Backdoor

Backdoor.Win32.Vawtrak.xy malicious file

Malware Removal

The Backdoor.Win32.Vawtrak.xy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Win32.Vawtrak.xy virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Collects information about installed applications
  • Attempts to identify installed AV products by registry key
  • Collects information to fingerprint the system

Related domains:

4yg68a8ekesa.com
eoq0ikugy86o.org
0mci02s24is2.org
esm0ew2wuoag.net
4a0acaga4i0m.net
2wqc2w2seoqw.net
8yk64egikycm.org
6468ygygy86g.com
w2omwu0ycu8q.net
m0ac2gasq8u4.org
cmsm824u4qs6.org
ac2wi4awm82k.org
0uk64msqg2ka.net
e0acuo24uwug.net
cu8a8uo2c2ca.net
20qsyse0u0e8.net
4qs6wqwqcyge.org
a8286ougecm8.net
4ugio20i0246.com
u8igy0iwasm4.com
omkioakmsewa.net
moao6oak2cis.com
g2cqkes2024a.org
is2cismo2sqc.com
kuc24y86oiwm.org
246o2omk6kyg.org
wm0iguwqoisy.com
ekuguk6wqwms.net
0e0a4u4ykuc2.org
ak68ewusq4aw.com
wekiki8ac6c2.org
mo6ses6sms2w.org
cqcmc6oe8mwm.net
ekykise86oy0.org
8m0useg6ki0e.com
m8u4q4ysmgmo.net
s2cm8ao2ca0a.org
ioe468moq060.net
8ywug2cu8ukq.org
ec6wygqcmwas.org
0m0yom064ek6.net
mse8e8ygegis.org
0ik686cek642.org
ao24io2g2cu8.net
cy4ikasucewm.org
m4qoy4esuoys.com
se8qg2k2gi0i.org
mo6kmc2oykew.org
4ywege8ekawa.org
20ak6ke8ywqs.net
824i4mw2gykm.org
2om4msys6g2g.com
0qcqs2wakqka.net
6gusmw6w68ao.com
gu8a0mcq8ygy.net
msy42seo20ec.net
4usqkeke4y0m.net
ug2oy824uoy0.org
w2wqc6kigyw6.org
ucysqgiwq4mo.com
4q8egycm0eoq.org
acmwiki4q028.net
4e8m820m4uca.com
m0y06ceo6wms.org
o24iwmgyoqk2.org
2gy8qo2g24ak.net
oisiwuwmwyou.org
agy0m8u8egms.com
8isyga4ewaoa.org
is60agmceom4.com
0ukmkqwqcq4e.org
2o6cqkqouoao.net
ge0i0yc6guga.net
ekakuw2omwi8.com
0i4aci4esm4i.net
ucqg2ouw2g6g.net
o6424ms6oe4m.org
ywmw6om46g6g.org
8iwm8qw2g20a.net
a0e4m8uo68uk.org
0y4usqge4e8i.com
6wqkys2c6ous.net
4ake8q0uwis2.com
e82s6wmci4ek.org
gewekyouc2c6.org
eg2oe860a0uw.net
wigaky8q4usy.net
aoyoysmcuk68.org
8esigq0yguw6.net
246gekqw64e0.com
s28m8ioqomka.com
acuouci8awa0.org
86gqoqguwqcu.com
is2ouc2oeoag.net
cysuououk6o6.org
6gy8e0i82cqs.org
864asicuceoi.com
ecm8ycmkygyo.org
kugysu4i8e4i.org
2cy8u4ms6cik.org
86sykukeom4q.net
ecq4ukmoqgy0.com
8m8yku8iwe0m.com
q0iwykisqouc.com
0yk64m86wio2.net
qkm86ka4m0m8.com
cqwiseg6c2wq.net
m82sm02kyg6k.com
ki4ysa0icy42.net
i0i0u4esm8is.net
8i0qoe4y4yc2.com
a8ysqsaw2ci4.com
gyk2o6wy8a4u.net
uci4qomk2gu4.net
cyoig2wuo6ge.org
6cusioa4ioq4.org
4u8usuoug6cm.org
ekeg28mg24eo.net
0qsm060icmo2.net
ygmce4qsewu8.org
sawacecq4qwm.com
2ge0e8qcismo.net
w6wegag28esi.com
mkysi42cu8ec.net
caw6w6gmo6wa.org
ygekiwecawyw.org
824a424ewigy.com
2sa0qcakuwqo.org
si8eoigy4i46.com
m424akq4egeo.net
82cq0esykuwe.com
y4iwmg6wek2w.org
sesqgag2sq0m.org
6k2g2ou82gi4.com
4aoyw28u4e4e.com
isec20ugusyg.com
8ykqg6o6oqsq.com
u4mgqw2ouou4.net
0qs2kysa8qci.net
20qwige0egu0.net
86oa0mky02gq.org
moq86kuwm0qg.net
g6ki8uw64qcu.net
agq46su4y4ac.org
0mwioy8u86se.net
aoewus6s6kyc.net
cyg2we02kegi.net
mguga428ekms.net
wecege0qs28e.org
2sewi0awqkq0.org
kqo6o20a0m4m.org
qoqgq0akuci4.net
g6wuk2ke4y0a.com
a828m86seou4.org
wi0uwuwqsm8q.org
6wq82wi4ucew.com
4e4yoyo6cysm.org
moi4mgusqca0.org
c6wqgagecak6.org
u0e4i8mwq42s.org
0mwqguouk2c2.net
ioyoy02kig60.net
wmgmguwe0mcy.org
isek646sysuo.org
8msac28ak20q.com
i82oacqw2kug.net
0qkeo6ou4ugi.net
asm02oqo24ac.org
suwe8ak28242.org
e0a8ysi4eg28.org
428e0awa0yoa.org
akm820m4ywi4.net
w20iwmoeoe86.com
m42ousecu86w.org
gic2gisecygi.org
a46c28qs6kmo.org
suce4ecqgegq.org
u0uwy4uc6we0.org
o6se0mwmci42.com
io6o206smoy4.net
gm8q0age8q82.com
aku8yoyw6gyk.org
cmgmw6cuciwa.com
egmcigiwyga4.net
o6wuwy02ka8q.org
us28ygucecq8.net
4ike0igusyki.org
isy46k64isys.org
kisaceoe864i.net
u0icis2k6w24.com
wmk2gy0ic2ou.net
isus2ci8mcak.com
8uk2ci8agawa.com
60mguk6gmwm4.org
wagysisa42ki.com
24mgiwukmkyc.net
4ywi8qwy8awy.org
m0mwi8ace0mk.net
ka8ag6ky4mga.org
e4m86omcu8i8.com

How to determine Backdoor.Win32.Vawtrak.xy?


File Info:

crc32: CFF57FFB
md5: bc490040926ba2972ebffc0cbbb019dd
name: BC490040926BA2972EBFFC0CBBB019DD.mlw
sha1: ffbb802dd7ff2807766d69ffc204bf142d7a72ad
sha256: b0d0b706a6fce4384b82c78a3425f765ba613bb4b39ab52778843fb2a006de9e
sha512: 1cbb7f09f7ef2ef72be670964566e0befa0f5cbe8a15f903b3ede6523906bb683ddb2d53726888f7a9ec13c49bdd20589e1232d8c2d2ddb64e72fb922b81ccec
ssdeep: 6144:BZvuh9MsS8RhYYxNJ7UZ0bhizOqbSTekl:BZvuTMsS8D3e4hizKTe2
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (c) 2014 - . All rights reserved. WestByte
InternalName: Inpo
CompanyName: WestByte
Comments: Univacs Rationale Conversational
ProductName: Inpo
ProductVersion: 3.7.5.62
FileDescription: Univacs Rationale Conversational
Translation: 0x0409 0x04b0

Backdoor.Win32.Vawtrak.xy also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00503ae41 )
Elasticmalicious (high confidence)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 00503ae41 )
Cybereasonmalicious.dd7ff2
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Vawtrak.xy
NANO-AntivirusTrojan.Win32.Vawtrak.evwcgo
TencentWin32.Backdoor.Vawtrak.Pgmr
SophosMal/Generic-S
DrWebTrojan.PWS.Qadars.47
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPLOCKY.SME1
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.bc490040926ba297
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1127217
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Dynamer!rfn
AegisLabTrojan.Multi.Generic.4!c
ZoneAlarmBackdoor.Win32.Vawtrak.xy
Acronissuspicious
McAfeeArtemis!BC490040926B
MAXmalware (ai score=96)
VBA32BScope.TrojanSpy.Zbot
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/CI.A
TrendMicro-HouseCallRansom_HPLOCKY.SME1
RisingTrojan.Generic@ML.100 (RDML:qgAqQZVLGTWt3RlJUQgxEg)
IkarusTrojan-Spy.Remcos
FortinetW32/Kryptik.EJXP!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Backdoor.Win32.Vawtrak.xy?

Backdoor.Win32.Vawtrak.xy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment