? x ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? ? ? 0 ? 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 ? 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 ? 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 x 0 ? 0 0 ? 0 0 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 ? ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 ? 0 0 ? ? 0 ? 0 0 ? ? 0 0 ? ? 0 0 ? 0 ? 0 x 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Stealer.ESA

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtCreateTimer2
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
Show More
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationThread
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimerEx
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState
Process Shell Execute
  • CreateProcess
Process Manipulation Evasion
  • ReadProcessMemory
  • VirtualAllocEx

Shell Command Execution

C:\Windows\SysWOW64\dllhost.exe (NULL)

Trending

Most Viewed

Loading...