Spy Trojan

Should I remove “Trojan-Spy.Win32.Stealer.alul”?

Malware Removal

The Trojan-Spy.Win32.Stealer.alul is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Stealer.alul virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • NtSetInformationThread: attempt to hide thread from debugger
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Detects Sandboxie through the presence of a library
  • Queries information on disks, possibly for anti-virtualization
  • Checks for the presence of known windows from debuggers and forensic tools
  • CAPE detected the RedLine malware family
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects VirtualBox through the presence of a device
  • Anomalous binary characteristics
  • Binary compilation timestomping detected

How to determine Trojan-Spy.Win32.Stealer.alul?


File Info:

name: 07501CF913AA46F62E4F.mlw
path: /opt/CAPEv2/storage/binaries/c03a6203330f60d8cbd4f8ef559316b95ba891e2b592846eaaa769ccd534d28c
crc32: CB8A659C
md5: 07501cf913aa46f62e4f2e2387716ec5
sha1: dbd01d5d3e39e61286136414f0d7a372b8e5004a
sha256: c03a6203330f60d8cbd4f8ef559316b95ba891e2b592846eaaa769ccd534d28c
sha512: fd3460a7a8b31082d4af940c29b16fc10d9c7259a0722a7b637624c55f39d0f208af133c4323c8578bceec21289bc791ee76b1c29d13383db16da490b4e59dba
ssdeep: 24576:vc88pvkNkBobrslgjMRarTbEzqFVwhHe5OLQjRAgJo0+:vb8980iljMRaf7odqvdAgo
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10465CF11A7E6082AD46E057058633B152E35FCF7BAE17247319E7B0E6FB2A534E83352
sha3_384: 0c26e8458dcc8bd099c1a7df20d6af26b5c4d31c9bf71089ea0e87eb09320cbf12e40f0aec43fc33a0503f7d1697e26f
ep_bytes: eb011150eb0584b70b7083e81b000000
timestamp: 2056-11-19 23:01:04

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: SpaceGame
FileVersion: 1.0.0.0
InternalName: SpecialFold.exe
LegalCopyright: Copyright © 2018
LegalTrademarks:
OriginalFilename: SpecialFold.exe
ProductName: SpaceGame
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Trojan-Spy.Win32.Stealer.alul also known as:

LionicTrojan.Win32.Stealer.l!c
ClamAVWin.Keylogger.Generic-9916369-0
FireEyeTrojan.GenericKD.47515252
CAT-QuickHealTrojanSpy.Stealer
ALYacTrojan.GenericKD.47515252
CylanceUnsafe
K7AntiVirusTrojan ( 0058b2201 )
AlibabaTrojanSpy:Win32/Stealer.ae91e80a
K7GWTrojan ( 0058b2201 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.Obsidium.CP
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan-Spy.Win32.Stealer.alul
BitDefenderTrojan.GenericKD.47515252
ViRobotTrojan.Win32.Z.Tiggre.1494688
MicroWorld-eScanTrojan.GenericKD.47515252
AvastWin32:DangerousSig [Trj]
Ad-AwareTrojan.GenericKD.47515252
SophosMal/Generic-S
Comodofls.noname@0
DrWebTrojan.PWS.Steam.22889
ZillyaTrojan.Stealer.Win32.19988
TrendMicroTROJ_GEN.R002C0WL221
McAfee-GW-EditionArtemis!Trojan
EmsisoftTrojan.GenericKD.47515252 (B)
GDataWin32.Trojan-Stealer.CredStealer.R9NNU6
JiangminTrojanSpy.Stealer.izs
WebrootW32.Trojan.Gen
KingsoftWin32.Troj.Stealer.al.(kcloud)
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Generic.D2D50674
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
McAfeeArtemis!07501CF913AA
MAXmalware (ai score=85)
VBA32BScope.Trojan.Tiggre
MalwarebytesTrojan.MalPack
TrendMicro-HouseCallTROJ_GEN.R002C0WL221
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
BitDefenderThetaGen:NN.ZexaF.34084.Br1@aSTAIPji
AVGWin32:DangerousSig [Trj]
PandaTrj/CI.A

How to remove Trojan-Spy.Win32.Stealer.alul?

Trojan-Spy.Win32.Stealer.alul removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment