Threat Database Stealers Trojan.Stealer.KF

Trojan.Stealer.KF

By CagedTech in Stealers, Trojans

Threat Scorecard

Popularity Rank: 5,151
Threat Level: 80 % (High)
Infected Computers: 1,744
First Seen: November 6, 2023
Last Seen: July 31, 2026
OS(es) Affected: Windows

The detection of Trojan.Stealer.KF on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise your computer's security and potentially steal sensitive information. It is essential to understand the nature of this threat and take prompt action to remove it and prevent future infections.

What Is Trojan.Stealer.KF?

Trojan.Stealer.KF is a type of Trojan horse malware that can infect your computer through various means, such as exploited vulnerabilities, phishing attacks, or drive-by downloads. Once installed, it can operate stealthily, making it challenging to detect without proper security software. The primary goal of this malware is to gather sensitive information, including login credentials, financial data, and other personal details.

How Trojan.Stealer.KF Operates

Trojan.Stealer.KF operates by exploiting system vulnerabilities or using social engineering tactics to gain access to your computer. It can then establish a connection with its command and control server, allowing attackers to remotely control your system and steal sensitive information. This malware can also install additional malicious components, such as keyloggers or screen scrapers, to further compromise your security.

Symptoms of Infection

Identifying the symptoms of a Trojan.Stealer.KF infection can be challenging, as it is designed to operate stealthily. However, some common indicators of infection include slow system performance, unexpected pop-ups or advertisements, and unusual network activity. You may also notice that your browser or other applications are behaving erratically or crashing frequently. If you suspect that your system is infected, it is crucial to take immediate action to remove the malware.

How to Remove Trojan.Stealer.KF

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for a more effective removal process.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malicious components.
  3. Uninstall any suspicious programs or applications that may be related to the infection.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your computer and perform another full scan with your anti-malware tool to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.Stealer.KF from your system requires a comprehensive approach that involves using reputable security software, uninstalling suspicious programs, and resetting your web browsers. It is essential to take prompt action to prevent further damage and protect your sensitive information. By following the steps outlined above, you can help ensure the removal of this malware and prevent future infections. Remember to always keep your operating system, software, and security tools up-to-date to prevent exploitation of known vulnerabilities. Additionally, practice safe browsing habits, such as avoiding suspicious links and attachments, to reduce the risk of infection.

Analysis Report

General information

Family Name: Trojan.Stealer.KF
Signature status: No Signature

Known Samples

MD5: 523246923f4cf6c9aa7d8ccc0356e5d9
SHA1: 2b8601842226052cebda839827c7afd5ad489965
SHA256: 7184E9B024DB42300EF6F96472AE8C29A8A0CDE604DB1523512DAB51622F3BE0
File Size: 904.88 KB, 904880 bytes
MD5: eb718d5ee15f7a1b12c22402c295878d
SHA1: 854d432e6047e097354efa55d47011e9d514b0cb
SHA256: 553B8E15C78348C4A6C1981C1EFD78EC6B1E2B104F4E37E2A070568F4AB12C2F
File Size: 1.07 MB, 1074880 bytes
MD5: f0c3bb2a56ef8b268ec54fe185dfe902
SHA1: 3aeaba8a095ef2652abfd779fedb2c4505d4ef1a
SHA256: 4A4B5F2C4294907AB189E74215904B5CAFAFA1E6D5D4F008B66A8B1D2A809DBD
File Size: 4.53 MB, 4525056 bytes
MD5: 9af8d8bca17fd60069457e27dafe2f30
SHA1: 88340f9b52ef188c3213a8751aadc5692d784494
SHA256: A89F2B1DE5751649ADCC5B2A5AD5D64559C2657D40C51EAF16C44D38D52E1BD1
File Size: 1.08 MB, 1081320 bytes
MD5: 0d5407272b2a5a88d2164e64e0896ac8
SHA1: 6a167706c0d601ab106a96f330c007e62ae16e7d
SHA256: F690CF5D2765E39E0385F376A93EA039062CB1DCC921EDB406C9320DC28FFEB5
File Size: 803.33 KB, 803328 bytes
Show More
MD5: 17d26d22913c19d7a93f7f6af7ec5d95
SHA1: 0bbc1e108af53990e4b9f2c34cbf7efbe442bc92
SHA256: E18684E62B3C076B91A776B71539A8B7640932055AE0831B73AD5FEE7C5DD4E7
File Size: 2.60 MB, 2598912 bytes
MD5: d2250c0f55c461f6318980d9bb27075c
SHA1: 079cbfa2f70bd1837894d625efed2c2b8398947e
SHA256: 01BC546BEE15F331374EF484BF66B9DDCBB4EC90EFEB0AFB7E98C4B7F6A14D36
File Size: 1.01 MB, 1005568 bytes
MD5: 94c4082c7583e5676c6ad8bfa5315bd3
SHA1: fa4afdd40e5c143b68609eca868b1c98bdd1b4df
SHA256: FBB551C66ADB4CEDA5DE338812593D5498356728E4E43679B375E7F183A006F9
File Size: 210.43 KB, 210432 bytes
MD5: c3afd16e821c7748e88edaf663cbc917
SHA1: 7ec03affe2f065a0f2a42de57a08263118cd4b22
SHA256: CB9696892CC868A0C04AEA046735174C2A556E9C8926D121A9990DF3F51D685B
File Size: 838.14 KB, 838144 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name
  • Digia Plc and/or its subsidiary(-ies)
  • ESET
  • Google Inc.
  • ICQ, Inc.
  • IObit.
  • Microsoft Corporation
  • The GLib developer community
File Description
  • C++ application development framework.
  • ESET Personal Firewall UI
  • GLib
  • ICQ Library
  • IDCRL Dynamic Link Library
  • PDFium (compiled by github.com/bblanchon)
  • Register Dynamic Link Library
  • Windows Live Client Code Module
  • Windows Live Client UX Core Module
File Version
  • 115.0.5744.0
  • 12.0.1101.0815
  • 11.0.0.365
  • 8.5.1235.0517
  • 6.5.0.1005
  • 4.100.313.1
  • 4.8.5.0
  • 4.0.474.0
  • 2.22.4.0
Internal Name
  • eguiEpfw.exe
  • ICQDb
  • IDCRL
  • libglib-2.0-0
  • MSNCore.dll
  • pdfium
  • UXCore.dll
Legal Copyright
  • Copyright (c) 1998-2007 ICQ, Inc.
  • Copyright (C) 2013 Digia Plc and/or its subsidiary(-ies).
  • Copyright (c) ESET 1992-2009. All rights reserved.
  • Copyright (c) Microsoft Corporation. All rights reserved.
  • Copyright 2023 PDFium Authors. All rights reserved.
  • Copyright © 1995-1997 Peter Mattis, Spencer Kimball and Josh MacDonald. Modified by the GLib Team and others 1997-2004.
  • Copyright © 1995-2006 Microsoft Corporation.
  • © IObit. All rights reserved.
  • © Microsoft Corporation. All rights reserved.
Legal Trademarks
  • IObit.
  • Microsoft® is a registered trademark of Microsoft Corporation.
  • NOD, NOD32, AMON, ESET are registered trademarks of ESET.
Original Filename
  • eguiEpfw.exe
  • ICQDb.dll
  • libglib-2.0-0.dll
  • msidcrl.dll
  • MSNCore.dll
  • pdfium.dll
  • QtCore4.dll
  • Register.dll
  • UXCore.dll
Product Name
  • Driver Booster
  • ESET Smart Security
  • GLib
  • ICQ
  • Microsoft CoreXT
  • Microsoft® Identity CRL
  • pdfium
  • Qt4
  • Windows Live Client UX
Product Version
  • 115.0.5744.0
  • 12.0.1101.0815
  • 11.0
  • 8.5.1235
  • 6.5.0.1005
  • 4.100.313.1
  • 4.0.474.0
  • 2.22.4

Digital Signatures

Signer Root Status
ESET, spol. s r.o. Class 3 Public Primary Certification Authority Hash Mismatch
IObit CO., LTD USERTrust RSA Certification Authority Hash Mismatch
VMware, Inc. VeriSign Class 3 Public Primary Certification Authority - G5 Hash Mismatch

File Traits

  • 2+ executable sections
  • CryptUnprotectData
  • dll
  • HighEntropy
  • imgui
  • x86

Block Information

Total Blocks: 4,114
Potentially Malicious Blocks: 557
Whitelisted Blocks: 3,448
Unknown Blocks: 109

Visual Map

? ? ? ? ? ? ? 0 ? ? 0 ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 1 0 0 1 1 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x x 0 0 0 0 0 0 x 0 0 x x x 0 0 x x x x x x x 0 0 x x x x x 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 x 0 0 0 x 0 0 0 x x x x x 0 0 x x x x x 0 0 x x 0 0 0 x x 0 0 0 0 0 x x x 0 x x 0 0 0 0 x 0 x x x 0 x x 0 0 0 0 x 0 x x x x x 0 0 x 0 x x x 0 0 x 0 x x x 0 0 x 0 x x x 0 0 x 0 x x x x x x x x x x 0 0 0 0 x x x x x x x x 0 0 0 0 x x x x x x x x x x x x x x x x x x x x 0 0 0 0 x x 0 0 0 0 x x x x 0 0 x x 0 0 x x 0 0 x x 0 0 x x x 0 0 0 0 x x 0 0 x 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 1 0 x 0 0 0 0 0 x x 0 0 0 x x x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 ? 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x 0 0 0 0 1 0 0 x 0 0 x x x 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 x 0 0 0 0 0 0 0 0 1 0 x 0 0 0 0 1 0 1 0 1 0 1 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 1 0 0 x x x x x 0 x 0 0 0 0 0 0 0 0 ? 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 1 0 0 x x x x 0 0 0 0 0 0 0 x x 0 0 0 0 x ? x 0 x x x x 0 0 0 1 0 0 0 x 0 x 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 ? x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 1 0 0 x 0 0 0 0 0 0 0 0 1 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 x 0 0 0 0 0 0 x 0 x 0 0 0 0 ? 0 x 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 x 0 0 0 1 0 x 1 x 0 x 0 0 0 0 0 0 1 0 x x x x x x x x x 0 0 0 x x x 0 x 0 x x x 0 x 1 x 0 0 0 x 0 0 0 0 0 0 0 1 x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 x x 0 0 x x 1 0 0 1 x x 0 0 0 0 0 0 0 0 0 0 1 x ? 0 0 0 0 1 0 0 0 0 0 0 0 0 0 x 0 0 1 0 x x 0 x 0 1 0 0 0 x 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 1 1 0 1 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 1 0 0 0 0 1 0 0 1 1 0 1 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 x ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 x 0 0 1 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 1 0 x 0 0 x 0 0 1 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 1 1 0 1 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 1 1 0 1 0 0 0 ? 0 0 0 0 ? 0 0 ? 0 1 1 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 1 1 0 1 0 0 0 0 0 0 0 1 1 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 ? x 0 0 0 x 0 1 1 0 1 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 1 1 0 1 0 0 0 0 0 1 0 0 x x 0 0 0 0 1 1 x 0 0 0 1 0 0 0 0 0 0 0 1 x 0 1 0 0 0 1 0 0 1 0 1 0 0 0 1 0 0 0 0 0 0 0 1 1 0 1 0 0 0 0 0 0 0 0 0 x 0 0 x x 0 0 0 x x 0 x x 0 0 0 x x 0 0 0 0 x x 1 x 0 0 0 0 x x x x x 0 1 1 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 x ? x 0 0 1 0 0 0 ? x ? 0 0 0 0 0 0 0 1 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 1 1 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 1 0 0 0 0 0 0 x 0 0 1 0 1 0 0 0 0 1 0 0 0 0 1 0 0 0 1 0 0 0 1 0 0 0 0 1 0 1 0 0 0 0 1 0 0 0 1 0 0 0 0 1 0 0 0 0 0 1 0 0 x 0 1 0 0 1 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 1 x 0 0 1 0 0 1 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 x x 1 0 0 0 0 0 0 1 0 0 0 1 0 1 0 0 0 1 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 1 0 1 1 0 0 0 0 0 0 0 1 0 x 0 x 0 0 1 1 0 0 0 0 0 0 0 x 1 0 x 0 0 0 x 1 0 0 0 1 0 0 x 0 x 0 0 0 0 0 1 1 x 0 0 0 0 0 0 0 1 0 0 0 ? 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 1 1 0 0 0 0 0 0 x 0 0 0 0 1 0 0 0 0 0 0 0 1 0 0 1 0 1 0 0 1 0 0 0 1 0 0 1 1 0 0 0 0 0 1 0 0 1 0 0 1 0 0 0 0 1 0 1 0 0 1 0 0 0 0 1 0 0 0 0 0 1 0 0 1 0 0 0 1 0 0 1 1 0 0 0 0 0 0 0 0 1 0 1 1 0 0 0 1 0 0 0 0 1 1 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 1 x 0 0 x x x 0 0 1 x 0 0 0 0 0 x x 0 0 0 1 0 0 0 1 0 0 x 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Rugmi.FI
  • Rugmi.O
  • Rugmi.OD
  • Rugmi.OH
  • Stealer.KF
Show More
  • Stealer.KFA
  • Vidar.FA

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtProtectVirtualMemory
Show More
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\2b8601842226052cebda839827c7afd5ad489965_0000904880.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\854d432e6047e097354efa55d47011e9d514b0cb_0001074880.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\3aeaba8a095ef2652abfd779fedb2c4505d4ef1a_0004525056.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\88340f9b52ef188c3213a8751aadc5692d784494_0001081320.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\6a167706c0d601ab106a96f330c007e62ae16e7d_0000803328.,LiQMAxHB
Show More
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\0bbc1e108af53990e4b9f2c34cbf7efbe442bc92_0002598912.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\079cbfa2f70bd1837894d625efed2c2b8398947e_0001005568.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\fa4afdd40e5c143b68609eca868b1c98bdd1b4df_0000210432.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\7ec03affe2f065a0f2a42de57a08263118cd4b22_0000838144.,LiQMAxHB