Spy Trojan

About “Trojan-Spy.Win32.Stealer.alaj” infection

Malware Removal

The Trojan-Spy.Win32.Stealer.alaj is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Stealer.alaj virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • NtSetInformationThread: attempt to hide thread from debugger
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • A HTTP/S link was seen in a script or command line
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Checks for the presence of known windows from debuggers and forensic tools
  • Created a process from a suspicious location
  • Collects and encrypts information about the computer likely to send to C2 server
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects VirtualBox through the presence of a device

How to determine Trojan-Spy.Win32.Stealer.alaj?


File Info:

name: A004467122CD9BDF6DCB.mlw
path: /opt/CAPEv2/storage/binaries/6a95ae9bbffe63256b6f7d36fd6d15a7eedd075642fbe6068542e63d9866aa10
crc32: 65EE8F16
md5: a004467122cd9bdf6dcb8b8ae73698d4
sha1: 5c4f6683151cbfa12eb6829a7606cea27e7ddca4
sha256: 6a95ae9bbffe63256b6f7d36fd6d15a7eedd075642fbe6068542e63d9866aa10
sha512: 3d6966b2e9b7f82e04aabab194e50ac544a18cae5b95777965828ece81d684a7e50c6e1260a62902d59686e979a2c6903ba1e99407beffcdbb9ab703f831bd5f
ssdeep: 24576:Vz66yTiPgN2CgDWqclcB6vQR1VJn0oNdOzqppr1Ec8Lvc+JnL+8fxO:Z14N2rDWDmB64R1VZ//Ozqfya+g8xO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13355DF4C5013B7ADCD60333B8A3A9F55C6F44E55D962826E39C0BE37E6B6F82063D642
sha3_384: 56fc9e56e379e3aa05f348a26319b0fe3cb2732f5c7d9ae6889c2d77fa427a62f2dff71b96d3a2beb93bb5314eb2db36
ep_bytes: 81ec8401000053565733db6801800000
timestamp: 2019-12-16 00:50:56

Version Info:

Comments: Left Hook Deliv
FileDescription: Make Descision Soft
FileVersion: 4.5.23.2
InternalName: Incirim Nolweas
LegalCopyright: (C) Software Inc.
LegalTrademarks: Software
Translation: 0x0409 0x04e4

Trojan-Spy.Win32.Stealer.alaj also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Stealer.l!c
Elasticmalicious (high confidence)
MicroWorld-eScanDropped:Trojan.GenericKD.38131168
FireEyeGeneric.mg.a004467122cd9bdf
ALYacGen:Variant.Bulz.783452
K7AntiVirusTrojan ( 005826bf1 )
BitDefenderDropped:Trojan.GenericKD.38131168
K7GWTrojan ( 005826bf1 )
CrowdStrikewin/malicious_confidence_60% (W)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenCBL.BGP
TrendMicro-HouseCallTROJ_GEN.R002H0CKR21
Paloaltogeneric.ml
ClamAVWin.Packed.Razy-9894224-0
KasperskyTrojan-Spy.Win32.Stealer.alaj
AlibabaTrojanSpy:Win32/Stealer.282dd631
TencentTrojan.Win32.BitCoinMiner.la
Ad-AwareDropped:Trojan.GenericKD.38131168
EmsisoftDropped:Trojan.GenericKD.38131168 (B)
DrWebTrojan.PWS.Siggen3.7247
McAfee-GW-EditionBehavesLike.Win32.Browser.tc
SentinelOneStatic AI – Suspicious PE
SophosMal/Generic-S
APEXMalicious
eGambitUnsafe.AI_Score_81%
AviraHEUR/AGEN.1144880
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.A!ml
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
GDataDropped:Trojan.GenericKD.38131168
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R441806
McAfeeArtemis!A004467122CD
MAXmalware (ai score=86)
VBA32BScope.Trojan.Tiggre
MalwarebytesTrojan.Downloader
RisingTrojan.IPLogger/NSIS!1.C696 (CLASSIC)
IkarusTrojan.Win32.Generic
AVGWin32:Malware-gen
AvastWin32:Malware-gen

How to remove Trojan-Spy.Win32.Stealer.alaj?

Trojan-Spy.Win32.Stealer.alaj removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment