Threat Database Trojans Trojan.Shellcode.FEA

Trojan.Shellcode.FEA

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 25,699
Threat Level: 80 % (High)
Infected Computers: 26
First Seen: September 18, 2025
Last Seen: May 18, 2026
OS(es) Affected: Windows

The detection of Trojan.Shellcode.FEA on your system indicates a potential security threat. This report provides an overview of the threat, its operating methods, symptoms of infection, and steps to remove it from your system. It's essential to address this issue promptly to prevent further damage or unauthorized access to your data.

What Is Trojan.Shellcode.FEA?

Trojan.Shellcode.FEA is a type of malware that can compromise the security of your computer. The term "Trojan" refers to a broad category of malicious software that disguises itself as legitimate programs to gain unauthorized access to a computer system. The presence of "Shellcode" in its name suggests that it may utilize shellcode techniques, which are snippets of code used as the payload in exploits. Shellcode is typically used to execute malicious actions once a vulnerability has been exploited. Understanding the nature of this threat is crucial for taking appropriate measures to protect your system and data.

How Trojan.Shellcode.FEA Operates

Malware like Trojan.Shellcode.FEA operates by exploiting vulnerabilities in software or manipulating users into installing it. Once installed, it can perform a variety of malicious actions, including but not limited to, stealing sensitive information, installing additional malware, or providing unauthorized access to the infected system. The specific operations of Trojan.Shellcode.FEA can vary, but its primary goal is to compromise the security and integrity of the infected computer. It's also possible for such malware to evolve over time, incorporating new techniques to evade detection and removal.

Symptoms of Infection

Symptoms of a Trojan infection can be subtle and may not always be immediately apparent. Common indicators include unexpected changes in system performance, such as slower operation, frequent crashes, or the appearance of unwanted programs or toolbars in your web browser. You might also notice that your antivirus software is disabled or that you are being redirected to unwanted websites. In some cases, there may be no noticeable symptoms at all, which is why regular system scans with reputable antivirus software are essential for early detection.

How to Remove Trojan.Shellcode.FEA

  1. Boot your computer in Safe Mode with Networking. This will help prevent the malware from loading and make it easier to remove.
  2. Perform a full scan of your system using a reputable antivirus tool, such as SpyHunter. Ensure your antivirus software is updated with the latest definitions before scanning.
  3. Uninstall any suspicious programs that you do not recognize or that were installed around the time you suspect the infection occurred.
  4. Reset your web browsers (Chrome, Firefox, Edge) to their default settings. This can help remove any malicious extensions or settings changes made by the malware.
  5. After completing the above steps, reboot your computer and perform another full scan with your antivirus software to ensure that all components of the malware have been removed.

It's crucial to follow these steps carefully and patiently. Removing malware can be a complex process, and rushing through it may lead to incomplete removal, leaving your system still vulnerable.

Conclusion

The removal of Trojan.Shellcode.FEA requires careful attention to detail and a systematic approach. By understanding how this malware operates and following the provided removal steps, you can help protect your system and data from further compromise. Remember, prevention is key; keeping your operating system, software, and antivirus tools up to date, along with practicing safe computing habits, can significantly reduce the risk of future infections. Stay vigilant and ensure that you regularly scan your system for any signs of malware to maintain a secure computing environment.

Analysis Report

General information

Family Name: Trojan.Shellcode.FEA
Signature status: No Signature

Known Samples

MD5: 3ad03edc550b5f4241b60af1cdba0f4e
SHA1: 0c1ad65361991ace9724aa91a680ce8ad379950d
SHA256: 6D4004BFBBB6F991484C5D68F395BA1972F9F675BA99C6BF88BBF2D3FA6A0011
File Size: 137.03 KB, 137027 bytes
MD5: 80da5f6020b2ed45f2875ef486cd7f13
SHA1: 1ed2c8a08c08034d9a558ad3928db276187613b2
SHA256: CE6F9FC85AC1DFCCCAA7999FDD11E1ACC3408232400140D08E01BB0BF526EC0C
File Size: 134.58 KB, 134581 bytes
MD5: 3f7477f2cc31b30dcfadf9a6257beadf
SHA1: c8ad2a7b0a72e6bf6596787356b9018dce88dc5c
SHA256: 11695351D80BDD8BE5CFD3491CBE440F31A0B67864DCC31FB52586760660ED44
File Size: 133.29 KB, 133291 bytes
MD5: c34eef28a5ed5c0d312801bfdec75b46
SHA1: d1bad7d824daae198f41542e349b3398e87d6dfa
SHA256: 6D54740BDCA5ECCB7C2CB72FC08B576C09DA79935DD6BCA2397AC53673710C3B
File Size: 129.02 KB, 129017 bytes
MD5: 41b055365fcd32b32969dd472535e61d
SHA1: 321e1b6b1885d1fb4a46c255adb7e4365aedb43c
SHA256: 6E18DE916B0ED519667E0B1B9F65AEC0DB507329B60224D0DCAC150424B63C60
File Size: 132.86 KB, 132859 bytes
Show More
MD5: 0ad3dab64c33848d0ac8e06eefdfa2c0
SHA1: 4fdded1c496ea16571c5626fd338d73be6512c26
SHA256: 92E3D0E549202EDFA22245F704815622D949AE14B67233EB2E2951FDD345A766
File Size: 131.25 KB, 131247 bytes
MD5: 091e5aef52c1b87f82b79ea44a4d3f32
SHA1: 6b6ed63af9a904b5f71629fff836a9a76fb9e89a
SHA256: 30B7E376BBEAE7BE924FA0CDC76A984ED5DEDC5F554D3F0CBC026AF563946B8A
File Size: 134.58 KB, 134581 bytes
MD5: 1685594e9acc8fc34d537449e6d3e78f
SHA1: 39405f4ca8d8094af6f13a0c44331023443cf20f
SHA256: 7857A2F60906644C0677EF6BCBB9CF4DF11895BA70691AB975783865A5DE91A0
File Size: 133.29 KB, 133291 bytes
MD5: 0760f779d2a65bea4f353e56f1e14755
SHA1: 45ec2b7c0d5fc35212a8fa15625acdd3224f0999
SHA256: 02B8739EE004824B7D87C7CC18DFAC23A069BFD63270CD008D69BBFF55157604
File Size: 129.02 KB, 129017 bytes
MD5: 2697e36e63c1f05664446b2f623d0761
SHA1: 7a0d74340a5334fe9fcb472df929814890e7829b
SHA256: 2EFC1ADAE36072A465E759F4A8D7AC61F8389182A3C0C33DAB230C086DEC0F49
File Size: 138.06 KB, 138057 bytes
MD5: f89b4a93b25fde4fc6c81e0a1e424153
SHA1: 778269fd9e9826beccdd352e20548bb8cfd93ce4
SHA256: D48957E1DEB07AAA251308653A5FE962631EB89D4179587DAC664AEF7C8B54BC
File Size: 136.53 KB, 136535 bytes
MD5: 27013001cbdb347b2d4ea37f22964cce
SHA1: 01a2d0529470fe1ff3b63756be6fd569cf4f1f69
SHA256: DE98DD900D07A10980AEB74CDBD5B27B37862E29B99B25F9D8F54ADBC253F562
File Size: 164.95 KB, 164952 bytes
MD5: 14dda38947b13f64fe337ac894d49578
SHA1: 25cf60fe976b563f6a93b165025f28486dd5167b
SHA256: 6D4EF9236B6908B0C17DF5DE681ABE1049397D52CAF1382DAFF610325B1C766D
File Size: 158.49 KB, 158488 bytes
MD5: d5f5d8e5368aec89e8e0056217589b81
SHA1: 40ab67352cd6bd022c4612ba884d507147510253
SHA256: F62C70141F278E3AF6D94ADB4026B2700DE534954DE664336EE028FD27387A8D
File Size: 128.80 KB, 128801 bytes
MD5: 8e733b552268eeacc58d662fafe62f15
SHA1: 23a8d647b0ebb003ad161d1c04b99971655928be
SHA256: 8E545BE47EC37B4E7553F442BD668213A9297D856EBAFF20DE5386887CEE6964
File Size: 137.03 KB, 137027 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • No Version Info
  • x64

Block Information

Total Blocks: 113
Potentially Malicious Blocks: 1
Whitelisted Blocks: 112
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.FRWR
  • Agent.GOD
  • Agent.IFGF
  • Agent.KORA
  • Agent.KPEC
Show More
  • Agent.KPED
  • Agent.KPSF
  • Agent.PDFA
  • Agent.PDFD
  • Agent.PDFE
  • Agent.PDFG
  • Agent.RAC
  • Agent.UFSF
  • CobaltStrike.FSC
  • CobaltStrike.GDH
  • CobaltStrike.GP
  • Downloader.Agent.RCA
  • HackAgent.GT
  • Kryptik.DTS
  • LockScreen.IA
  • LockScreen.KA
  • Metasploit.Gen.H
  • Phave.D
  • ReverseShell.GDA
  • Rozena.FDA
  • Rozena.XV
  • Shellcode.FEA
  • ShellcodeRunner.FO
  • ShellcodeRunner.RF
  • ShellcodeRunner.RFA
  • ShellcodeRunner.RFB
  • ShellcodeRunner.WE
  • Trojan.Agent.Gen.AFP
  • Trojan.Agent.Gen.ALS
  • Trojan.Agent.Gen.BBK
  • Trojan.Agent.Gen.BEU
  • Trojan.Agent.Gen.FK
  • Trojan.Agent.Gen.ME
  • Trojan.Agent.Gen.OE
  • Trojan.Agent.Gen.OF
  • Trojan.Agent.Gen.PO
  • Trojan.Injector.Gen.DIU
  • Trojan.Kryptik.Gen.AZJ
  • Trojan.Kryptik.Gen.BDJ
  • Trojan.Kryptik.Gen.CGG
  • Trojan.Kryptik.Gen.CMI
  • Trojan.Kryptik.Gen.CWB
  • Trojan.Kryptik.Gen.KR
  • Trojan.ReverseShell.Gen.AC
  • Trojan.ReverseShell.Gen.CW
  • Trojan.ReverseShell.Gen.CX
  • Trojan.ReverseShell.Gen.F
  • Trojan.ReverseShell.Gen.V
  • Trojan.ShellcodeRunner.Gen.DS
  • Trojan.ShellcodeRunner.Gen.FR
  • Trojan.ShellcodeRunner.Gen.LA
  • Trojan.ShellcodeRunner.Gen.OY

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Trending

Most Viewed

Loading...