Malware

About “Exploit.Win32.Shellcode.xew” infection

Malware Removal

The Exploit.Win32.Shellcode.xew is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Exploit.Win32.Shellcode.xew virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (5 unique times)
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Ukrainian
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Steals private information from local Internet browsers
  • Attempts to access Bitcoin/ALTCoin wallets
  • Attempts to create or modify system certificates
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

telete.in
apps.identrust.com
trashbininspector.fun

How to determine Exploit.Win32.Shellcode.xew?


File Info:

crc32: 8A96554B
md5: 5f26cbfdec8afdb730c1a7729adf69d1
name: 5F26CBFDEC8AFDB730C1A7729ADF69D1.mlw
sha1: 8739df80f68c0c3188e76752553122c6150cea08
sha256: f40c77a22e3ec01343290ceab219f059bbde44af897e2949e779fb827720a5a4
sha512: 32f94f81b62516f7148180acd0a7dc1b46f51f9530e54699f95f5e7386c6f2542df2c46eb9c30d587a61cf10d82ee598c5c7f33d62381fa8aaebe1f43b7f4d83
ssdeep: 6144:vEjg6LHXyeJhAj2xkW1+6KifbV4OwrV9aNGbVUwaOpX/xljh7lVM54vTHPfIu7b:vOhhQEaoz+d/VUTiv97lqGr3Iu7T8
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalSurname: debaukd.ekze
Prod: 1.2.7
FileVersions: 1.0.5.6
LegalCo: Copyri (C) 2019, permudationzi

Exploit.Win32.Shellcode.xew also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.35913168
CAT-QuickHealTrojan.Multi
McAfeeRDN/Generic.grp
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 005756421 )
BitDefenderTrojan.GenericKD.35913168
K7GWTrojan ( 005756421 )
Cybereasonmalicious.0f68c0
CyrenW32/Trojan.KFFB-6183
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:DropperX-gen [Drp]
KasperskyExploit.Win32.Shellcode.xew
AlibabaTrojan:Win32/Shellcode.b37193e2
ViRobotTrojan.Win32.Z.Agent.463872.ZP
AegisLabTrojan.Multi.Generic.4!c
TencentWin32.Exploit.Shellcode.Sxes
Ad-AwareTrojan.GenericKD.35913168
EmsisoftTrojan.Crypt (A)
ComodoMalware@#3tnm5d9k7e2s4
F-SecureTrojan.TR/Crypt.Agent.btpuj
DrWebTrojan.Siggen11.56849
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
FireEyeGeneric.mg.5f26cbfdec8afdb7
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_95%
AviraTR/Crypt.Agent.btpuj
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Zenpack.MU!MTB
GridinsoftTrojan.Win32.Packed.oa
ArcabitTrojan.Generic.D223FDD0
ZoneAlarmExploit.Win32.Shellcode.xew
GDataTrojan.GenericKD.35913168
CynetMalicious (score: 100)
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34700.CmGfaWTqLpgc
ALYacTrojan.GenericKD.35913168
MAXmalware (ai score=99)
VBA32Trojan.Azorult
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HILR
TrendMicro-HouseCallTROJ_GEN.R002H0CLT20
RisingBackdoor.Agent!8.C5D (TFE:5:IhzqwXEXQUL)
IkarusTrojan.SuspectCRC
FortinetW32/Kryptik.HGHW!tr
AVGWin32:DropperX-gen [Drp]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Generic/HEUR/QVM11.1.3D82.Malware.Gen

How to remove Exploit.Win32.Shellcode.xew?

Exploit.Win32.Shellcode.xew removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment