Threat Database Stealers Trojan.Stealer.GZG

Trojan.Stealer.GZG

By CagedTech in Stealers, Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 24
First Seen: December 1, 2023
Last Seen: February 4, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Stealer.GZG
Signature status: No Signature

Known Samples

MD5: 363d22dfaafc89d80418127f3051a4c4
SHA1: 8fb54f43942ad30e6d5aea63077dc4a177e032b4
File Size: 99.33 KB, 99328 bytes
MD5: b6b642dd838c5a6fee793cf963359f37
SHA1: d0c9c21f269f85ea9c0cce07f24dca77214da324
SHA256: E4E8870C0AF201364E327C56A591B809AF1CE08B897015ADFADC444332F28C41
File Size: 107.01 KB, 107008 bytes
MD5: c5d36819bb9370060c0ad4ada642ae2b
SHA1: 4213c1f0871192a5c1d46fa11f0965e8cb4ce94c
SHA256: FE4B463181B08801D0ADD16B366C1328292BF8385C26F9B2C4429794D85B4212
File Size: 92.16 KB, 92160 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • 2+ executable sections
  • JMC
  • No Version Info
  • x64

Block Information

Total Blocks: 215
Potentially Malicious Blocks: 0
Whitelisted Blocks: 214
Unknown Blocks: 1

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.FYM
  • Agent.KFF
  • Agent.LEC
  • HackKMS.LN
  • Injector.GFDC
Show More
  • Injector.KUB
  • ReverseShell.XE
  • Shellcode.BX
  • ShellcodeRunner.LD
  • ShellcodeRunner.LR
  • Trojan.Agent.Gen.AOM
  • Trojan.Agent.Gen.YG
  • Trojan.ShellcodeRunner.Gen.CW

Trending

Most Viewed

Loading...