Spy Trojan

About “Trojan-Spy.Win32.Stealer.bblh” infection

Malware Removal

The Trojan-Spy.Win32.Stealer.bblh is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Stealer.bblh virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid

How to determine Trojan-Spy.Win32.Stealer.bblh?


File Info:

name: 9C4FCC0CE1912943F6B0.mlw
path: /opt/CAPEv2/storage/binaries/535227daae672de22a6609d6012d6a45aa0890ac5abdc7095082981feee6c675
crc32: 7E7E5CD4
md5: 9c4fcc0ce1912943f6b05b02deb30efa
sha1: 2c164d3c978de2912356411b49fad36335061456
sha256: 535227daae672de22a6609d6012d6a45aa0890ac5abdc7095082981feee6c675
sha512: aecddfe464204ee6be961280f82b2fc86a61178df690319fc79b9a9663fce8eb03051892fc4eeb56394e063fa524a2198fb9a5d08e0688eaa7767776415ed45f
ssdeep: 196608:TECW9SaNsFSeyjjl3mUbJqcJOKVV9kTP/CIVwbFmWdDAv:TERLvjscwKVV9UaIVy+v
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F46633E19E747590D4AAB673B0A8573C3BC68D0DCA7849559393F52B29B4AC0A0F3C4F
sha3_384: b1862d26a6621b838094fc92a326d978ba3ce164659dd30597ab27937c814d408c44216f2924e5eee1caf74f25c5dcc8
ep_bytes: 558bec81ecf40300005356576a205f33
timestamp: 2021-09-25 21:57:46

Version Info:

0: [No Data]

Trojan-Spy.Win32.Stealer.bblh also known as:

LionicTrojan.Win32.Stealer.l!c
MicroWorld-eScanGen:Heur.Mint.Porcupine.@xZabWazK2eig
McAfeeArtemis!9C4FCC0CE191
CylanceUnsafe
SangforSuspicious.Win32.Attribute.HighConfidence
K7AntiVirusTrojan ( 0058c4bd1 )
AlibabaTrojanPSW:Win64/BroPass.f42b795e
K7GWTrojan ( 0058c4bd1 )
CyrenW32/ASProtect.H.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32multiple detections
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Spy.Win32.Stealer.bblh
BitDefenderGen:Heur.Mint.Porcupine.@xZabWazK2eig
AvastWin32:Evo-gen [Susp]
TencentWin64.Trojan-qqpass.Qqrob.Hupr
EmsisoftGen:Heur.Mint.Porcupine.@xZabWazK2eig (B)
F-SecureHeuristic.HEUR/AGEN.1208938
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
FireEyeGeneric.mg.9c4fcc0ce1912943
SophosMal/Generic-S
IkarusTrojan-PSW.Agent
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1208938
MAXmalware (ai score=87)
MicrosoftTrojan:Win32/Tiggre!rfn
ViRobotTrojan.Win32.Z.Mint.7049952
GDataGen:Heur.Mint.Porcupine.@xZabWazK2eig
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R465775
ALYacGen:Heur.Mint.Porcupine.@xZabWazK2eig
VBA32BScope.Trojan.Tiggre
TrendMicro-HouseCallTROJ_GEN.R002H0CB222
SentinelOneStatic AI – Suspicious PE
AVGWin32:Evo-gen [Susp]

How to remove Trojan-Spy.Win32.Stealer.bblh?

Trojan-Spy.Win32.Stealer.bblh removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment