Trojan

Trojandownloader.Stralo (file analysis)

Malware Removal

The Trojandownloader.Stralo is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojandownloader.Stralo virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • The binary likely contains encrypted or compressed data.
  • Checks for the presence of known windows from debuggers and forensic tools
  • The following process appear to have been packed with Themida: marg.exe
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects the presence of Wine emulator via registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Anomalous binary characteristics

Related domains:

bitbucket.org

How to determine Trojandownloader.Stralo?


File Info:

crc32: 06F71995
md5: b68c8121787369ee612c92cd23790cd7
name: marg.exe
sha1: 30e455e45a0195a00d468a41dc9bbb7de97f0fa9
sha256: 65d2701534641f47601f4a2e226d1b53de51488a42dd1393c1dccc7533be0e89
sha512: 16255673b73ff1deda344cdf20e3cdbe74644416eedd4cc1517c4251cd57a9f4dc22355770fece13df51c61e2f8f35b726859afc85a9776240cfd4655b7df017
ssdeep: 49152:8oCsV7YFzzaGBDZqtzVTPECDGukoz9sXnfWGGs:GshYdeeZuzVT8Cp2XOGG
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName:
FileVersion: 1.1.28.01
ProductName:
ProductVersion: 1.1.28.01
FileDescription:
OriginalFilename:
Translation: 0x0409 0x04b0

Trojandownloader.Stralo also known as:

BkavW32.HfsAutoB.
MicroWorld-eScanTrojan.GenericKD.33042201
FireEyeGeneric.mg.b68c8121787369ee
CAT-QuickHealTrojandownloader.Stralo
Qihoo-360Generic/HEUR/QVM19.1.0A4D.Malware.Gen
McAfeeArtemis!B68C81217873
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Stralo.a!c
K7AntiVirusTrojan ( 00559ab31 )
BitDefenderTrojan.GenericKD.33042201
K7GWTrojan ( 00559ab31 )
Cybereasonmalicious.45a019
TrendMicroTrojan.Win32.WACATAC.USXVPB520
ESET-NOD32a variant of Win32/Packed.Themida.GZV
APEXMalicious
Paloaltogeneric.ml
GDataTrojan.GenericKD.33042201
KasperskyHEUR:Trojan-Downloader.Win32.Stralo.vho
AlibabaPacked:Win32/Themida.68c2b4fd
AvastWin32:Trojan-gen
RisingDownloader.Stralo!8.1147C (CLOUD)
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.33042201 (B)
F-SecureHeuristic.HEUR/AGEN.1038489
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusWin32.Outbreak
CyrenW32/Trojan.KCYB-5076
WebrootW32.Stralo
AviraHEUR/AGEN.1038489
MAXmalware (ai score=80)
MicrosoftTrojan:Win32/Skeeyah.A!MTB
ArcabitTrojan.Generic.D1F82F19
ZoneAlarmHEUR:Trojan-Downloader.Win32.Stralo.vho
Acronissuspicious
ALYacTrojan.GenericKD.33042201
Ad-AwareTrojan.GenericKD.33042201
MalwarebytesTrojan.Downloader.AHK.Themida
TrendMicro-HouseCallTrojan.Win32.WACATAC.USXVPB520
TencentWin32.Trojan.Agent.Pftc
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Themida.ASK!tr
AVGWin32:Trojan-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojandownloader.Stralo?

Trojandownloader.Stralo removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment