Spy Trojan

About “Trojan-Spy.Win32.Stealer.axhs” infection

Malware Removal

The Trojan-Spy.Win32.Stealer.axhs is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Stealer.axhs virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan-Spy.Win32.Stealer.axhs?


File Info:

name: F5CA7A4283A387AC2D9F.mlw
path: /opt/CAPEv2/storage/binaries/0684df47e885ab1f70b2ee3fcfd5d2fa3e3ae1155f11acd6bcddaea4022d36aa
crc32: F81D5168
md5: f5ca7a4283a387ac2d9fc3427d20eb17
sha1: 055120692b38e06fa5b5993262dd4ff1a572da1c
sha256: 0684df47e885ab1f70b2ee3fcfd5d2fa3e3ae1155f11acd6bcddaea4022d36aa
sha512: f602eecdcf05246233c6bd4a41670dde5230f0961fae1065c62630359f8826b27d3a3ff18bebb1b06811643ae976258c86cdf3b59a12d010cf02e5c9dea07365
ssdeep: 49152:mxuaOaZuK/iUwHDyK3IYytOFNCX/4WmmHisrWqcjs9Za01EpgUbzpi0ckWmNaYHS:o/ijZIYbS49mDWZjs9lAb9i0c3a9S
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T130F5333CA8C1EED4C46E7CB9E0C538B602FAB0194DC81BEE97125564FE258B1AF5417E
sha3_384: 1af80f8b5b81a215defeb28d7f34376129bbe847fa7e15d15bcec91369cb103f3697b78d9e6e938b515e961b1d780039
ep_bytes: 6801f08f00e801000000c3c3ce033f97
timestamp: 2022-01-05 20:28:41

Version Info:

0: [No Data]

Trojan-Spy.Win32.Stealer.axhs also known as:

LionicTrojan.Win32.Stealer.l!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Steam.24507
MicroWorld-eScanTrojan.GenericKD.38459901
FireEyeGeneric.mg.f5ca7a4283a387ac
CAT-QuickHealTrojanSpy.Stealer
McAfeeGenericRXRL-EP!F5CA7A4283A3
CylanceUnsafe
ZillyaTrojan.Asprotect.Win32.185
SangforSpyware.Win32.Stealer.axhs
K7AntiVirusTrojan ( 0058c4bd1 )
AlibabaTrojanSpy:Win32/Stealer.ece208fb
K7GWTrojan ( 0058c4bd1 )
Cybereasonmalicious.92b38e
BitDefenderThetaGen:NN.ZexaF.34160.ANWaaidK9jck
CyrenW32/Stealer.W.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Packed.Asprotect.LG
TrendMicro-HouseCallTROJ_FRS.VSNTA622
Paloaltogeneric.ml
ClamAVWin.Malware.Fragtor-9935236-0
KasperskyTrojan-Spy.Win32.Stealer.axhs
BitDefenderTrojan.GenericKD.38459901
AvastWin32:Malware-gen
TencentWin32.Packed.Asprotect.Eera
Ad-AwareTrojan.GenericKD.38459901
EmsisoftTrojan.GenericKD.38459901 (B)
ComodoMalware@#3cgx8c9ab7v10
TrendMicroTROJ_FRS.VSNTA622
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
SophosMal/Generic-S
IkarusTrojan.Win32.ASProtect
GDataTrojan.GenericKD.38459901
JiangminTrojanSpy.Stealer.mup
eGambitUnsafe.AI_Score_61%
Antiy-AVLTrojan/Generic.ASMalwS.35015FD
KingsoftWin32.PSWTroj.Undef.(kcloud)
GridinsoftTrojan.Heur!.032120A1
ViRobotTrojan.Win32.Z.Agent.3573248.B
MicrosoftTrojanSpy:Win32/Aicat.A!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Evo-gen.R464029
ALYacTrojan.GenericKD.38459901
MAXmalware (ai score=87)
VBA32BScope.Trojan.Tiggre
MalwarebytesTrojan.MalPack
APEXMalicious
RisingSpyware.Stealer!8.3090 (CLOUD)
YandexTrojanSpy.Stealer!0mBLYM61QwU
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.137697082.susgen
FortinetW32/PossibleThreat
WebrootW32.Malware.Gen
AVGWin32:Malware-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan-Spy.Win32.Stealer.axhs?

Trojan-Spy.Win32.Stealer.axhs removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment