Threat Database Stealers Trojan.Stealer.YA

Trojan.Stealer.YA

By CagedTech in Stealers, Trojans

Threat Scorecard

Popularity Rank: 16,450
Threat Level: 80 % (High)
Infected Computers: 11
First Seen: November 14, 2023
Last Seen: June 11, 2026
OS(es) Affected: Windows

The detection of Trojan.Stealer.YA on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise your computer's security and steal sensitive information, making it essential to understand its nature and take prompt action to remove it.

What Is Trojan.Stealer.YA?

Trojan.Stealer.YA is a type of Trojan horse malware that can infect your computer through various means, such as downloading malicious software, opening infected email attachments, or visiting compromised websites. Once installed, it can operate stealthily, making it challenging to detect without proper security tools.

It's crucial to note that the term "Trojan" refers to the type of malware, not a specific family. Trojans are known for their ability to disguise themselves as legitimate software, making them difficult to identify. The ".Stealer.YA" part of the name suggests that this particular malware is designed to steal sensitive information, but the exact nature of the threat can vary.

How Trojan.Stealer.YA Operates

Trojan.Stealer.YA, like other Trojans, can operate in various ways, depending on its design and purpose. It may create backdoors, allowing unauthorized access to your computer, or it may be used to steal sensitive information such as login credentials, financial data, or personal information. In some cases, it can also be used to install additional malware or ransomware, leading to further complications.

The malware can also modify system settings, disable security software, or interfere with system operations to maintain its presence on the infected computer. Its ability to adapt and evolve makes it a significant threat to computer security.

Symptoms of Infection

Identifying the symptoms of a Trojan.Stealer.YA infection can be challenging, as it is designed to operate stealthily. However, some common indicators of a malware infection include slow system performance, frequent crashes, or unusual network activity. You may also notice unfamiliar programs or icons on your computer, or you may receive unexpected pop-ups or alerts.

In some cases, you may not notice any symptoms at all, which is why regular system scans and monitoring are essential for detecting and removing malware.

How to Remove Trojan.Stealer.YA

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for internet access. This will make it easier to download and install removal tools.
  2. Download and install a reputable anti-malware tool, such as SpyHunter, and perform a full system scan to detect and remove the malware.
  3. Uninstall any suspicious programs or software that you don't recognize or that were installed around the time of the infection.
  4. Reset your web browsers, such as Chrome, Firefox, or Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your computer and perform another full system scan to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.Stealer.YA requires a combination of technical knowledge and the right tools. By following the steps outlined above and maintaining good computer security practices, such as regularly updating your operating system and security software, you can reduce the risk of infection and protect your sensitive information.

It's also essential to be cautious when downloading software or opening email attachments from unknown sources, as these are common ways for malware to spread. By being proactive and taking the necessary steps to secure your computer, you can help prevent future infections and maintain a safe and secure computing environment.

Analysis Report

General information

Family Name: Trojan.Stealer.YA
Signature status: Root Not Trusted

Known Samples

MD5: d4c64c4f89e803a56b9089234034e8d3
SHA1: 913b7fb7d47a278f5de12938fb524b455a294c53
SHA256: 3A949385A16532D7FA76504D91CA4F4D1DCAA93289E1472AFF692DF698A06C51
File Size: 5.44 MB, 5439488 bytes
MD5: cfcb87005ee466302ef87f792e255a07
SHA1: fea669e5aecfc5b73f5da3fb899e1512d8857282
SHA256: C9420F43919A1C4D567870EDAAB1C23CEFFFF1BA97D027BE4780D65CDCEAAF98
File Size: 4.94 MB, 4939576 bytes
MD5: a8838f280e2b0ebdd8241c999a9bf669
SHA1: c1841c7dbb0f545c1b7a0343e75491d95beb08fc
SHA256: FE64CF22C44E83231F8BD1A0C592CC49AA1AC819FB12233F89E170FBE59248D7
File Size: 4.94 MB, 4939064 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • -
  • Paramount Software UK Ltd
File Description Macrium Reflect Disk Imaging and Backup
File Version
  • 8, 0, 7783, 0
  • 1.0.0.212
  • 1.0.0.207
Internal Name Macrium Reflect
Legal Copyright
  • (c) Paramount Software. All rights reserved.
  • Copyright (C) 2022
Original Filename MRVerify.exe
Product Name Macrium Reflect File Verifyer
Product Version
  • 8, 0, 7783, 0
  • 0.0.0.0

Digital Signatures

Signer Root Status
Beijing AoLanDe Information Technology Co., Ltd. DigiCert Trusted Root G4 Root Not Trusted

File Traits

  • 2+ executable sections
  • HighEntropy
  • imgui
  • ntdll
  • x86

Block Information

Total Blocks: 14,846
Potentially Malicious Blocks: 389
Whitelisted Blocks: 14,343
Unknown Blocks: 114

Visual Map

0 0 0 x x x x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x x x x 0 x 0 0 x x x x 0 x x x x x x 0 x x x x x x x x x x x x 0 x x x x x x x x 0 x x x 0 x 0 0 0 0 x x 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 x x 0 0 0 x x 0 x 0 x 0 x 0 x x x x x x x x x x x x 0 x x x 0 x 0 ? ? 0 0 0 0 x 0 0 x 0 0 x 0 0 0 x x 0 x 0 x x x x x x x x x x x x x x x 0 x 0 0 x 0 ? x ? ? x 0 ? ? x x x x x x 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x 0 x 0 0 0 0 0 x x 0 0 x 0 x x 0 x x 0 0 x 0 0 x x x x x 0 0 0 0 0 x x 0 0 x x x x x x x x 0 x x ? x x ? ? ? ? 0 x 0 x x x x x x x 0 x x x x x x x 0 0 0 0 x 0 x x 0 0 x 0 x x x x 0 x x x 0 0 x x 0 x x x x x x 0 x x x x x 0 x x x x x 0 x x x x x x x x x x x x x x ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x x ? ? x 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x x x x x 0 ? x x x 0 x x x x x x x x 0 x 0 0 x x 0 x 0 x 0 0 0 x 0 0 x 0 0 0 0 0 0 0 x 0 0 x x 0 x x 0 x x x x x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? 0 ? 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • AdAgent.AB
  • Downer.B
  • Stealer.YA

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
User Data Access
  • GetUserObjectInformation
Other Suspicious
  • AdjustTokenPrivileges
Network Info Queried
  • GetAdaptersInfo
Network Winsock2
  • WSAStartup
  • WSAttemptAutodialName
Network Winsock
  • accept
  • bind
  • closesocket
  • connect
  • freeaddrinfo
  • getaddrinfo
  • getsockname
  • recv
  • send
  • setsockopt
Show More
  • socket

Trending

Most Viewed

Loading...