Threat Database Stealers Trojan.Stealer.UB

Trojan.Stealer.UB

By CagedTech in Stealers, Trojans

Threat Scorecard

Popularity Rank: 8,194
Threat Level: 80 % (High)
Infected Computers: 1,580
First Seen: September 2, 2021
Last Seen: July 11, 2026
OS(es) Affected: Windows

The detection of Trojan.Stealer.UB on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise your computer's security and steal sensitive information, making it essential to understand its nature and take prompt action to remove it.

What Is Trojan.Stealer.UB?

Trojan.Stealer.UB is a type of Trojan horse malware, which is a broad category of malicious software that disguises itself as legitimate to gain unauthorized access to a computer system. The term "Trojan" refers to the method of infection, where the malware is disguised as something harmless or desirable, much like the Trojan Horse of legend. The ".Stealer" part of the name suggests that this particular malware is designed to steal information from the infected computer. Understanding that the name itself does not necessarily imply a specific malware family, but rather describes its function, is crucial. The "UB" could indicate a unique identifier or variant, but without specific details, it's essential to focus on the general characteristics of Trojan-type threats.

How Trojan.Stealer.UB Operates

Trojan.Stealer.UB, like other Trojans, operates by deceiving users into installing it on their systems. This can happen through various means, such as opening malicious email attachments, downloading software from untrusted sources, or visiting compromised websites. Once installed, the malware can carry out a variety of malicious activities, including stealing personal data, such as login credentials, credit card numbers, and other sensitive information. It may also install additional malware, provide unauthorized access to the infected computer, or disrupt system operation. The specific actions of Trojan.Stealer.UB can vary, but its primary goal is to compromise the security and privacy of the infected system.

Symptoms of Infection

Identifying a Trojan.Stealer.UB infection can be challenging because it is designed to operate stealthily. However, there are several symptoms that may indicate the presence of this or similar malware. These include unexpected changes in system performance, such as slow operation or frequent crashes, appearance of unwanted programs or toolbars, unusual network activity, and pop-ups or other unwanted advertisements. Additionally, if you notice that your personal data is being accessed or used without your permission, it could be a sign of a malware infection. It's essential to be vigilant and monitor your system's behavior regularly to catch any potential threats early.

How to Remove Trojan.Stealer.UB

  1. Enter Safe Mode with Networking to prevent the malware from loading and to allow for a clean environment to perform removal steps.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system. Ensure the tool is updated with the latest definitions to increase the chances of detecting and removing the malware.
  3. Uninstall any suspicious programs that you do not recognize or that were installed around the time the malware was detected.
  4. Reset your web browsers, such as Chrome, Firefox, or Edge, to their default settings to remove any malicious extensions or settings changes made by the malware.
  5. Reboot your computer and perform another full scan with your anti-malware tool to ensure that all components of the malware have been removed.

Conclusion

Removing Trojan.Stealer.UB requires a combination of technical knowledge and the right tools. It's crucial to act quickly to minimize the potential damage and protect your sensitive information. After removal, it's also important to take preventive measures to avoid future infections, such as keeping your operating system and software up to date, using strong, unique passwords, and being cautious when interacting with emails and websites. By understanding the nature of Trojan-type threats and taking proactive steps, you can significantly reduce the risk of infection and keep your digital life secure.

Analysis Report

General information

Family Name: Trojan.Stealer.UB
Signature status: Self Signed

Known Samples

MD5: a75278f4a91997a827a34a52a3bd8f46
SHA1: 74625faf4d8e67f8d09c79bafe10cd5e6a6c7689
SHA256: 3BBDC8F264E816B66C3DC55771BA02FEC24E504C07FE23539242B37AD5C14FFD
File Size: 5.70 MB, 5702640 bytes
MD5: 766421818a7e8a3657ae088698ad0e44
SHA1: 4eceeaa98fdf2fac5070695bb7dbda2f8ee62f14
SHA256: 800962E0F13611C1197C54A2FCFA5DC24F42ECA4A6E8081A73638AE6E6380CD0
File Size: 5.70 MB, 5702640 bytes
MD5: 22907101c5987476015955e879ec816d
SHA1: d4708d80658c1a118652f05a153cdd5f68f20173
SHA256: A68444F673255A2E11581166E2A2251AEA98BEFB37ECB13A3432180A06816DAD
File Size: 4.90 MB, 4895744 bytes
MD5: 62defe5a99b589fea24f8fd8e6be5074
SHA1: f56ae64afc4a939f384052fb9f5ae32892870415
SHA256: AFED751CE662A42ACB0D42957CEEE56688774F56EE1BA2DA2B1C21C5878A5874
File Size: 6.12 MB, 6115328 bytes
MD5: 27662ef27c6727721570f9c318f5e6c9
SHA1: 6aef417f2ec14f43ea15f1858782d01e344d1520
SHA256: C3B2D2F7BB46F6C68BD4E61973AE8D0C924A421C304AD1011DDD11234F780031
File Size: 4.04 MB, 4038817 bytes
Show More
MD5: 94c4ec8e965ca2a723dc628cd7e34315
SHA1: 9e998234041cae4e69054963c64c4f5c936ee654
SHA256: 9504A2F6BC8C5FC0B16ED0C85D61A1D54EDC15379ADF18FB1B58F11F84BC45BD
File Size: 6.57 MB, 6573056 bytes
MD5: d2137fdc01a3322547c8a289de956cf0
SHA1: ea5049d13f7edfc5ea95cd5bb51d84c7b7261794
SHA256: FD10A4711483C47749F9F1B763B9EFAA237F2E5AF1B2250A5B9B959AAF59361F
File Size: 6.23 MB, 6230696 bytes
MD5: 15266c5e437999fb491fdfacf8cf146d
SHA1: 52fcf136029b8efc5653cc7b92a39add06f9fa80
SHA256: 99E50AD000DD05288F91D00F77E240B8E22706DF8CB0BAF7E19E7A2FC016A006
File Size: 4.37 MB, 4365824 bytes
MD5: 4a3b25d6e13f62bb5d249c07a8045ffb
SHA1: 7b02da71d6ad508d9b7054abe8a5b8fd1b4456da
SHA256: EE9622DB0D02B965CA7B4CD622C12EA5113B907E95AB3460EFE7FA7EDBB6B3F6
File Size: 4.89 MB, 4889600 bytes
MD5: 67156b565e32f742aa793b059bbefc1c
SHA1: 9f8304ea7e0049fe89a6150d446d117717ebea23
SHA256: 53095CCB2F655961C38F6E0DC87DBEB6D6F0CDF329765387A16F444B787E4173
File Size: 4.99 MB, 4991408 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Assembly Version
  • 25.0.9467.22040
  • 3.4.142.1813
  • 1.0.0.1
  • 1.0.0.0
  • 0.0.0.0
Comments Taxware Software Auto Patcher
Company Name
  • Fiery LLC
  • Taxware Systems, Inc
File Description
  • Bet
  • LogCapture
  • MEIDevice
  • NemesisTool
  • PERS
  • SirHurtUI
  • TaxwareAutoPatcher
File Version
  • 25.0.9467.22040
  • 24.11.05.1
  • 3.4.142.1813
  • 1.0.0.0
  • 0.0.0.0
Internal Name
  • Bet.exe
  • EX3cutioN3Rv1.0.exe
  • LogCapture.exe
  • NemesisTool.exe
  • PERS.exe
  • Pontus.exe
  • SirHurtUI.exe
  • TWUpdate.exe
  • Uninstaller.exe
Legal Copyright
  • Copyright © 2016
  • Copyright © 2021
  • Copyright © 2024
  • Copyright © 2024 Fiery LLC
  • Copyright © 2025
  • Copyright © Taxware Systems 2022
  • Pearlabyss Corp
Legal Trademarks Fiery Driven®
Original Filename
  • Bet.exe
  • EX3cutioN3Rv1.0.exe
  • LogCapture.exe
  • NemesisTool.exe
  • PERS.exe
  • Pontus.exe
  • SirHurtUI.exe
  • TWUpdate.exe
  • Uninstaller.exe
Product Name
  • Bet
  • LogCapture
  • MEIDevice
  • NemesisTool
  • PERS pss version
  • SirHurtUI
  • TaxwareAutoPatcher
Product Version
  • 25.0.9467.22040
  • 24.11.05.1
  • 3.3.650
  • 1.0.0.0
  • 0.0.0.0

Digital Signatures

Signer Root Status
Fiery, LLC DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Self Signed
Pearl abyss Corp DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Self Signed
TAXWARE SYSTEMS, INC. DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Self Signed
Pearl abyss Corp DigiCert Trusted Root G4 Root Not Trusted

File Traits

  • 2+ executable sections
  • HighEntropy
  • Installer Manifest
  • Installer Version
  • themida
  • themida section variant
  • x86

Block Information

Total Blocks: 8
Potentially Malicious Blocks: 1
Whitelisted Blocks: 2
Unknown Blocks: 5

Visual Map

0 ? 0 ? x ? ? ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Stealer.UB

Files Modified

File Attributes
\device\harddisk0\dr0 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\programdata\mntemp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\zpyit.exe Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\taxwareautopatcherv2.err.log Generic Write,Read Attributes

Windows API Usage

Category API
User Data Access
  • GetComputerNameEx
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection

Trending

Most Viewed

Loading...