Trojan.StealthWorker.GO
Short bio
Trojan.StealthWorker.GO is Malwarebytes’ detection name for a trojan written in Golang that adds the infected computer to a botnet.
Type and source of infection
Trojan.StealthWorker.GO adds the affected system to a botnet designed to bruteforce Magento sites. Trojan.StealthWorker.GO was found as the payload for Trojan.WallyShack.
Protection
Home remediation
Malwarebytes can detect and remove Trojan.StealthWorker.GO without further user interaction.
- Please download Malwarebytes to your desktop.
- Double-click MBSetup.exe and follow the prompts to install the program.
- When your Malwarebytes for Windows installation completes, the program opens to the Welcome to Malwarebytes screen.
- Click on the Get started button.
- Click Scan to start a Threat Scan.
- Click Quarantine to remove the found threats.
- Reboot the system if prompted to complete the removal process.
Business remediation
How to remove Trojan.StealthWorker.GO with the Malwarebytes Nebula console
You can use the Malwarebytes Anti-Malware Nebula console to scan endpoints.
Nebula endpoint tasks menu
Choose the Scan + Quarantine option. Afterwards you can check the Detections page to see which threats were found.
Traces/IOCs
Hash: fdc3e15d2bc80b092f69f89329ff34b7b828be976e5cbe41e3c5720f7896c140
IP & port: 5.45.69.149:7000