Threat Database Stealers Trojan.Stealer.HI

Trojan.Stealer.HI

By CagedTech in Stealers, Trojans

Threat Scorecard

Popularity Rank: 22,280
Threat Level: 80 % (High)
Infected Computers: 7
First Seen: September 1, 2021
Last Seen: April 20, 2026
OS(es) Affected: Windows

The detection of Trojan.Stealer.HI indicates a potential security threat to your system. This report provides an overview of the threat, its characteristics, and steps to remove it. It is essential to address this issue promptly to prevent further damage or unauthorized access to your sensitive information.

What Is Trojan.Stealer.HI?

Trojan.Stealer.HI is a type of Trojan threat, which is a broad category of malware that can perform various malicious activities on an infected system. The name "Trojan" refers to the fact that this type of malware often disguises itself as legitimate software or hides within other programs to gain unauthorized access to a system. The ".Stealer" part of the name suggests that this particular threat may be designed to steal sensitive information, such as login credentials, financial data, or personal details.

How Trojan.Stealer.HI Operates

Trojan.Stealer.HI, like other Trojans, can operate in various ways, depending on its design and purpose. It may spread through infected software downloads, suspicious email attachments, or exploited vulnerabilities in the system or applications. Once inside, it can create backdoors for remote access, install additional malware, or modify system settings to evade detection. The threat may also communicate with its command and control servers to receive updates or send stolen data.

Symptoms of Infection

Identifying a Trojan infection can be challenging, as these threats often hide in the background and may not exhibit obvious symptoms. However, some common indicators of a potential Trojan infection include unusual system behavior, such as slow performance, frequent crashes, or unfamiliar programs running in the background. You might also notice unexpected changes to your system settings, new toolbars or extensions in your web browser, or suspicious network activity. If you suspect that your system has been infected with Trojan.Stealer.HI, it is crucial to take immediate action to remove the threat.

How to Remove Trojan.Stealer.HI

  1. Boot your system in Safe Mode with Networking to limit the malware's ability to interfere with the removal process.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all components of the Trojan.
  3. Uninstall any suspicious programs or applications that you do not recognize or that were installed without your consent.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or settings changes.
  5. Reboot your system and perform another full scan to ensure that all remnants of the malware have been removed.

Conclusion

Removing Trojan.Stealer.HI requires careful and thorough steps to ensure that all components of the malware are eliminated from your system. By following the guidance provided in this report and using reputable security tools, you can help protect your system and sensitive information from further harm. It is also essential to maintain good security practices, such as keeping your operating system and software up to date, using strong passwords, and being cautious when opening email attachments or downloading software from the internet. Regular system scans and backups can also help prevent and mitigate the effects of future malware infections.

Analysis Report

General information

Family Name: Trojan.Stealer.HI
Signature status: No Signature

Known Samples

MD5: 71c13d3cf7d12f013d4627841b2d5c28
SHA1: 017dd4a5450298d014a2102ef38633ef443cb1aa
SHA256: 3806EBD7FF35D1C9703F9ADD0BA32ADE41763D7A8851BCA5BBDEB076DB8B071F
File Size: 1.51 MB, 1507328 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
File Description CLedShowDemo Microsoft 基础类应用程序
File Version 1, 0, 0, 1
Internal Name CLedShowDemo
Legal Copyright 版权所有 (C) 2004
Original Filename CLedShowDemo.EXE
Product Name CLedShowDemo 应用程序
Product Version 1, 0, 0, 1

File Traits

  • HighEntropy
  • x86

Block Information

Total Blocks: 528
Potentially Malicious Blocks: 234
Whitelisted Blocks: 294
Unknown Blocks: 0

Visual Map

x x x x x 0 x x x x x 0 x x x 0 0 x 0 x 0 x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x x x 0 0 x 0 0 0 x 0 0 0 0 x 0 0 x x 0 x 0 x 0 0 x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 x 0 x 0 0 x x x 0 x x x x 0 x x x x x x x x x x x 0 0 0 x x x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x x x 0 0 x 0 0 x x x x 0 x 0 0 0 0 x 0 0 0 x x 0 0 0 0 x 0 0 0 x 0 x x x 0 x 0 x x x x 0 0 0 x x x 0 x x x x x 0 0 x x 0 x x 0 x 0 x 0 0 x 0 x x x x x x x x x 0 0 0 x x x x 0 0 0 0 0 0 x 0 x x 0 x x x x x 0 x x 0 x x x x x x 0 x x 0 x 0 x x x 0 x x x 0 x 0 x x x x x x x x x 0 0 0 x 0 x x x 0 x x 0 x 0 0 0 0 0 x x 0 0 0 0 0 0 x x 0 x x x x 0 0 0 0 0 0 x x 0 x x x x x x x x 0 0 0 0 x 0 x 0 x x x 0 x x x x x x x 0 x x x x 0 x 0 x x 0 x 0 0 x x 0 x x 0 0 0 x 0 0 x x 0 x x x 0 0 0 0 0 0 0 x 0 0 x x 0 x x x x x x 0 x 0 x 0 0 x x 0 0 0 0 0 x x x 0 x x x x x x x 0 x 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Stealer.HI

Files Modified

File Attributes
c:\users\user\downloads\017dd4a5450298d014a2102ef38633ef443cb1aa_0001507328 Synchronize,Write Attributes
c:\windows\syswow64\dumdu.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\dumdu.exe Synchronize,Write Attributes

Registry Modifications

Key::Value Data API Name
HKLM\system\select::marktime 2025-11-25 17:27 RegNtPreCreateKey

Windows API Usage

Category API
Service Control
  • OpenSCManager
  • OpenService
  • StartService
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess

Shell Command Execution

C:\WINDOWS\system32\cmd.exe /c ping -n 2 127.0.0.1 > nul && del c:\users\user\DOWNLO~1\017DD4~1 > nul

Trending

Most Viewed

Loading...