Spy Trojan

What is “Trojan-Spy.Win32.Stealer.vma”?

Malware Removal

The Trojan-Spy.Win32.Stealer.vma is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Stealer.vma virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Slovenian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to identify installed AV products by installation directory
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Anomalous binary characteristics

Related domains:

iplogger.org
leatherbond.top

How to determine Trojan-Spy.Win32.Stealer.vma?


File Info:

crc32: F5984D68
md5: 1a6760ebbff9dfbd8cff877a303df66a
name: 1A6760EBBFF9DFBD8CFF877A303DF66A.mlw
sha1: e66d7e55d74548dea55aeeb0eed3284a8a1c1a28
sha256: 96bbdcb417228948effc7c21ddc3a08addcaa2421dca8870b64ea4f9f691dddd
sha512: a130b99c5fee0afa3958bbb0972d7a4770d601065e14cd6ea957d34a6d00edffdafd9bf822bf7d1609e79333ffa53e24735cf4a550ee900493f516fbbad2b615
ssdeep: 12288:39nR+269o6yhEA6WRIxUQ6E6Vu27vqyEeIEYv0qRDzCxXDaz05pY:39U269o6yaVUQr6l7vqnVv74TawY
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalSurname: rebound.exe
Product: 1.7.6
FileVersions: 1.0.5.4
LegalCo: Copyri (C) 2019, parritions
Translation: 0x5539 0x00fa

Trojan-Spy.Win32.Stealer.vma also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.35847783
CAT-QuickHealTrojan.Multi
McAfeeRDN/RedLineStealer
AegisLabTrojan.Win32.Malicious.4!c
SangforMalware
K7AntiVirusTrojan ( 0057533c1 )
BitDefenderTrojan.GenericKD.35847783
K7GWTrojan ( 0057533c1 )
Cybereasonmalicious.5d7454
ArcabitTrojan.Generic.D222FE67
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HIKN
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Spy.Win32.Stealer.vma
AlibabaTrojanSpy:Win32/Stealer.778fa7ef
ViRobotTrojan.Win32.Z.Siggen11.705536
Ad-AwareTrojan.GenericKD.35847783
EmsisoftTrojan.GenericKD.35847783 (B)
F-SecureTrojan.TR/AD.AHKInfoSteal.grbmv
DrWebTrojan.Siggen11.56472
McAfee-GW-EditionBehavesLike.Win32.PWSBanker.jc
FireEyeGeneric.mg.1a6760ebbff9dfbd
SophosMal/Generic-S
IkarusTrojan.Win32.Crypt
AviraTR/AD.AHKInfoSteal.grbmv
MAXmalware (ai score=82)
KingsoftWin32.Troj.Stealer.v.(kcloud)
GridinsoftTrojan.Win32.Kryptik.oa
MicrosoftTrojan:Win32/Glupteba!ml
ZoneAlarmTrojan-Spy.Win32.Stealer.vma
GDataTrojan.GenericKD.35847783
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.RL_Kryptik.R360326
ALYacTrojan.GenericKD.35847783
VBA32BScope.Backdoor.Agent
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_91%
FortinetW32/Kryptik.HFSR!tr
BitDefenderThetaGen:NN.ZexaF.34700.RmGfay9tOtdc
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Generic/Trojan.8fd

How to remove Trojan-Spy.Win32.Stealer.vma?

Trojan-Spy.Win32.Stealer.vma removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment