Trojan

Trojan.StealerRI.S25297305 (file analysis)

Malware Removal

The Trojan.StealerRI.S25297305 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.StealerRI.S25297305 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Nepali
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization

How to determine Trojan.StealerRI.S25297305?


File Info:

name: 63A396A6D85186E70B84.mlw
path: /opt/CAPEv2/storage/binaries/e7ddd0be269afba478a8769122c10883398faed6c8096fbdf22a7b55aa7db40a
crc32: ED057807
md5: 63a396a6d85186e70b846e17362a8f72
sha1: a5ea1c89f3d991a591199c63e7f2d15ce9e80b72
sha256: e7ddd0be269afba478a8769122c10883398faed6c8096fbdf22a7b55aa7db40a
sha512: 2d57957bc980347c3e0a3d6b814f46a97a4e07e6ebb0e6a79fb145e4736e5c9bf6f879a01600fed681ba04dff5eadb2caa1312d3d2129e44fbd08959a966ef55
ssdeep: 3072:EPTq8F8fejINpVsYWJZYIDx9pJi8dKgMXUaFv1gPdLPgMDeQMGu56iLW:42JffVMsIVN67v12djRBMgi
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AE54AD2133A0C032D49725768915CBB58E7AB4312A266ACBBFD44EBD9F247D1E73530E
sha3_384: e6fd2496d72a96552df2e86707bd2175d8ff190625f7bfc601a3d6d1fc7c54e776e104bbfda0e19872be2fc399ee8f76
ep_bytes: e86c840000e978feffff8bff558bec83
timestamp: 2020-09-10 21:42:16

Version Info:

FileVers: 7.0.4.24
ProductVersa: 7.0.25.71
InternalName: reaLatimad
LegalCopyrighd: Jdfglsdffa
Translations: 0x0169 0x0301

Trojan.StealerRI.S25297305 also known as:

LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen15.62805
MicroWorld-eScanTrojan.GenericKD.38193515
FireEyeGeneric.mg.63a396a6d85186e7
CAT-QuickHealTrojan.StealerRI.S25297305
ALYacTrojan.GenericKD.38193515
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0058b6971 )
AlibabaTrojanSpy:Win32/Azorult.134b5bd7
K7GWTrojan ( 0058b6971 )
Cybereasonmalicious.9f3d99
BitDefenderThetaGen:NN.ZexaF.34114.rq0@a0mFZKpG
CyrenW32/Kryptik.FWZ.gen!Eldorado
SymantecPacked.Generic.620
ESET-NOD32a variant of Win32/Kryptik.HNOL
TrendMicro-HouseCallTrojan.Win32.SMOKELOADER.YXBLFZ
Paloaltogeneric.ml
ClamAVWin.Packed.Pwsx-9917767-0
BitDefenderTrojan.GenericKD.38193515
NANO-AntivirusTrojan.Win32.Stealer.jixhem
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
Ad-AwareTrojan.GenericKD.38193515
EmsisoftTrojan.Crypt (A)
TrendMicroTrojan.Win32.SMOKELOADER.YXBLFZ
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
SophosMal/Generic-S + Troj/Krypt-BO
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.1CNP511
JiangminTrojan.Agent.dsqx
MaxSecureTrojan.Malware.300983.susgen
AviraTR/AD.MalwareCrypter.skjkc
MAXmalware (ai score=99)
Antiy-AVLTrojan/Generic.ASMalwS.34E9657
GridinsoftRansom.Win32.Sabsik.sa
ViRobotTrojan.Win32.Z.Win.279040.F
MicrosoftTrojan:Win32/Azorult.RM!MTB
CynetMalicious (score: 100)
AhnLab-V3CoinMiner/Win.Glupteba.R456355
Acronissuspicious
McAfeePacked-GBE!63A396A6D851
VBA32Malware-Cryptor.2LA.gen
MalwarebytesTrojan.MalPack.GS.Generic
APEXMalicious
YandexTrojan.Agent!kRscWqMAfus
IkarusBackdoor.Win32.Kredoor
FortinetMalicious_Behavior.SB
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan.StealerRI.S25297305?

Trojan.StealerRI.S25297305 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment