Trojan

TrojanDownloader:Win32/Dalexis.F (file analysis)

Malware Removal

The TrojanDownloader:Win32/Dalexis.F is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Dalexis.F virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (5 unique times)
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
sintjoep.nl
stocksandstares.co.uk
amberaffair.org.au
pupillenwijhe92.nl
sompex.de
scottwall.com
bmws1vc.altervista.org

How to determine TrojanDownloader:Win32/Dalexis.F?


File Info:

crc32: DB3089F7
md5: 7881b8fc637db2c3264174b597810ebe
name: 7881B8FC637DB2C3264174B597810EBE.mlw
sha1: 5607bf00991a5316c1e32e4d32e6d2a051ee9df7
sha256: 1f08b4187c160f1ba81b6dd010eb29237842b3db258a0f5cee3680ac79e1b0f0
sha512: fd1ec1ad508c7b6161fce22b89b80a2da42703a97f506f1e638e9d7c13ea327de876aa6842318ecbaf993e8693f1144242f24cf23f7aab11387f5d40a6aa6a00
ssdeep: 768:PZtRyqYA+PwyEsbqUaeMt6/ofx5ewlCojFP:PZ3yqYA+PwypqUaPUU7ewg
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

TrojanDownloader:Win32/Dalexis.F also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Agent.BIZO
FireEyeGeneric.mg.7881b8fc637db2c3
CAT-QuickHealTrojanDwnldr.Dalexies.F4
McAfeeRansom-CTB.gen
CylanceUnsafe
ZillyaDownloader.CTBLockerGen.Win32.1
K7AntiVirusTrojan ( 004be5001 )
BitDefenderTrojan.Agent.BIZO
K7GWTrojan ( 004be5001 )
Cybereasonmalicious.c637db
BaiduWin32.Trojan.Elenoocka.a
CyrenW32/Elenoocka.C.gen!Eldorado
SymantecDownloader.Ponik!gen9
APEXMalicious
AvastWin32:GenMalicious-JWL [Trj]
KasperskyTrojan-Downloader.Win32.Cabby.cemy
AlibabaTrojanDownloader:Win32/Cabby.f6e8bb7a
NANO-AntivirusTrojan.Win32.Cabby.dqngqj
ViRobotTrojan.Win32.Downloader.77824.JK
RisingTrojan.Win32.CTB.i (RDMK:cmRtazq/QJkYOGqIDpdwGtbp2dwu)
Ad-AwareTrojan.Agent.BIZO
SophosML/PE-A + Troj/Agent-AMNP
ComodoTrojWare.Win32.TrojanDownloader.Elenoocka.BADA@5pa6l9
F-SecureTrojan.TR/Cabhot.vuze
DrWebTrojan.Upatre.208
VIPRETrojan-Downloader.Win32.Dalexis
McAfee-GW-EditionBehavesLike.Win32.Emotet.lt
EmsisoftTrojan.Agent.BIZO (B)
IkarusTrojan-Ransom.CTBLocker
GDataTrojan.Agent.BIZO
JiangminTrojanDownloader.Cabby.uk
AviraTR/Cabhot.vuze
MAXmalware (ai score=81)
Antiy-AVLTrojan[Downloader]/Win32.Cabby
ArcabitTrojan.Agent.BIZO
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
ZoneAlarmTrojan-Downloader.Win32.Cabby.cemy
MicrosoftTrojanDownloader:Win32/Dalexis.F
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/CTBLocker.Gen
Acronissuspicious
ALYacTrojan.Agent.BIZO
VBA32BScope.Trojan.Zbot.2312
MalwarebytesTrojan.Agent.ED
PandaTrj/Ransom.BH
ESET-NOD32Win32/TrojanDownloader.Elenoocka.C
TrendMicro-HouseCallTROJ_DALEXIS.SMN
TencentTrojan.Win32.Cabby.cemya
YandexTrojan.GenAsa!dtl5pieHMpo
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_88%
FortinetW32/Elenoocka.C!tr.dldr
AVGWin32:GenMalicious-JWL [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.Downloader.462

How to remove TrojanDownloader:Win32/Dalexis.F?

TrojanDownloader:Win32/Dalexis.F removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment