Spy Trojan

Trojan-Spy.Win32.Stealer.apen information

Malware Removal

The Trojan-Spy.Win32.Stealer.apen is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Stealer.apen virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • NtSetInformationThread: attempt to hide thread from debugger
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Detects Sandboxie through the presence of a library
  • Queries information on disks, possibly for anti-virtualization
  • Checks for the presence of known windows from debuggers and forensic tools
  • CAPE detected the RedLine malware family
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects VirtualBox through the presence of a device
  • Anomalous binary characteristics
  • Binary compilation timestomping detected

How to determine Trojan-Spy.Win32.Stealer.apen?


File Info:

name: B3CA568CE7E111C8A040.mlw
path: /opt/CAPEv2/storage/binaries/00eaffdde594219d4fb31833bc38e6dcbfc6c1dbc2ef37628487b8216a0c65ea
crc32: 5B23EA82
md5: b3ca568ce7e111c8a040f1d62552d1bb
sha1: 02f110e02faeb810b9102ab4f615b3781974aa6d
sha256: 00eaffdde594219d4fb31833bc38e6dcbfc6c1dbc2ef37628487b8216a0c65ea
sha512: d07d383839ff05e01d74ea7dd50b8789dd4bc3ac1932dbd96075441991c72b00cd746dfd0c384a75b54ed6478b54f04f08a5bcf4195ba3398e900680e4a05f10
ssdeep: 49152:XZvj8ODLkW6SkKDVqq/Yu6W2Q0lQD1eX5HohAZ8K:XZvjX8zSk45Qu12QQQ8JHohdK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T112A51218BA241DE9F18716326563B37023B36E964E6681AC28E49F077C731C71F676CB
sha3_384: 573d8d444ff146765aaca0c045ddf490437ea33c1f1adc3168fccdbbe2e178a4655ec88d7387b2e883e1797ef744ce64
ep_bytes: eb05d0f3c6693850eb0562875e7aade8
timestamp: 2046-05-23 23:05:03

Version Info:

Translation: 0x0000 0x04b0
Comments: EntityFramework.dll
CompanyName: Microsoft Corporation
FileDescription: EntityFramework.dll
FileVersion: 4.4.20627.0
InternalName: EntityFramework.dll
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: EntityFramework.dll
ProductName: Microsoft® .NET Framework
ProductVersion: 5.0.0.net40
Assembly Version: 4.4.0.0

Trojan-Spy.Win32.Stealer.apen also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Malicious.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.38237267
FireEyeGeneric.mg.b3ca568ce7e111c8
ALYacTrojan.GenericKD.38237267
CylanceUnsafe
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojanSpy:Win32/Stealer.12e6280b
K7GWTrojan ( 0058b97b1 )
K7AntiVirusTrojan ( 0058b97b1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.Obsidium.CY
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Spy.Win32.Stealer.apen
BitDefenderTrojan.GenericKD.38237267
AvastWin32:Trojan-gen
Ad-AwareTrojan.GenericKD.38237267
Comodo.UnclassifiedMalware@0
DrWebTrojan.PWS.Siggen3.8262
TrendMicroTrojanSpy.Win32.STEALER.USMANLB21
McAfee-GW-EditionBehavesLike.Win32.Fujacks.tc
EmsisoftTrojan.GenericKD.38237267 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan-Stealer.CredStealer.LTK23Y
KingsoftWin32.Troj.Stealer.ap.(kcloud)
GridinsoftRansom.Win32.Sabsik.ns
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
Acronissuspicious
McAfeeArtemis!B3CA568CE7E1
MAXmalware (ai score=100)
VBA32BScope.Trojan.Tiggre
MalwarebytesTrojan.MalPack
TrendMicro-HouseCallTrojanSpy.Win32.STEALER.USMANLB21
YandexTrojanSpy.Stealer!6fyZZoqdFww
IkarusTrojan.Win32.Obsidium
FortinetMalicious_Behavior.SB
BitDefenderThetaGen:NN.ZexaF.34084.!r3@a0UqmOdi
AVGWin32:Trojan-gen
Cybereasonmalicious.02faeb
PandaTrj/CI.A

How to remove Trojan-Spy.Win32.Stealer.apen?

Trojan-Spy.Win32.Stealer.apen removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment