Malware

How to remove “Exploit.Win32.Shellcode.wul”?

Malware Removal

The Exploit.Win32.Shellcode.wul is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Exploit.Win32.Shellcode.wul virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Slovenian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Checks for the presence of known windows from debuggers and forensic tools
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to identify installed AV products by installation directory
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
iplogger.org
leatherbond.top
ip-api.com

How to determine Exploit.Win32.Shellcode.wul?


File Info:

crc32: 80CF3E3A
md5: 70303ea440f18f06fa67777799319c7d
name: 70303EA440F18F06FA67777799319C7D.mlw
sha1: dc595125ac50fae49a3c9a655a25ca0588c538b8
sha256: d688fbf199c66861079b6fb41c9d6233d83ed7ec11f01324a92bb2b8cf661ab7
sha512: f8dffcb770b3ed990f2c383c99e4efdde4de7efadc227955a47a9e03c771943b6d99844944c7684ac0f5e575f57b1be5dce335a5d897eb303679329cefe40903
ssdeep: 12288:2CbNWCznlvykr3A7ChBVARGubdMJ3F33QLmlT/pJIYbPxDjJI9jB:2QWCznVyQ3A7ChBVAJWJVHQA/pDbPxQ
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalSurname: reboud.exe
Product: 1.7.6
FileVersions: 1.0.5.4
LegalCo: Copyri (C) 2019, patritions
Translation: 0x5539 0x00fa

Exploit.Win32.Shellcode.wul also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45149482
FireEyeGeneric.mg.70303ea440f18f06
Qihoo-360Generic/HEUR/QVM11.1.251F.Malware.Gen
McAfeeGenericRXAA-AA!70303EA440F1
CylanceUnsafe
AegisLabTrojan.Win32.Malicious.4!c
SangforMalware
K7AntiVirusTrojan ( 0057533c1 )
BitDefenderTrojan.GenericKD.45149482
K7GWTrojan ( 0057533c1 )
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyExploit.Win32.Shellcode.wul
AlibabaExploit:Win32/Shellcode.c7a3ffa0
ViRobotTrojan.Win32.Z.Kryptik.706048.AM
Ad-AwareTrojan.GenericKD.45149482
SophosMal/Generic-S
Comodo.UnclassifiedMalware@0
F-SecureTrojan.TR/AD.AHKInfoSteal.hrjco
DrWebTrojan.Siggen11.56472
TrendMicroTrojanSpy.Win32.ARTEMIS.USMANLO20
McAfee-GW-EditionBehavesLike.Win32.Trojan.jc
EmsisoftTrojan.GenericKD.45149482 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraTR/AD.AHKInfoSteal.hrjco
MAXmalware (ai score=83)
KingsoftWin32.Exploit.Shellcode.w.(kcloud)
MicrosoftTrojan:Win32/Azorult.FW!MTB
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.Generic.D2B0ED2A
ZoneAlarmExploit.Win32.Shellcode.wul
GDataTrojan.GenericKD.45149482
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.RL_Kryptik.R360326
BitDefenderThetaGen:NN.ZexaF.34700.RmGfay6FZcoc
ALYacTrojan.GenericKD.45149482
VBA32BScope.Backdoor.Agent
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HIKN
TrendMicro-HouseCallTrojanSpy.Win32.ARTEMIS.USMANLO20
TencentWin32.Exploit.Shellcode.Adtw
IkarusTrojan.Win32.Krypt
eGambitUnsafe.AI_Score_91%
FortinetW32/Kryptik.HFSR!tr
AVGWin32:PWSX-gen [Trj]
AvastWin32:PWSX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Exploit.Win32.Shellcode.wul?

Exploit.Win32.Shellcode.wul removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment