Trojan

Trojan.Win32.Ekstak.axduj (file analysis)

Malware Removal

The Trojan.Win32.Ekstak.axduj is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Ekstak.axduj virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan.Win32.Ekstak.axduj?


File Info:

name: DC898BF0BE081754E1BB.mlw
path: /opt/CAPEv2/storage/binaries/dfb269cc34f48d2cf315302cc2bfb5d3f95d4328bd47d3160fc9fa7115dc6196
crc32: 63ED41D1
md5: dc898bf0be081754e1bbba2c48f9b239
sha1: 2185888d15f173ce677c73618be3f713ff8903af
sha256: dfb269cc34f48d2cf315302cc2bfb5d3f95d4328bd47d3160fc9fa7115dc6196
sha512: 74c15a874bb5ff28d1e1d2979e21a9ea411a740bfb99a8a34a8ecbb305cdee529733ff8237499be4df3906cbd77e4ea01ed392f1cee374a48496d3ff9516a9b7
ssdeep: 196608:yCXiYdaeAO8pkYcS4fhfD4BSPnuYl3Hh4mJay58pIcViNCcT:XXiq4O8pNcSwxjtl3hnJa4Y3iQcT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14C863342A2776AB5C1788D70605F16C75E7206823B2DBD0EB4A4DC3E76AB743806C7B3
sha3_384: bf3ac44783e2e305bc6be2fcfc5776a51a274e2019fc7bc1f614586f14479af7c6584e8591383c34ad68d17c557ca09e
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 2024-04-14 02:30:46

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: JS Video Plugin Setup
FileVersion:
LegalCopyright:
ProductName: JS Video Plugin
ProductVersion:
Translation: 0x0000 0x04b0

Trojan.Win32.Ekstak.axduj also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
SkyhighBehavesLike.Win32.BadFile.rc
Cylanceunsafe
SangforTrojan.Win32.Ekstak.Vahn
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 005722f11 )
K7AntiVirusTrojan ( 005722f11 )
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R002H0CDE24
KasperskyTrojan.Win32.Ekstak.axduj
AvastOther:Malware-gen [Trj]
TencentWin32.Trojan.Ekstak.Kmnw
F-SecureHeuristic.HEUR/AGEN.1373347
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GoogleDetected
AviraHEUR/AGEN.1373347
VaristW32/Trojan.CICV-6871
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmTrojan.Win32.Ekstak.axduj
GDataWin32.Backdoor.Bodelph.ALXF1B
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Malware-gen.R645202
McAfeeArtemis!DC898BF0BE08
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/Chgt.AD
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.240207333.susgen
FortinetW32/Agent.SLC!tr
AVGOther:Malware-gen [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan[dropper]:Win/Ekstak.axduj

How to remove Trojan.Win32.Ekstak.axduj?

Trojan.Win32.Ekstak.axduj removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment