Trojan

Trojan.Win32.Ekstak.ahhqm (file analysis)

Malware Removal

The Trojan.Win32.Ekstak.ahhqm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.ahhqm virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify desktop wallpaper
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Attempts to identify installed AV products by installation directory

How to determine Trojan.Win32.Ekstak.ahhqm?


File Info:

name: 59FE5A3CE7873F644090.mlw
path: /opt/CAPEv2/storage/binaries/05f2266bd3e791400b16a600acfeb9e5f1b75ae9dca3021f674fc3fefa4ec605
crc32: 0D705ED6
md5: 59fe5a3ce7873f644090dbef1f350110
sha1: 899b9f68471b27a11520aa88e04d66a51bbf6ebd
sha256: 05f2266bd3e791400b16a600acfeb9e5f1b75ae9dca3021f674fc3fefa4ec605
sha512: dbda84f5d789ca2e0834b9b72db0a17c70bd79594cfbbb1e265488ca932aac64e077ea92fe6a2cef459ce16ad6d2352763bb1491743122bf2390c712db9c9556
ssdeep: 196608:eOJt+YmTHf6BS3zLqik+owOz31n108dd5r93jdJEmszVNgZTZB/qdIVmBm:epOSDBFAz3v08drr93jw/YTj/q0mw
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T188B633954B180E7FCCD409F4BA37E0890F9524B35BB0628E20C9ADB76DB6C5DE6E6311
sha3_384: 2f7f0793452ebf9f5ed6898d7ae3756fd31049404ae192f190e657172db14b2d5821fab1768c9e18b29dfa72f64edf13
ep_bytes: 558bec83c4c453565733c08b0d28ce40
timestamp: 2020-11-10 16:11:15

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: iosoft Ltd.
FileDescription: IP Player Pro Setup
FileVersion: 0.0.0.0
LegalCopyright:
ProductName: IP Player Pro
ProductVersion: 1.9.3.4
Translation: 0x0000 0x04b0

Trojan.Win32.Ekstak.ahhqm also known as:

CylanceUnsafe
SangforTrojan.Win32.Wacatac.C
K7AntiVirusTrojan ( 005722f11 )
AlibabaTrojanDropper:Win32/Ekstak.564202cc
K7GWTrojan ( 005722f11 )
CyrenW32/Agent.CDM.gen!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
APEXMalicious
KasperskyTrojan.Win32.Ekstak.ahhqm
AvastOther:Malware-gen [Trj]
SophosInnoMod (PUA)
DrWebTrojan.Zadved.1661
McAfee-GW-EditionArtemis!Trojan
EmsisoftAdware.Downloader (A)
IkarusTrojan.Win32.Crypt
JiangminTrojanDownloader.Razy.hmh
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1233157
MicrosoftProgram:Win32/Wacapew.C!ml
ZoneAlarmHEUR:Trojan-Dropper.Win32.Inokrypt.gen
AhnLab-V3PUP/Win32.DownloadAssistant.R355462
McAfeeArtemis!59FE5A3CE787
MalwarebytesAdware.DownloadAssistant
YandexTrojan.Ekstak!IMkxZL8jXjc
MaxSecureTrojan.Malware.109605089.susgen
FortinetRiskware/Agent
AVGOther:Malware-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Ekstak.ahhqm?

Trojan.Win32.Ekstak.ahhqm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment